• 0 Posts
  • 21 Comments
Joined 5 months ago
cake
Cake day: September 20th, 2025

help-circle





  • For me, I have three proxmox nodes that are configured to restart VMs and LXC containers if a host goes offline. There’s a Palo Alto pa-440 for my fw/router and a brocade switch (they were something work gave me for practicing for a network exam).

    The nodes, Palo, brocade, and AT&T modem are all on two UPS 1500va systems along with my wifi ap. Run time in case of power loss is around an hour.

    I’m this close to getting a comprehensive shutdown script working from a raspberry pi that is triggered if there’s power loss (most UPS systems have some capability to trigger scripts on a host that’s connected to the UPS’s console port).

    If I can get that script working, the battery backup will run a PI for several days.

    Back on the redundancy side, I host two PowerDNS systems in the proxmox cluster along with a 3 node/LXC container Vault.




  • I tried terraform for my three node proxmox cluster and all the providers were shit (and one was written by a for-profit prison company).

    I ended up just deploying manually, but I do heavily use ansible for things like let’s encrypt wild card cert renewal/installation and patch management.

    I love terraform when the providers are good - my #dayjob is predominantly spinning up hybrid cloud/global AWS environments and we could not do what we do without tools like Cruft, Terraform, and Ansible.






  • Maybe a controversial take, but I like pihole for blocking only - I have a pair of powerDNS servers set up for my internal name resolution. They recurse to Pihole, but can fall back to internet DNS servers if Pihole isn’t responsive.

    I tried pihole for local resolution and found it to be a fairly large pain to automate. Plus kubes has PDNS hooks for auto-updating DNS entries.




  • plateee@piefed.socialtoSelfhosted@lemmy.worldCams, anyone?
    link
    fedilink
    English
    arrow-up
    3
    ·
    3 months ago

    Unifi Protect is what runs on the CloudKey/NVR physical device - you don’t need to have it go through to the Internet.

    Remember, for better or worse Ubiquiti is positioning themselves as SMB Enterprise security - some companies won’t want their footage to be accessible outside their network.



  • plateee@piefed.socialtoSelfhosted@lemmy.worldCams, anyone?
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    1
    ·
    3 months ago

    This is maybe controversial, but I love the Ubiquiti security stuff. Cameras (interior and exterior) doorbells, etc, it’s all great. Pricey, but you get what you pay for.

    And the data can stay local or be accessible via their services.

    I chose to go local only, grabbed their UNVR and populated it with 4x 2TB drives and it has enough space to handle 7 cameras HD history for about a month.