PfSense is another choice, if you want something with a more polished UI.
- 1 Post
- 35 Comments
grehund@lemmy.worldtohomelab@lemmy.ml•Docker Homelab - Docker Socket Security Risks and Docker-Socket-Proxy [help/discussion]
2·7 days agoThe risk is certainly lower if you’re not exposing services to the internet, but that’s not the only way to end up with a rogue container. I use docker-socket-proxy for most of my stacks that need socket access. It can sometimes require a little bit of troubleshooting to understand what services you need to proxy, but I’ve had a pretty good success rate. Reading the logs from the socket-proxy and referring to the Docker Engine API documentation will help you to understand what Services you need to enable in the socket-proxy config.
Are you interested in the networking side of self hosting? If so, you should get a better router, something you can run OPNsense or similar on. There are other “options”, but they’re workarounds that avoid fixing the real problem.
grehund@lemmy.worldto
Technology@lemmy.world•Israel’s IDF Bans Android Phones—iPhones Now ‘Mandatory’English
1031·5 months agoThey don’t want people installing GrapheneOS on them.
grehund@lemmy.worldto
No Stupid Questions@lemmy.world•How do I make pictures less blinding if I prefer dark apps?
4·6 months agoIf possible, don’t play in a completely dark room, have a dim light on, so your eyes are not as shocked when hitting a white screen.
You might want to check out the self-hosted communities on Lemmy for more info.
If you want to use Cockpit, the 45drives Cockpit modules make dealing with SMB easier. I think TrueNAS is a better option. If you want more flexibility, then Proxmox VE is a popular choice.
grehund@lemmy.worldto
World News@lemmy.world•US and Russia begin talks in Saudi Arabia on Ukraine ceasefireEnglish
3·1 year agoI think I’ve seen this one before.
grehund@lemmy.worldto
Pi-hole@sh.itjust.works•How practical is it to block everything by default?
5·1 year agoUntrusted devices should really be on their own VLAN. You will have much better control over them and their ability to reach out to the net, or gather info on your network and other devices. Some IoT devices have their DNS hardcoded, so they will ignore your Pihole anyway - you will need to redirect the DNS with outbound NAT to combat this.
grehund@lemmy.worldto
science@lemmy.world•Once named world’s ugliest animal, blobfish wins New Zealand’s fish of the yearEnglish
16·1 year agoI can see another John Oliver episode incoming.
I don’t have one myself, but several of the guys on YouTube use them. See “The Home Automation Guy” or “Smart Home Solver“. I can’t remember the brand they use.
grehund@lemmy.worldto
Selfhosted@lemmy.world•[problem] Running my server impairs traffic on the networkEnglish
15·1 year agoIf you’re not using a VPN, it’s possible your ISP is throttling your connection when it sees p2p traffic. Just another thing to look into.
grehund@lemmy.worldto
Technology@lemmy.world•France is about to pass the worst surveillance law in the EU.English
32·1 year agoAnd Sweden, just this week.
Worth noting that this is from 2016.
grehund@lemmy.worldto
Music@lemmy.world•What are your thoughts on “The fat of the land” by Prodigy ?English
161·1 year agoGood album, so many great tracks.
grehund@lemmy.worldto
Gardening@lemmy.world•Any gardeners in the Southern hemisphere?English
1·1 year agoYep, Aussie here. Not a very good gardener though.
Smarter Every Day, Veritasium
Before you move to Linux, have you had a look at OpenCore Legacy Patcher? It will allow you to install newer versions of MacOS on your unsupported MBP. Mr Macintosh’s channel on YouTube is a good resource for this.
Have you considered other approaches, such as Tailscale or Cloudflare Tunnels? I think you’re complicating things.






It really depends on which Socket Services the container requires. If you have a lot of containers that all need the same set of Socket Services, you could potentially use a single socket-proxy to serve all of them (in theory, I think).
I usually run one per stack, sometimes more if I have a container within my stack that requires more/different Socket Services to the other(s).
I’m not a docker expert though, so I’m not sure I can say what’s recommended. If you find/get a more authoritative answer on this question, I’d be interested to know.