Mod alt of @[email protected]

If you need to DM me, please reach out to me there, this account is primarily for dealing with reports.

  • 0 Posts
  • 73 Comments
Joined 4 months ago
cake
Cake day: June 6th, 2026

help-circle











  • Up until the point the resources available (CPU/ram/storage) become a problem.

    That said, managing those apps as installations can be troublesome, which is why people like podman/docker. Updates are more contained, system updates don’t break services, and vice-versa.

    A more comprehensive option is to use Proxmox or similar to manage services as a combination of Virtual Machines, LXC’S (Linux containers), and maybe podman/docker on a VM. Note that Proxmox techincally supports importing a docker container as an LXC, but this is a one-time action. Not recommended. (EDIT: For the record, there is a Proxmox on pi effort, but its community supported not Proxmox supported as of the last time I looked.)

    Navidrome and pihole are the easy ones on that list also. Jellyfin itself is easy, but you aren’t going to be transcoding video on the fly, so make sure its in a format that is friendly to all of your devices, transcoding in advance if needed.





  • Secure enough I suppose.

    f2b at the FW, auth with MFA for anything exposed, anything local only has restricted access at the FW level, with exposed (via proxy) and local-only (separate proxy) on different vlans. Each service is (typically, with some exceptions) an LXC, with additional rules and templated out based on use case. The few cases where docker is involved is local-only and that has its own vlan with additional rules.