Maybe, but there is always the possibility that Downloads and downloads both exist in that path and in a case sensitive file system, those are going to be two completely different directories, so adding that obfuscation on top might wind up biting you later.
- 0 Posts
- 41 Comments
TVA@thebrainbin.orgto Selfhosted@lemmy.world•Selfhosting Sunday - What's up to date, selfhosters?2·18 days agoI just followed their instructions and on 2 of the nodes in my cluster, I migrated all VMs/LXCs off and then did the upgrade and they went through without a hitch. For the last one, I just YOLO’d it and powered off the VMs/LXCs and upgraded it and it also went through without a hitch.
One thing I did find interesting was the systemd-boot packages needed to be removed and were on 2/3 of the machines. I basically intentionally keep their config as close to identical as possible, so I have no clue why it was only needed on 2 of them.
One of the nice things about ProxMox is that you can also set up a cluster. When OP outgrows it, they can just add a new machine to the cluster and just migrate some VMs over to it.
I keep mine in 2FAS and Vaultwarden.
For anyone in IT who works in multiple tenants or with multiple clients that use the same site(s), it’s an absolute gamechanger
TVA@thebrainbin.orgto Selfhosted@lemmy.world•My reason for wanting HomeAssistant and a locked down VLAN...1·2 months agoThe security here is the WiFi password anything that connects to LAN gets a LAN vlan tag. but it’s not like anything that connects to any of the SSIDs can get the DHCP lease of some random device on any vlan cuz it got tagged before. Or am I missing something?
That sounds accurate. I have all my devices assigned a specific IP address, based on their MAC address, but that’s only per-interface. The other interfaces aren’t aware of my assignments for each other.
If I connect my phone to my LAN SSID, it’ll get its assigned IP, but if I connect it to the NOT [network of things, no internet access] SSID, it’ll get assigned a new address out of the DHCP pool because I haven’t assigned it an IP on that interface, until I assign it an IP. But, which VLAN it’s connected to will determine which IP its getting, and it still requires me to know the passwords for each SSID.
I believe where you’re getting confused is that a some businesses (or homelabs) might use a RADIUS server which will be more like this: ONE_SINGLE_SSID-Broadcast -> Device connects -> RADIUS Server detects account/certificate/MAC -> RADIUS Server assigns interface -> Device connects to VLAN the RADIUS server granted it access to
So, in that scenario, if the ONLY thing that’s being used to validate the access is the devices MAC address, just changing the MAC address will effectively grant a completely different level of access with nothing else changing. Most people in a homelab (and even plenty of larger businesses) aren’t running the infrastructure to do this though, they’re just effectively connecting a VLAN to a port and then that port can only be used to connect to that VLAN. They’re doing the same with the WiFi SSIDs where each SSID connects directly to the VLAN.
Usually though, for places that are implementing the RADIUS server, they’ll also install a certificate on their devices and the certificate needs to be in place in order to get certain access otherwise the RADIUS server will authorize less permissive access or just won’t allow access at all. Or, it’ll also need a user to log in to gain additional access.
For wired, the company may also implement port locking where the port will only allow a certain amount of MAC addresses to connect (presumably one unless there is also a VOICE VLAN with a phone being used, in which case it’d be two) where if you change your MAC address (or connect a different device), the port will lock and won’t power POE devices and won’t allow connectivity until an admin clears the lock. It’s possible that they may have multiple VLANs allowed on the port and client side you can change VLANs, but, this isn’t typically done on all ports, usually only on trusted ports or ports that need the multiple VLANs (my VM server for instance has access to a port that’ll allow multiple VLANs and I just enter the tag I need when I create the VM). This would be similar to your WiFi scenario, the port with the WAP connected to it will have access to multiple VLANs and then those WLANs just connect to the VLAN that they’re assigned to.
TL;DR - Typically one wireless SSID connects to one VLAN and if you want to jump to the other VLAN you’d need to connect to the other SSID, so you still have the individual passwords protecting you. On wired, typically VLANs are assigned per port and you can’t jump between then, but where they aren’t, it should be in a planned way and not just every port having access to every VLAN. Bad implementations exist though, so, anything is possible.
VMs can also be live migrated to another server in the cluster with no downtime and backups don’t need to take the VM down to do their thing. If in the future you want to move to physical hardware, you can use something like Clonezilla to back it up (not needed often, but still, something to consider).
Both have their places, but those factors are the main ones that come into play of when I want to use a VM or LXC.
TVA@thebrainbin.orgto Mildly Infuriating@lemmy.world•Roommate refuses to use my body wash cause it's not "manly"7·3 months agoYeah, nothing says “I just don’t like that scent” quite like “I ain’t no bitch”
Looks fine for me with mobile app, Interstellar, fwiw, not even a little bit blurry.
TVA@thebrainbin.orgto Mildly Infuriating@lemmy.world•To join Facebook these days, one must record a video selfie4·3 months agoEspecially when they put the price as free and then say make me an offer!
At least put $1 so I don’t have to see your bullshit at all if I filter correctly.
TVA@thebrainbin.orgto Firefox@fedia.io•Top Pocket (Mozilla Bookmarking Service That will Shutdown) Alternatives.6·3 months agoI’ve never used Pocket, but I do use Karakeep and like it.
TVA@thebrainbin.orgto Selfhosted@lemmy.world•What's up, selfhosters? It's selfhosting Sunday again!2·4 months agoSorry, I didn’t mean to insinuate you were being insulting!
“Don’t feel crazy/bad/dumb, I’ve had the same thing happen to me!” is a pretty common phrasing in my region to show sympathy and understanding and I thought that’s what you had meant (and it sounds like for your area, ‘pregnant’ serves the same general purpose!).
TVA@thebrainbin.orgto Selfhosted@lemmy.world•What's up, selfhosters? It's selfhosting Sunday again!2·4 months agoIt’s always crazy how that happens sometimes and after weeks of banging your head, everything just ‘clicks’ when you’re exposed to the information in the way that works best for you!
Dude, don’t feel pregnant.
Context clues, I assumed this autocorrect was some variation of crazy/bad/dumb? :-D
TVA@thebrainbin.orgto Selfhosted@lemmy.world•What's up, selfhosters? It's selfhosting Sunday again!1·4 months agoWeirdness: My Authentik instance had a PostgreSQL upgrade prerequisite in order to update it.
I’d followed instructions 3-4 times completely unsuccessfully and had to keep reverting to backup.
So, I gave up for a couple weeks and left it be in order to get over my frustration.
Yesterday, I followed the instructions again. As far as I can tell, I did nothing different than I’d tried previously and it worked first try and then I was also able to upgrade Authentik.
NOTE: The instructions aren’t exactly difficult! So, I don’t see how I’d have gotten it wrong!
TVA@thebrainbin.orgto Showerthoughts@lemmy.world•No movie has a bigger cultural impact than Final Destination 24·4 months agoIt made kids afraid to swim in swimming pools!
Jaws and those notes hit something primal
TVA@thebrainbin.orgto No Stupid Questions@lemmy.world•How do I decrease acne after shaving my face?2·4 months agoYeah, DE + the process that typically goes with it (brush, shave soap, lathering it up, etc…) can do wonders to reduce the irritation.
With that said, I even found that shaving in the shower with normal hair conditioner and a DE was a better experience than the 5 bladed razors with the shave gel
OP - The blades are so cheap you can use a new one every time if you wanted (you don’t need to, but you can)
TVA@thebrainbin.orgto No Stupid Questions@lemmy.world•Is it a red flag if a potential employer rushes you?5·6 months agoSame, 2/3 of my most recent jobs came this way … doesn’t mean it’s not a potential red flag though
TVA@thebrainbin.orgto Technology@lemmy.ml•The Pebble smartwatch is making a comeback. Google has open-sourced the Pebble software, which means anyone — including Pebble’s founder — can make one.8·7 months agoMy AmazFit Bip could do a month when it was new (it’s down to ~10 days now after a few years), so I would think a month from Pebble would be feasible.
I don’t understand using a watch that you can’t use for AT LEAST a weekend without power … as it is, I’m pissed off that I’m down to 10 days (it’s stayed steady here for 6 months or so, so, I’m hoping it won’t degrade too much more before the new Pebble comes out).
He can only pardon federal crimes. In most states, governor’s can pardon state crimes … some states have different processes and some don’t allow it at all.
Pardoning is typically also an admission of guilt…ie you’re guilty of the crime, but your sentence is completed, so you still have it on your record.
With that said, I have absolutely zero clue how all that works with these blanket pardons where they’re just given out to thousands of people at once.
Absolutely! That’s probably the best compromise to make it easier without risking something breaking or not working as expected