I really don’t think it’s the devs driving these decisions…
I really don’t think it’s the devs driving these decisions…
Ok so it is fully qualified then? I’m just confused because it sounded like you were saying I wasn’t using the term correctly in your other comment.
Hmm, my understanding was that FQDN means that anyone will resolve the domain to e.g. the same IP address? Which is the case here (unless DNS rebinding mitigations or similar are employed) — but it doesn’t resolve to the same physical host in this case since it’s a private IP. Wikipedia:
A fully qualified domain name is distinguished by its lack of ambiguity in terms of DNS zone location in the hierarchy of DNS labels: it can be interpreted only in one way.
In my example, I can run nslookup jellyfin.myexample.com 8.8.8.8
and it resolves to what I expect (a local IP address).
But IANA network professional by any means, so maybe I’m misusing the term?
TIL, thanks. I use namecheap and haven’t had any problems (mikrorik router).
If you have your own domain name+control over the DNS entries, a cute trick you can use for Jellyfin is to set up a fully qualified DNS entry to point to your local (private) IP address.
So, you can have jellyfin.example.com point to 192.168.0.100 or similar. Inaccessible to the outside world (assuming you have your servers set up securely, no port forwarding), but local devices can access.
This is useful if you want to play on e.g. Chromecast/Google TV dongle but don’t want your traffic going over the Internet.
It’s a silly trick to work around the fact that these devices don’t always query the local DNS server (e.g., your router), so you need something fully qualified — but a private IP on a public DNS record works just fine!
Travel expense reimbursement — though many companies have a “no receipt required if under $xyz” policy.
How do we get everyone angry.
This is the problem — taking away my coffee makes me angry, but I’ll be too tired to do anything about it.
Add to that photo editing (as much as GIMP is great…). I would guess DAW and video editing would fall under that category, too…and good luck finding many AAA open source games.
Come see the vise grips inherent in the system! Help! Help! I’m being drill pressed!
Perhaps microwaving for significantly longer, at a low power level, would be safer and result in higher success/yield?
Just stick to elements lighter than iron and you’ll be fine.
Handy back-of-the-envelope is that a year is about pi*10^7 seconds.
Also…hate to be the guy to mention leap years but…
It’s mostly so that I can have SSL handled by nginx (and not per-service), and also for ease of hosting multiple services accessible via subdomains. So every service is its own subdomain.
Additionally, my internal network (as in, my physical LAN) does not have any port forwarding enabled — everything is over WireGuard to my VPS.
My method:
VPS with reverse proxy to my public facing services. This holds SSL certs, and communicates with home network through WireGuard link configured on my router.
Local computer with reverse proxy for all services. This also has SSL certs, and handles the same services as the VPS, so I can have local/LAN speeds. Additionally, it serves as a reverse proxy for all my private services, such as my router/switches/access point config pages, Jellyfin, etc.
No complaints, it mostly just works. I also have my router override DNS entries for my FQDN to resolve locally, so I use the same URL for accessing public services on my LAN.
The one I’ve heard replaces “brains” with “money.”
Nah, no hard feelings towards the retail folks, they’re doing what they’re supposed to. It’s just that I wish the corporate incentives were different so it felt more like the staff were trying to help.
My only complaint with microcenter is that the commission in incentives come off as extreme. Like I will be walking around with something in my hand and a rando will come up to me, say “hey there boss, lemme just slap this on that for you,” and proceed to put a sticker on it with their ID. Not a big deal, but palpable, and makes it harder to just browse.
Yeah, I get that people feel like they have so little control over their lives that they feel the need to generally be passive aggressive assholes to people they deem unworthy, but this is just an overall dick move. Having working public/municipal plumbing is a good thing.
Getting TLS certs will be complicated
I just use Let’s Encrypt with a wildcard domain — same certs for public and private facing domains. I’m sure this isn’t best practice, but it’s mostly just for me so I’m not too worried :)
If I wanted to give it a bold facelift I’d just use the top one and remove the letters. Gives it an arrogant, “if you have to ask what this is…” vibe, which is probably a good thing for them.