On my home server (just an older desktop PC)

- qBittorrent for "Linux ISOs"

- Jellyfin so I can watch/read/listen to my "Linux ISOs"

- Tailscale so me, my family and friends can watch/read/listen to my "Linux ISOs" from anywhere in the world

- Self hosting my photo albums. Immich is a handy choice for this. Very useful for personal photos you don't want to trust to strange tech companies.

- Gitea for self-hosting git repos for some personal projects I have not open-sourced.

> - Tailscale so me, my family and friends

If you're privacy conscious, please be aware that Tailscale by default is creating behavioral metadata from all of those computers for the Room 641As of the world about everything you do on your supposedly “private” network: https://tailscale.com/docs/features/logging

“This includes real-time events for open and close events for every inter-machine connection (TCP or UDP) on your network.”

https://tailscale.com/docs/features/logging#opt-out-of-clien...

Yeah for sure, but good luck getting mom and dad to edit `%PROGRAMDATA%\Tailscale\tailscaled-env.txt` at all, much less do so correctly.

o no, they’re seeing open and close events between my laptop and my vps and database. the fbi will surely bring the hammer down on me

Why don’t people just use Wireguard?

Once you get to N = >10 devices, and expect some degree of decentralized communication between them you find yourself maintaining N^2 entries. Every change to the set of public keys, require you updating N entries. Things get worse once you want consistent rules on what-device-should-access-what.

I initially used WireGuard, but as my home lab scaled, it became unwieldy. Some people could work around these limitations with bash scripts, but if you have an heterogeneous environment (esp iOS clients), making programmatic configuration changes to WireGuard becomes trickier.

Today I use Tailscale (with Headscale as the control plane) for all users, and WireGuard as a emergency access to key servers.

Does headscale fully replace the corporate tailscale network? I've been looking at replacing my home wireguard if I can self-host tailscale but haven't had the free time to really figure out how much privacy I can retain by using headscale.

It definitely can. By default it ships with the normal Tailscale DERP map but it also ships with a default-off DERP server. You can turn that on and set your DERP map to only include that one server (or you can fan out a couple if you want). At that point you're not using Tailscale assets at all.

Thanks! Once I have some more time this winter I will take a look at using this to replace my wireguard setup.

For much the same reason most people choose Windows or Mac over Gentoo. Most people set up something like Tailscale to accomplish something rather than create a project and ongoing maintenance burden for themselves, and setting up Wireguard is not terribly friendly to the uninitiated.

WireGuard is one of the easiest things to set up. The total amount of reading you'd need to do to set up WireGuard amounts to half of a page. I spent more time figuring out what firewall rules are needed for WireGuard traffic than actually setting up WireGuard, it's so simple.

I'm going to disagree with you there. It's been a while since I set up anything with WireGuard but "easy" is not a word I would apply to it. A simple tunnel or VPN configuration was close to that but a network comparable to a Tailnet got pretty involved to do properly. By contrast Tailscale was effortless.

Needing to do additional things like figure out firewall rules is exactly what I'm talking about. I enjoy tinkering for fun most of the time but I'm generally looking to tinker on something specific, not every step along the way.

AI has mostly removed the difficulty of Linux configuration for beginners

It's also removed the difficulty of configuring a mikrotik router as well. Mikrotik has a cloud router instance which is much easier to deal with I think than linux. Mostly because there's a UI interface for Mikrotik that makes it a little easier to inspect what's going on.

One of my pet projects I need to get back to is an SDN to make configuration for mikrotik routers easier (particularly with VLAN's, wireguard or VPNS, or routing configuration between ports).

Winbox is nice in a sense because it tells you the true configuration. But what I really want is something that can start with a network diagram (e.g.) and then get the current state of the router, and then validate that against the network config.

How does wireguard helps you with NAT traversal? Reliable NAT traversal on top of wireguard is their moat.

> Reliable NAT traversal on top of wireguard is their moat

And a damned good one at that. I can spend five minutes on a (family) nontechnical user's device and set it up to be able to access the parts of my network it needs to get to, and it's easy enough to use that I can walk them through the troubleshooting over the phone if it ever goes awry. Regardless of where they are or I am.

> How does wireguard helps you with NAT traversal?

It does not. You need a public endpoint, but presumably the $5 VPS or the "homelab" provides that, or it's of little use for things like email, Web, or game servers.

This. Wireguard is a single short text file with keys. It's simple and robust, and setting it up on a client like a laptop or a phone is equally easy. Tailscale or Headscale (the self-hosted version) are massively overengineered for something as basic as accessing your Linux ISOs from your phone.

I'll argue though that the convenience and autonomic management make a big difference in that case because if your Wireguard configuration is busted you might need a working Wireguard to log into your homelab and fix it.

Of course the default behavior that Tailscale forces you to reauthenticate periodically can cause the same problem unless... you turn it off. You know things like that always happen at the worst time.

It’s also entirely impossible to use by itself when both devices you’re trying to connect are behind a NAT or some other restricted network.

That's true, but the $5 VPS should have a public IP, either v4 or v6. Other devices can route their traffic through it, and then every device can reach other devices, regardless of NAT.

It better have v4 if you ever want to use it while traveling. v6 is still not widely enough available on public Wi-Fi networks and even many mobile operators.

On some OSes you could probably also use some additional 4->6 tunnel, but that probably doesn't work stacked under Wireguard on iOS and Android.

But I'd think at that point there'd be arguments for using that vps to instead facilitate a p2p connection... right?

Yes, but only if the VPS becomes a bottleneck. Otherwise self-hosting Headscale does not seem worth it. My guess is that the threshold is at dozens of devices in simultaneous use.

That’s a bit like telling somebody to take a ship instead of an airplane: A nice idea, but not everybody lives at the sea.

I started with Wireguard first, however the setup / maintenance makes it a way bigger project than simply using Tailscale.

arguably that's the entire point of tailscale -- ain't gotta worry about the logistics

[deleted]

good alternatives that do near the same thing?

Netbird, been using it for about 6 months now with no complaints. Fully OSS, mobile clients, etc.

self-hosted open source alternative Headscale/Headplane. Uses the Tailscale client without their SaaS being involved.

Same! Although, for Headplane you may need at least 1GB of RAM.

Headscale turns the $5 VPS into the thing that connects my laptop to my other compute resources while I am out and about.

What's the advantage of Tailscale anyway? I guess ease of use compared to say setting up IPSEC? I haven't played with it yet but from what I read it's just wireguard with a bit of proprietary "one click and sell your soul" magic around it?

Tailscale automates wireguard key distribution and then layers routing, DNS, network ACLs, and other niceties on top.

For example, you can create a token that grants VPN access with inbound SSH as the only allowed traffic. Add that as a secret to GitHub Actions and now you can ad-hoc debug failing CI via `tailscale ssh`.

It's a VPN essentially but just works easily and affordably. We don't stress on managing keys, secrets etc and it's SSO friendly.

How do you know their client won't send them the metadata anyway?

It is open source

Sanctum! Entirely free and open-source and PQ-secure.

https://sanctorum.se

tl;dr

> no mobile clients

I’ve no need for them personally so they don’t exist in the official repo.

I know of some people however who hacked up their own using the sanctum library (https://github.com/jorisvink/libkyrka)

That is a bummer.

Netbird has a self hosted option

You can ask an LLM to set up a wireguard network for you with an idempotent bash script to deploy everything. You'll need a $5 VPS to bounce everything through. Works an absolute treat.

Is that the prompt you would use, or is there more to it?

The wireguard docs are pretty good, and it's probably worth it at least a little to actually understand what it does.

https://www.wireguard.com/quickstart/

Actually I wish they would be a lot more verbose and explain the details a little bit better.

Yep and the LLM can help explain, but it is actually super straightforward. Public key cryptography and the text file configs are tiny.

[dead]

You could try with that as a prompt. I have a repo set up with all of my sysadmin scripts and so the LLM had that as additional context.

[deleted]

Netbird!

I saw all the Netbird recs here so looked into it briefly. Depends I guess on what you use Tailscale for. Tailscale Funnel is easy and stable. Self-hosted on Netbird is ... a bit more involved.

Definitely a place for both services, IMO.

i literally do not care about that metadata

Sad

Why? It's TCP/UDP connection data for troubleshooting you can turn off. No privacy issue there.

> connection data for troubleshooting you can turn off. No privacy issue there.

You can't turn off the centralised element of Tailscale though, i.e. IP tracking etc.

So for the privacy conscious Tailscale remains a poor choice. Especially as they operate under US jurisdiction:

     - "Tailscale US Inc., a Delaware corporation with registered address at 447 Sutter St Ste 405 #543, San Francisco, CA 94108, USA"
     - "For any dispute not subject to arbitration you and Tailscale agree to submit to the personal and exclusive jurisdiction of and venue in the federal and state courts located in New York, NY".

So CLOUD, PATRIOT and friends very much apply to Tailscale.

You may jest "but its only metadata", but you can do a lot with metadata, especially if its all nicely attractively centralised like Tailscale.

I ran Headscale for a while, and now wireguard directly, but never really considered it to be more private.

What is Tailscale getting that my ISP and google/Facebook via their pixels and tracking scripts aren't?

> What is Tailscale getting that my ISP and google/Facebook via their pixels and tracking scripts aren't?

Tons more. A lot could be written about, but a few "for starters" things to think about:

    - The web is decentralised.  And a lot of the web trackability can be dealt with in a dozen different ways.  But Tailscale is centralised and all the data nicely structured (stable node keys etc.) and "ready to go" for metadata analysis.
    - Tailscale have "behind the firewall" visibility at a far greater level, it enables building of a topology map and associated flows.
    - Tailscale visibility is perhaps most concerning in relation to metadata surrounding mobile devices.  Where is the device ? Is it in use ? Is it near other devices (from the same customer / other customers) ? etc. etc. etc.
Yes, `--no-logs-no-support` exists for the Tailscale client — but that's per-device, per-platform inconsistent (as the docs show), forfeits support, and doesn't change the fact that coordination traffic, the DERP relays, and the control plane still run through Tailscale. You can't opt out of the centralized control plane at all.

I think you are overestimating how decentralized the web is. Tailscale (could) collect a different kind of data than e.g. Google, and I believe it's far less harmful for the average user. If you are a journalist or persecuted by a government then sure, Tailscale is bad news.

But if you think Tailscale is bad for mobile devices because they might be able to tell that you're near another Tailscale user, that is absurd. If you have a need to be physically untrackable, the only solution is to leave your tracking device at home.

> You may jest "but its only metadata", but you can do a lot with metadata, especially if its all nicely attractively centralised like Tailscale.

Like? What exactly could they plausibly do, that I should care about, if I otherwise have no reason to worry about these institutions?

"We kill people based on metadata." - NSA Chief Gen. Michael Hayden, 2014[1]

In case you were not aware, spooks have focused on metadata analysis over "full take" (data) analysis for a very long time because they are far more effective and require less data to analyse. This has been the case at least since the early 2000s with Stellar Wind but arguably even the Stasi worked this way -- they cared a lot more about who you were talking to than what you were talking about. The Snowden revelations in 2013 talked almost entirely about metadata-only systems that were being used to invasively surveil the world.

If your point was more "I have nothing to hide" then you can find plenty of articles online to disabuse you of that notion. There's even a Wikipedia article about it[2].

[1]: https://abcnews.com/blogs/headlines/2014/05/ex-nsa-chief-we-... [2]: https://en.wikipedia.org/wiki/Nothing_to_hide_argument

Can you be on the internet and avoid the collection of metadata that can eventually be accessible for the NSA or other TLA? You have an ISP which logs everything, same for your destination endpoint, and those logs are already being correlated.

Can I even hide from NSA level adversaries without employing extreme methods? Assuming "no", then for this particular threat model do the tools employed next matter?

There is some evidence that Tor has posed significant problems for three-letter-agencies in the past, so it's not like there is nothing to be done at all.

But there is a bigger point to be made: in my experience most privacy activists argue that taking an absolutist stance personally is counter-productive -- just because it is almost impossible to completely eliminate risks from your life does not mean you should give up and not try to minimise them. And of course, the goal for most people isn't to protect against targeted attacks (since that means you already need to take fugitive-on-the-run-level precautions), it's to avoid becoming a target in the first place.

Most privacy activists are already taking an absolutist stance.

Reality is, for normal people there's no point where worrying about spooks and taking actions to protect themselves is reasonable. As you say, there's nothing one can do against a targeted attack. But same is true for broad, untargeted sweeps - if they really care, they will find you anyway, and attempting to reduce your data exposure just flags you as an anomaly, making you more interesting, not less.

The whole "privacy vs spooks" threat analysis is not relevant to regular people.

What I mean to ask was related to the mention made above, that Tailscale shouldn't be used by privacy conscious people.

> If you're privacy conscious, please be aware that Tailscale by default is creating behavioral metadata from all of those computers for the Room 641As of the world about everything you do on your supposedly “private” network

Is Tailscale creating additional metadata that doesn't already exist in "concentrated" form with my ISP? As a regular person trying to live a normal "internet enabled" life (self hosting a few things, sharing things with family or friends....) are there alternatives to Tailscale that leave substantially fewer traces for "Room 641s" and other similar entities, and doesn't just move the metadata collection to the hosting provider or the ISP?

And finally, does disabling logging in Tailscale mitigate those concerns? After all Tailscale will always be a target for data collection whether they cooperate or not by virtue of where they placed themselves. Similar to Cloudflare probably.

My point is I don't care. It's not a thing worth caring about.

I don't argue "I have nothing to hide", even uttering this phrase is giving in to privacy paranoia.

In reality, I have plenty to hide. But those who I want to hide it from, don't have access to the metadata you mention - and those who do have access, couldn't give less of a damn about the things I want to hide.

That's a really uncharitable take. Yes there's client logging by default, but those who are privacy conscious probably also continued to read the very next few sentences in the same section of the docs you quoted, showing precisely how to opt out.

I picked up a new hobby of buying Linux ISOs from thrift stores. I usually get them for $1/each. Up to 300 now - all mine. Jellyfin is great to organize them

I have some Linux ISOs I ripped myself, but it can be especially hard to find older ISOs from other countries - you usually can't find them on normal websites. It's really nice to have them on my own server and not worry about them disappearing someday.

I’ve been collecting a lot of post-war Italian neorealism Linux ISOs and running a DHT indexer has made it pretty easy to find distros that may be out of print.

First I've heard of this DHT indexer concept. Is this bitmagnet? What kind of resources does it require? Thanks for any info you can provide.

It’s so hard to find drivers for those

Vittorio de Sica's Ladri di biciclette is a Linux ISO I can recommend.

I used to have a substantial collection of very rare Euro/US short and performance art films on DVD that were lost to the sands of time during a period of my life where my work led me to be mostly nomadic. In retrospect, I wish I would have ripped the collection onto a hard drive as most of them are completely irreplaceable now on DVD.

[deleted]

$1 won't get you Linux ISOs up to modern display standards. Great if that works for you but the high end is more like $20+ (emphasis on the +, taxes and shipping not included) per Linux ISO so its understanding why many might prefer sharing them digitally. And that's before getting into cases where the Linux ISO vendors don't even want to give you the specific version you want.

Did you see the 'thrift store' part of his comment? I do the same thing as him, and depending on the location around town, an ISO on a DVD can be as little as 50 cents, and a modern Linux ISO on bluray, including 4K (though rare I see those) are rarely over maybe $3.

Yeah, garage sales are another place. you can get multiple for a buck :)

Especially those "one package wonder" ISO vendors, $20 is steep.

Problem is the resolution. I don't want to experience paid 480p in a world of free 4k.

Blu rays aren't bad either. The glory days were back when Netflix was cheap and there was an oversupply (in that era I built up a library of hundreds), but even today you can get most things in 1080p for $10 or less.

If you don't think 2 hours of professionally produced content is worth $10, well that's why AI isn't the only thing destroying art and culture.

The issue with Blu-rays is they are costly to rip. Basically, the only software that let you do it right now is MakeMKV, and it's proprietary. I believe that the VLC team is working on some open-source solutions, but last time I checked, it was only able to read old Blu-ray (which is understandable, they have to care about potential copyright and drm issue, unlike the people behind makemkv).

So if you want to rip recent Blu-ray, you will need to buy makemkv (they do have a 1-month trial tho). But worse, if you want to rip 4k Blu-ray, you will need a specific br-drive that makemkv support (as I understand, they make custom / modified firmware for some drives, allowing to read the protected data). The issue is that there is barely anyone still making br drives and whenever makemkv support one it goes out of stock and/or become extremely expensive on the second hand market.

This is really annoying me because I know this is the end of the physical market for movie. I fully expect Blu-ray to completely die off in a few years. Movie will probably only be available through streaming services, which means it will be harder and harder to get a good quality encoding. With recent codecs (av1, h265, will see how av2 does), the quality that streaming services is okay, but we are far from what a full Blu-ray dump allows today.

MakeMKV has an effectively perpetual free trial right now. It's not like old shareware were you have to pay after a month but rahter that you have to feed it a new free activation key every month and maybe wait a couple of days for one to be posted.

That can change (and the official communication is that its only free while in beta) but my guess is that the free beta is the main thing holding back alternatives. MakeMKV does solid work but it's not rocket science and a lot of parts (like all the complementary LibreDrive / UHD firmware work) doesn't even have a paid license check at all.

> I fully expect Blu-ray to completely die off in a few years.

I don't. It might continue to shrink and thereby get more expensive but the distributor market is still very healthy and has more active competition than movie production itself. The biggest danger is disc production but I don't think its impossible to shift that over to a BD-on-USBFlash or whatever else is convenient if needed.

Maybe, just like Adobe products recently, someone should vibe code an alternative to that blu-ray ripper...maybe even you.

I'm back in to collecting physical media as well. I get my wife to use her Facebook account to find stuff on marketplace. Lightly used bundles can get movies down to like a dollar per.

1080p doesn't really say much when that could be an old DVD-era master with questionable color correction crammed onto a BD25 disc with other features/extras vs a modern archival-quality master professionally encoded to 40+ GB.

It's rare that the latter goes for < $10.

I hate blueray. At least for having physical copies. Too many times I've tried watching something I own only to have it fail due to my player not having current decryption keys. Perhaps it's more of a player issue and less of a disc issue, but it's still a problem with the overall format.

The one time I actually bought a Bluray, I couldn't play it because of fricking Region Coding. Like this is the 2020s and you still have to deal with that BS?!

MakeMKV hasn't failed me yet. As always, only people fully abiding by corporate rules suffer.

In France many public libraries let you rent them for free (or a ridiculously low annual subscription); you take them home, copy them, return them, and it costs nothing.

And it is legal to do so ! We pay the "copie privé" tax for that reason.

Some of ours in the US even have video games. The one I go to even has tools and all sorts of other interesting physical objects. People really need to visit their libraries, they’re already paying for it via taxes.

Same with USA. I was surprised at the variety of platforms supported.

Hmm, public DVDs I know often have read errors.

but you trust a random torrent upload more?

at least with the library DVDs I can be reasonably certain the weird artifact is not embedded malware, just scratches

What? Rent linux iso:s for free? Good deal!

glad to hear I'm not the only one!!!

a few months back I opened up a streaming service that I pay for to watch a old TV show. I was _enraged_ to find out that they put ADS WHERE COMMERCIALS USED TO BE. I thought the whole point of paying was to avoid ads!

so now I visit my used Blu-Ray/DVD store about once a month. they always have buy two/get one free, and the prices are ridiculously low.

is it a better solution? I don't know, but I do know that I don't have to watch those ads anymore.

[dead]

I started picking them up from the library. Goodwill wants like five bucks a disk now. Library has them for .25 to a dollar each. Or free if you just check them out.

What kind of thrift store sells these? In what country?

I suspect "Linux ISOs" are not actual Linux .iso images but ~pirated~ movies, music, and digital books ;)

Joking aside, a few early commercial Linux distro (Red Hat, Yellow Dog, SuSe, Corel Linux) had really nice packaging and media artworks. I'd love to collect them.

Yes, seriously, my intro to linux as a kid was seeing the slick Red Hat boxed media on the shelves at CompUSA.

No way!

ding ding ding

ISOs of what, music or video?

movies, tv, and occasional audio books. A good blueray reader costs a bit but it is worth it to have them legally

Thrift stores? Really?

Yes there’s usually a good cache for very cheap though most are scratched up

1000% percent!

I go to a local game exchange place, they have all kinds of DVDs and Blu-Rays for dirt cheap.

absolutely. whole walls of old movies, music, whatever.

the really good stuff eventually goes, but there is often a lot of pretty dang good media there too.

check for scratches, tho

psst, they're talking about movies

is this an internet secret code I am missing ?

It's even in the Urban Dictionary [1]:

> Linux ISO: A codeword for copyrighted material shared without permission, usually over P2P networks.

[1] http://linux-iso.urbanup.com/2782626

Many Linux ISOs are distributed via torrents.

Ask yourself what other types of media can be had on popular torrent sites.

The two things that torrents are best at are downloading Linux ISOs and pirating content. So using qbittorrent to download Linux ISOs is usually code for piracy, since torrenting Linux ISOs is legal and piracy is not :)

Piracy is legal if you're big enough

I think that's called being a privateer, you just need the right papers from the king!

[dead]

[dead]

In my neck of the woods "Linux ISOs" is a euphemism for porn.

It is generous of you to share your "Linux ISOs" with your family and friends.

"Linux ISOs" is just anything pirated in general.

I’ve usually heard it as a euphemism for torrents specifically, since these would be one of the main legal uses of torrents.

All my Linux ISOs are actually FreeBSD.

Mine are temple OS

[dead]

First time I heard this. When did it start? It's pretty funny.

Very common on Slashdot fifteen or twenty years ago. The Pirate Bay trial was a big story back then, for instance, and there was advocacy from the copyright cartels to ban the bittorrent protocol. Another hot story was when Comcast dropped customers for using too much data despite being on “unlimited” plans, justified because only a pirate would download so much. Hence, “You can’t do that, I use bittorrent to download my Linux ISOs!”

It really was common in the early 2000s for Linux distros to provide torrent downloads. Internet speeds were such that downloading peer‐to‐peer could be significantly faster, and (probably more importantly) it saved the distro mirrors a lot of bandwidth. I think this practice has mostly died out among newer distros, but distros from the era such as Ubuntu or Arch still provide them.

Thanks!

[deleted]

GitHub also has free private repositories, but I guess your server has a much better uptime than them.

> Self hosting my photo albums

I used to do this, until I learned the value of offsite backups.

Learn from my mistake (if you aren't already :) ).

I use backblaze with restic. Got about 300GB up there, fully encrypted, keys in 1Password.

My exact setup. Main repo on a second internal disk, one replica on an external disk, second replica in backblaze. Replicas are kept in sync with `restic copy`. Backup integrity gets checked automatically with `restic check`. It all works great.

Same here. It's been very reliable for me.

I have an encrypted offsite backup. A lot of people I know with home servers work out a deal with a family member to have cross-backups with each other.

Sadly I don’t have a family member that I can trust with that, but I do put an encrypted copy on AWS glacier and I have an encrypted volume in Dropbox.

Yeah I do something similar, a local backup on an external drive that mostly lives in a different place and a last resort backup in glacier

> encrypted volume

This.

What ist your plan if you die? Do you have a spouse that will be able to read your-and-your-spouses data?

I am on the older side and do not plan to be in another long term relationship. not a helpful answer maybe

Yes, my spouse has access to my password storage, which has all the decryption keys. Whether she remembers how to do it is a different question. :). Maybe I should write it down, or show one of my kids...

you should probably include the instructions in your estate document kit

That's why you always practice 3-2-1 with important data.

My photos are on: Captured devices(phones, camera). Immich on my homelab, and google photo(which is lossy, but better than nothing).

The issue with this is that Google gets a copy of your photos. If you really want to use Google or other cloud storage, you should encrypt your files.

Proton Drive may work better here?

I am honestly not sure. I use GG photo because that what i use first and i was too lazy to investigate better deal. Also, i know Google does really well at keeping my data available, which is what you want for backup.

One mistake with your google account and poof, everything is gone.

Granted, an average person most likely will never mess up, but in google-land the surface area where to make that mistake is quite large.

Luckily i have 321 back up, don't i ?

I didn't check ToS of proton drive, but in my experience, every cloud storage has requirement about what kind of data is allowed to store(after all, they dont want to accidentally store illegal stuff).

I just purchased a hetzner storage box and used claude to configure kopia to backup to it.

I then tested restore vis kopia desktop onto my desktop to validate restore works.

13 eur for 5tb is more than enough for immich backups for my personal use.

What happened?? As someone who is currently doing this without backups…

I moved homes and damaged both drives because they traveled together.

I have mine in a RAID 5 setup rn because I was scared about that, but I definitely should set up offsite backups, it’s just so expensive

Raid is not a backup :( For the really important data (photos, documents, ecc) a small 1GB raspberry pi + USB external HDD works great as a Borg server for daily backup, there is no need for a full NAS when you can store all important data in less the a handful of terabytes

A raid is one layer and one copy in a backup.

Inherently to inner copy it provides some redundancy.

Backups need more than one copy.

RAID is not a backup because anything happening within that file system happens to both drives immediately.

ZFS snapshots can help, but this is one layer of a comprehensive backup strategy.

both drives? Only 2 mirrored drives isn't really what a RAID can be.

Constructing a RAID5 with 4 drives provides failover and recovery if one of the drives dies.

You can have as much redundancy as you like on your RAID, but if you fat finger an rm -r it's all gone.

A real backup protects both against hardware faults and accidental deletion.

I’m not implying Raid 5 on its own is a complete backup.

Within a storage array though it does provide redundancy at that level, and generally speaking most people don’t access a raid or NAS at a shell level only where they drop rm -fr’s

Separate and offsite backups are non negotiable, however running a raid 5 locally can greatly reduce storage rebuild/restore time, if a single drive fails the rest of the raid continues to work fine until replaced.

A RAID 5 setup is more exposed to that. He had to damage all of his disks to lose all data, you need to damage two of your disks to lose all data

I use RAID1 so that each disk can be pulled and used as standalone.

HDD failure probably

Or a house fire, or flood...

Yeah. Which is why I use Ente.com. But I should have a offsite backup of ente.com copy self-hosted as well maybe.

That’s sad :( Where do You backup offsite now?

So not a $5 VPS

read the OP, they mentioned home servers too

Out of curiosity: why use Gitea for personal projects when you can put up raw git repos and run the git-daemon that comes with git? Super lightweight, really functional. Add _cgit_ if you need to be able to view the repos online. Simple and does not require upkeep like gitea (which seems to break with every update and is really heavy).

Ive been running a personal gitea instance for nearly 7 years now and have never had anything break with an update, sans user error.

If your server is 100W that's 72kWh a month. If your electricity average is more than 7 cents an hour then it's cheaper to run a $5 server.

N100/N95 idling at <5W and ~20W on full load while also quite performant

While it's probably the case for a desktop PC, a new mac-mini has an idle power draw of < 5W.

~10W is what my socket reports for regular use on the M2 Pro.

They are not cheap anymore, unfortunately, but at least you get much more performance out of them than you would from some $5 VPS.

$5 servers don't include a GPU for Jellyfin transcoding

Good luck finding a $5 server with enough storage for a decent Linux ISO collection.

usbx gives you 1tb for that which is enough unlike you're an archivist

i think usbx means https://ultra.cc/

I have a seedbox for Linux ISOs and then sync to my home NAS with Syncthing. That way I can use private trackers and get a healthy ratio.

How are you sharing tailscale with your family and friends? do you run the server yourself?

Tailscale is free for home use and lets you invite people to your network by email

[dead]

why not use just usbx for your "iso" needs - it costs $5-$15/month and might be cheaper than your home kwh usage and is less headache

qBittorent (vueTorrent frontend) , jellyfin, tailscale, readeck, cloudflare tunnels (should replace with something else), beszel

How many Linux ISOs are stored on your $5 VPS? One?

Like I said, this is on an old desktop PC that I shoved some spare SSDs into. I have a few thousand Linux ISOs on there. I have an rclone job running regular encrypted offsite backups as well, so that my Linux ISOs are safe from hardware issues.

How are you adding new Linux ISOs? Do you prune the ISOs you've already installed somewhere, or are they kept around to be re-installed?

> How are you adding new Linux ISOs?

With qBittorrent.

> Do you prune the ISOs you've already installed somewhere, or are they kept around to be re-installed?

I keep them all. Compression algorithms are pretty good these days, as is storage density.

I'm surprised you save much space since ISOs are usually stored in already compressed formats

Weirdly, my "Linux ISOs" are compressed in x265 :)

Which is only marginally more effecient than the H.264 encoding that many of them are delivered in. And the biggest shiniest Linux ISOs already use H.265 out of the box.

No he means a full length Linux ISO can be as small as 700 MB, I personally prefer 1.4 GB

I prefer my Linux ISOs to one or two orders of magnitude more fully featured than that.

[deleted]

Does this mean you have to decompress your "ISOs" when you want to watch them ? Does jellyfin support this ?

They're compressed in x265, most web browsers can decompress that natively ;) Heck, when you watch something on YouTube you are decompressing the content ont he fly

But yes, Jellyfin can also natively transcode formats on the fly if you stick a GPU in there: https://jellyfin.org/docs/general/post-install/transcoding/

Oh i thought you went 1 step further, compress all those "ISO" into 1 single blob.

Since Linux ISOs demand random access for a good user experience most of the relevant compression formats support that and so compressing as a blob wouldnt't really get you much but also not prevent individual access.

> - qBittorrent for "Linux ISOs"

This doesn't sound safe, since this is not anonymous and there are a lot of "Linux haters". Consider switching to and thus support torrents in I2P.

just use a tailscale exit node

why not switch to nntp?

What does a Linux ISO sound like?

intriguing list

I mean just say you’re pirating…

Whaaaaaat? That's illegal! I'm just an OS enthusiast!

We all enjoy a bit of sailing on the OS (Open Sea)

Especially using Sailfish OS

Boomers like to prove they can still have fun

As a gen-x'er, it's my birthright

You lost me with the quotes. Why are Linux ISOs needing such broad distribution that mirrors won't handle? Those mirrors might be on full self driving cars taking people to the movies or a concert, right?

Woof. Folks really hated my joke here :)

bots, autists, idiots, and possibly people who don't speak english as a first language and miss the in-joke