What’s the problem then? I’m living in a country where there is no return period 🫣
What’s the problem then? I’m living in a country where there is no return period 🫣
Really weird warranty 45 days, are you sure these are not fake?
I have some of their ssds, and the warranty is 5 years
Bitwarden, keepass, pass
I believe it’s yes for all
Even raspberry pi 4 doesn’t run on 3-4w, it’s probably for the older models and zeros
Rpi4 is more like 5-6w, and 8-10w theoretically
RPI5 is 12-15w theoretically
Rpi5’s power supply is actually 27w, my thinkcentre’s power supply is 60w
Rpi5 has a 2.4ghz 4cores
My thinkcentre has 2.4-5ghz 8cores 16threads
Also, arm is fun, but it’s a headache to selfhost a lot of stuff on it
And really, I moved from RPI hosting to x86-64, I didn’t know some apps like jellyfin, or elk, or basically anything can open instantly. Even nextcloud is working pretty well
And you can put an ssd inside, or even two, or even do some soldering a put 3 ssds inside
I’m even starting on RAM which you can buy and replace
Basically zram is compression inside ram
Or even a thinkcentre, I got mine for less than $300 with 36gb ram, 1tb nvme ssd, and es i9
It was even closer to $200, and I had a plan to make a cluster out of these, but one this thing is powerful enough to do like anything, so I dropped the idea
Edit: also, about the power consumption, it’s very similar to rpi5 and at the same time can do so much stuff
Nixos ❄️
I’m actually not from the “close everything, don’t open ports, always sit behind cloudflare” camp
We selfhost so we can use and share our services
There are other things we can practice instead of just isolationism and keeping everything as simple as possible
There are many ways to do many things in nixos
For updates you can do automatic updates
Also, there are many deployment tools, like deploy-rs, morph, colmena, bento. They all have different approaches. Some you use ssh to deploy a remote system. Some just fetch the configuration and autodeploy it.
There are many ways how you can play with this. So you can disable sudo, and deploy with ssh only from some or a specified ip. Or you can keep ssh for root disabled and just deploy home-manager. It’s really a lot, you imagination is the only limit
P.s. or you can just generate an image from a trusted machine, and flash it onto the device you want, unlimited number of ways
I’m a Nixos user, I wouldn’t be much help unless you do Nixos. But it’s a whole new rabbit hole which would take you months/years to learn and setup 😅
What I can say, you can do “access from home network”, “access from VPN network”, “1fa/2fa from the internet” OR “access for / and /api, but 1fa/2fa for stuff like /admin, /admin-settings, or just /login or /logged-in”
Fail2ban is fun, also maybe have a look at crowdsec
Notifications on system file access
Notifications on root login/sudo
Declarative OS, tmpfs root, disabled sudo
Bastion server, but right now I don’t have a proper router to do it at home
Yubikey, or a separate phone on Graphene OS for otp, keys, etc
Authelia + fascist fail2ban (or some CSF)
Most of these are pretty normal, but usually you don’t do them all at once 😄 also, I don’t really like hiding my services from the open internet, authelia is fine tuned to let people only access what they are supposed to. And regular users of my server usually don’t notice that I even have it
You still should set two dns servers… Two piholes/adguards
That’s why you usually have two piholes, or adguard homes
And can even synchronize them
Nixos, brothers and sisters, show yourself 🥸
Check if you can find yggdrasil useful
Or just tailscale(headscale), or wireguard
Lenovo thinkcentre? 🤔
The op probably meant removing one key and adding another
No problem, the world of pain is my hometown
https://downloadmoreram.com/
And maybe CPU, and also need some good old fine tuning