

I use a dual NIC mini PC running OpnSense. Ot would support USB sims. I actually have two of the routers connected woth a network cable. If one goes down, the other takes over.
I firmly believe I was way more prepared to ride a motorcycle because I spent countless hours reading about techniques before I got on one.
So… Maybe.
I’m not sure I follow the question. All of the TLD *.arpa
is not reserved for private use, only *.home.arpa
. So all your internal services are required to be a sub domain.
No thanks. I get some people agreed to this, but I’m going to continue to use .lan
, like so many others. If they ever register .lan
for public use, there will be a lot of people pissed off.
IMO, the only reason not to assign a top-level domain in the RFC is so that some company can make money on it. The authors were from Cisco and Nominum, a DNS company purchased by Akamai, but that doesnt appear to be the reason why. .home
and .homenet
were proposed, but this is from the mailing list:
- we cannot be sure that using .home is consistent with the existing (ab)use
- ICANN is in receipt of about a dozen applications for “.home”, and some of those applicants no doubt have deeper pockets than the IETF does should they decide to litigate
https://mailarchive.ietf.org/arch/msg/homenet/PWl6CANKKAeeMs1kgBP5YPtiCWg/
So, corporate fear.
I just use openssl"s built in management. I have scripts that set it up and generate a .lan
domain, and instructions for adding it to clients. I could make a repo and writeup if you would like?
As the other commenter pointed out, .lan
is not officially sanctioned for local use, but it is not used publicly and is a common choice. However you could use whatever you want.
I use a domain, but for homelab I eventually switched to my own internal CA.
Instead of having to do service.domain.tld
it’s nice to do service.lan
.
I just validated that the latest version of the LDAP privilege escalation issue is not an issue anymore. The curl
script is in the ticket.
This was the one where a standard user could get plugin credentials, such as the LDAP bind user, and change the LDAP endpoint. I.E., bad.
I chose this one because after going through all of them, it was the only one that allowed access to something that wasn’t just data in Jellyfin.
So for me, security is less of an issue knowing that, as only family use the service, and the remaining issues all require a logged in user (hit admin endpoint with user token).
Plus, I tried a few of those and they were also fixed, just not documented yet. I didn’t add to those tickets because I was not as formal with my testing.
Use an LDAP to OIDC bridge?
Do what makes you comfortable.
You’ll be out with family and friends, in an environment where most any swimsuit would be expected. Any lack of confidence would come from your own internal comfort, so you do you.
As a more practical suggestion if you’re on the fence, wear a wrap? Then you can decide how you feel in the moment.
Either comment OP hasn’t followed the news, or they forgot this was the Fediverse.
I used to do all the things mentioned here. Now, I just use Wireguard. If a family member wants to use a service, they need Wireguard. If they don’t want to install it, they dont get the service.
Actually #2 may be a brain fart for me. I’m probably thinking of the setting in the Arrs that changes file date to release date.
How long ago? I ran both side by side and felt the same way at first, but eventually dropped Komga.
I personally dont like rhe folder structure required for Kavita comics, so I have Mylar sort them and then create a symlink structure Kavita uses. Kavita handles Epub great, with the same structure as Calibre.
You can’t follow a post. Making the project am actor lowers the amount of federated data. If a user was an actor and you wanted to federate a project, you’d have to federate all their projects.
Ahh OK, a Docker bind. 3 things to check:
That you added the folders in that weird way Unraod requires, see: https://forum.jellyfin.org/t-solved-jellyfin-not-detecting-media-in-unraid (this probably isn’t it, but worth checking)
Make sure for newly added, Jellyfin is configured for Date File Scanned into Library, vs the Created Date on the file
Ensure the Arrs aren’t set to change the date on file import. By default they modify created/modified dates to be the release date, which can put things in an unexpected order.
I switched to Kavita. More modern and supports OPDS, so it connects to readers just like Caliber does. It was originally designed for comics, which is why it probably looks so good.
Hmm, shared how? NFS?
https://github.com/SynoCommunity/spksrc/issues/5941 ?
I really wanted Jellyfin working in my DS214Play with DSM6, and I noticed that a package for these evansport CPUs doesn’t exist and it’s officially not supported, so I tried myself and I succeeded.
Frame it. Neato.