Skip Navigation

Posts
12
Comments
60
Joined
3 yr. ago

  • What I'm doing is using a dedicated VPN Gateway container. The instances running delicate services have a static default route to the GW-container.

    This is an extra step, but allows me add easily route other services or clients or even whole networks through my VPN without additional setup or specialized containers bundling both.

    Wanna use it on the phone? Change the gateway address. Wanna use it from my Linux machine? Add a static default route. Etc...

    Works flawlessly!

  • Of course! So in order to get maximum speed on your services, you wanna use a direct internal route when you're inside your net. My understanding is, that when using an external cloud VPS with a proxy, local clients go through unnecessary routing..

    Local request --out--> external VPS (proxy) --request data from internal--> receive data on external proxy --send back--> local client

    So what I am saying, all requests are unnecessarily routed through the external VPS. So one would have to create an exact duplicate reverse proxy internally to avoid leaving the net. When accessing domain.com, the internal DNS returns the local proxy IP, when outside you receive the cloud VPS IP.

    Or am I missing something?

    Thank you for taking the time!

  • One of my considerations is the privacy side… VPN or self hosted solution seems to be the waay better choice in that case.

  • Haha! Explaining for dummies, I like it.

  • Thanks! How do you handle that with internal DNS? I suppose you’d need to setup the exact same proxies on the internal and external server, and local DNS handles which one my domain it’s being resolved to?

  • Thank you for the detailed explanation. I am running Tailscale as a temporary solution to access some services, but I dislike that you have to set firewall rules basically twice (once in your local network and once in Tailscale). I suppose it would be similar for CF?

  • NetworkChuck does videos for beginners, but sometimes that’s just what an experienced user need ^^ thanks for sharing! Watching the video right now

  • Thanks for the write up! I’ll definately check out your blog as well. A cloud gateway is something I’ve considered as well (especially when the costs are around $5 monthly). How do you handle authentication?

  • One of the mysteries I am facing ^^ selfhost headscale? Tailscale? VPN? CF?

    Too many options :D

  • I read Austria is also the most liveable country? Funny how you can be both simultaneously

  • Agree. I can always tell if an actor is inhaling or puffing. And (I wish everyone the best in health) this looks just weird.

  • First and foremost: Thank you @ernest for your incredible work and dedication.

    1. Pay yourself a salary. Whatever you feel is appropriate & covers your personal costs. Developing and maintaining /kbin seems to be a full time job (or at least will become one)

    2. THANK YOU FOR YOUR TRANSPARENCY. That's why we are here. This builds such a huge trust with the community. Whatever you need, we'll be here.

  • Make sure you have backups of your vault. Reliable backups.

    Especially if you are just starting off with docker, you don't want to loose access to all your accounts because you f up some configuration (e.g. redeploy an updated image)

  • They have, bu current fluctuation and constant black swans raise the legitimate question

  • Try Resilio Sync. Running it for 5+ years now and did not have a single synchronization issue. Syncing around 5 devices flawlessly, instantly and error free (not sponsored)

  • Google for "The Fappening"

  • Look for "The Fappening", you will not be disappointed

  • Masayoshi Son (founder of Softbank and the legendary Vision Found) was lucky with Alibaba once. His strategy is literally (confirmed by many founders) that if you throw enough money in there (usually in 150mn+), it'll scale and be a unicorn.

    Well, what do you think happens if you are a unicorn founder raising maybe 500k-2mn and some oversees fund comes along and gives you 170mn with the only goal of scaling globally.

    Launch events here, new market there, private jets, ... Softbank and Son is also known for his lax oversight in his investments and throwing more money at it when they become bankrupt.

    Another famous example is WeWork (10bn+ investment by Softbank).

    And every story is just exceptionally dumb and easily avoidable.

    Source: Experience

  • Every time I hear any news about Austria it seems like satire. Honestly. Double-checking every time.