Skip to content

Self Hosted

CrowdSec CloudFlare Worker Bouncer.

Having CrowdSec installed on your local reverse proxy is vital for security. But if you are just having repeated attempts after repeated attempts through a tunnel such as CloudFlare tunnel, you're still going to get all of that traffic to your reverse proxy and see all of the 403 forbiddens in your logs. We can fix that with a CloudFlare Worker Bouncer.

Setting up Pangolin Passthrough

A couple of people expressed concerns about Oracle snooping in on their unencrypted traffic between SSL termination on pangolin and the Gerbil tunnel to their home server. In this post I will explore the pros and cons of using a Raw TCP tunnel to pass encrypted traffic through the tunnel without decrypting it.

Creating a VPS with Oracle's always free tier

I know everyone hates on Oracle but they certainly have the best free tier out there for virtual private servers (VPS). I'm setting up a VPS to create my own reverse proxy tunnel outside of my home network with Pangolin. This allows me to expose home lab applications indirectly, without exposing my public IP and opening ports. It's like we're setting up our own Cloudflare Tunnel, just without the benefit of its CDN and DDoS protections.

Installing Proxmox and Restoring Ubuntu Server in a VM

So it does in fact seem that my old m.2 hard drive which is running my Ubuntu server is dying. I've had to restart it daily the last couple of days and now multiple times today and from what I've seen in the logs it looks like there is some corruption going on.

The plan is going to be to boot up a new m.2 hard drive and install Kopia onto it.

Setting up AdguardHome and PiHole on the bridge network

Last week I showed you how to run AdguardHome and PiHole using MacVLans. This way we didn't have to deal with any port conflicts and each dns server could be run simultaneously on its own IP address. However, it is undeniable that the MacVLan is a little bit trickier, so in this post we're going to set these up again, only one running at a time of course, in the bridge network, so that our actual server is also a DNS server.