• cenzorrll@piefed.ca
      link
      fedilink
      English
      arrow-up
      3
      ·
      7 months ago

      I’ve moved my homelab twice because it became stable, I really liked the services it was running, and I didn’t want to disturb the last lab**cough**prod server.

      My current homelab will be moar containers. I’m sure I’ll push it to prod instead of changing the IP address and swapping name tags this time.

    • Ek-Hou-Van-Braai@piefed.socialOP
      link
      fedilink
      English
      arrow-up
      76
      ·
      7 months ago

      But if my backups actually work then I miss out on the joy of rebuilding everything from scratch and explaining to my wife why non of the lights in the house work anymore.

    • JetpackJackson@feddit.org
      link
      fedilink
      English
      arrow-up
      19
      ·
      7 months ago

      Yesterday! Switched my media server from freebsd to alpine and got the arr stack all set up using the backup zip files

    • piranhaconda@mander.xyz
      link
      fedilink
      English
      arrow-up
      4
      ·
      7 months ago

      What’s a backup solution…? (I’m only being half sarcastic, I really need to set one up, but it’s not as “fun” as the rest of my homelab, open to suggestions)

        • piranhaconda@mander.xyz
          link
          fedilink
          English
          arrow-up
          7
          ·
          7 months ago

          I at least have external backups for important family pics and docs! But yea the homelab itself is severely lacking. If it dies, I get to start from scratch. Been gambling for years that “I’ll get around to a backup solution before it dies”. I wouldn’t bet on me :|

  • tal@lemmy.today
    link
    fedilink
    English
    arrow-up
    46
    ·
    7 months ago

    logging is probably down

    You do, of course have a dedicated rsyslogd server? An isolated system to which logs are sent, so that if someone compromises another one of your systems, they can’t wipe traces of that compromise from those systems?

    Oh. You don’t. Well, that’s okay. Not every lab can be complete. That Raspberry Pi over there in the corner isn’t actually doing anything, but it’s probably happy where it is. You know, being off, not doing anything.

        • Caveman@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          7 months ago

          I set my homelab up on Bazzite immutable with podman and SELinux. It took a while to work everything out and have it boot up into a valid state hahaha

        • The Stoned Hacker@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          7 months ago

          It’s not that difficult to get SELinux working with podman quadlets, especially if you run things rootless. I have a kerberized service account for each application I host and my quadlets are configured to run under those. I very rarely encounter applications that simoky can’t be run rootless but I usually can find an adequate alternative. I think right now the only thing that runs as root is one of the talk or collabora containers in my nextcloud stack. No selinux issues either.

          • epicshepich@programming.dev
            link
            fedilink
            English
            arrow-up
            0
            ·
            7 months ago

            I use podman-compose with system accounts and I don’t have a ton of issues. The biggest one is that I can’t seem to get bluetooth and pip working on Home Assistant at the same time. Most of the servers I manage have SELinux and it works fine as long as I use :z/:Z with bind mounts.

            A few years ago, I set up a VPS for my friend’s business; at the time, I didn’t know how to work with SELinux so I just turned it off. I tried to flip it back on, and it somehow bricked the system. We had to restore from a backup. Since then, I’ve been afraid to enable it on my flagship homelab server.

    • irmadlad@lemmy.world
      link
      fedilink
      English
      arrow-up
      23
      ·
      7 months ago

      At 71, I have to document. I started a long time ago. I worked for a mec. contractor long ago, and the rule was: ‘If you didn’t write it down, it didn’t happen.’ That just carried over to everything I do.

  • tal@lemmy.today
    link
    fedilink
    English
    arrow-up
    39
    ·
    7 months ago

    You have remote power management set up for the systems in your homelab, right? A server set up that you can reach to power-cycle other servers, so that if they wedge in some unusable state and you can’t be physically there, you can still reboot them? A managed/smart PDU or something like that? Something like one of these guys?

    Oh. You don’t. Well, that’s probably okay. I mean, nothing will probably go wrong and render a device in need of being forcibly rebooted when you’re physically away from home.

      • TerHu@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        7
        ·
        7 months ago

        if you can cycle your home assistant with the shelly plug whilst your home assistant is down, yes. from experience it’s really quite annoying to have a smart plug switch off HA…

        • lemming741@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          7 months ago

          HA is on the same proxmox host as the router. So yeah I can end up locked out. Hasn’t happened yet tho! The relay is on my test machine, it’s always nvidia that crashes there.

        • B0rax@feddit.org
          link
          fedilink
          English
          arrow-up
          0
          ·
          7 months ago

          The Shelly can be configured to automatically turn back on after a certain amount of time. It has local scripting capabilities.

          If they did that… I don’t know.

    • FauxLiving@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      7 months ago

      Oh. You don’t. Well, that’s probably okay. I mean, nothing will probably go wrong and render a device in need of being forcibly rebooted when you’re physically away from home.

      *furiously adds a new item to the TODO list*

    • tychosmoose@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      7 months ago

      If you do have the smart PSU and power management server you probably also went down the rabbit hole of scripting the power cycling, right? Maybe made that server hardened against power loss disk corruption so it can be run until UPS battery exhaustion.

      What if there is a power outage and NUT shuts everything down? Would be nice to have everything brought back up in an orderly way when power returns. Without manual intervention. But keeping you informed via logging and push notifications.

  • DownByLaw@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    39
    ·
    7 months ago

    Have you already tried implementing an identity provider like Authentik, so you can add OIDC and ldap for all your services, while you are the only one that’s using them? 🤔

  • tal@lemmy.today
    link
    fedilink
    English
    arrow-up
    36
    ·
    7 months ago

    All of those systems in your homelab…they aren’t all pulling down their updates multiple times over your network link, right? You’re making use of a network-wide cache? For Debian-family systems, something like Apt-Cacher NG?

    Oh. You’re not. Well, that’s probably okay. I mean, not everyone can have their environment optimized to minimize network traffic.

    • the_tab_key@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      7 months ago

      I set this up years ago, but then decided it was better to just install different distros on each of my computers. Problem solved?

    • [object Object]@lemmy.ca
      link
      fedilink
      English
      arrow-up
      2
      ·
      7 months ago

      You can forgejo with a container index enabled, I don’t know if there’s a way to use that as a proxy for downloading containers though.

  • FauxLiving@lemmy.world
    link
    fedilink
    English
    arrow-up
    26
    arrow-down
    1
    ·
    7 months ago

    The comments in this thread have collectively created thousands of person-hours worth of work for us all…

  • tal@lemmy.today
    link
    fedilink
    English
    arrow-up
    18
    ·
    7 months ago

    You have an intrusion detection system set up, right? A server watching your network’s traffic, looking for signs that systems on your network have been compromised, and to warn you? Snort or something like that?

    Oh. You don’t. Well, that’s probably okay. I mean, probably nothing on your network has been compromised. And probably nothing in the future will be.

  • nucleative@lemmy.world
    link
    fedilink
    English
    arrow-up
    18
    ·
    7 months ago

    Never run:

    docker compose pull
    docker compose down
    docker compose up -d
    

    Right before the end of your day. Ask me how I know 😂

    • shym3q@programming.dev
      link
      fedilink
      English
      arrow-up
      9
      ·
      7 months ago

      compose up will automatically recreate with newer images if the new one were pulled. so there is no need for compose down btw

  • Fedegenerate@fedinsfw.app
    link
    fedilink
    English
    arrow-up
    15
    ·
    7 months ago

    Going into spring/summer that’s ideal, I wanna go places do things. Mid winter, I’m feature creeping till something breaks.