• 2 Posts
  • 49 Comments
Joined 10 months ago
cake
Cake day: April 27th, 2024

help-circle

  • It’s a bit unconventional maybe, but I vote simple-nixos-mailserver - IF you are curious / willing to learn nix. It’s essentially just sanely configured dovecot, postfix, rspamd.

    My config for those three combined is about 15 lines, and I have never had an issue with them. Slap on another 5-10 lines for Roundcube as a webmail client.

    Since it’s Nix, everything is declarative, so should SOMETHING happen to the server, you can be up and running again super quickly, with the exact same setup.



  • We expose about a dozen services to the open web. Haven’t bothered with something like Authentik yet, just strong passwords.

    We use a solid OPNSense Firewall config with rather fine-grained permissions to allow/forbid traffic to the respective VMs, between the VMs, between VMs and the NAS, and so on.

    We also have a wireguard tunnel to home for all the services that don’t need to be available on the internet publicly. That one also allows access to the management interface of the firewall.

    In OPNSense, you get quite good logging capabilities, should you suspect someone is trying to gain access, you’ll be able to read it from there.

    I am also considering setting up Prometheus and Grafana for all our services, which could point out some anomalies, though that would not be the main usecase.

    Lastly, I also have a server at a hoster for some stuff that is not practical to host at home. The hoster provided a very rudimentary firewall, so I’m using that to only open necessary ports, and then Fail2Ban to insta-ban IPs for a week on the first offense. Have also set it up so they get banned on Cloudflare’s side, so before another malicious request ever reaches me.

    Have not had any issues, ever.



  • Hi. I’m German. I bake my own bread. My parents bake bread. My brother bakes bread.

    We freeze the bread after it’s cooled down from being baked.

    You know why?

    Because that way, it’s great even weeks later.

    Sure, nothing beats bread that’s just out of the oven. But honestly, I think I prefer bread that’s been frozen and reheated even to bread that’s only 1-2 days old.

    Waaaaaay Less stale.











  • Inhave the original A5 from Supernote, and while the device still works just fine after 5 years (also I think I never had to change a nib even once), I’ve grown disillusioned with the company.

    It came down to the A5 or the rM2 for me hack then. I liked everything about the A5 better, EXCEPT that the rM2 allowed you to mod it and access it via SSH.

    The A5 runs on a slim version of Linux. So I asked Supernote if they’d consider opening SSH for users. And they said “Yes! It’s actually in our roadmap for the next release!”

    And that’s been the answer I’ve been getting for the past 5 years. The last update for the device was about 3 years ago.

    I love that the tablet is running plain Linux, but it suuuuuucks that I can’t use it to its full potential because the sync options suck.