• 4 Posts
  • 115 Comments
Joined 2 years ago
cake
Cake day: June 9th, 2023

help-circle
  • Lem453@lemmy.catoSelfhosted@lemmy.worldgoodbye plex
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 hours ago

    The best and most versatile system is having domains and a reverse proxy that has internal and external domains. Ie jelly.example.com and Vaultwarden.internal.example.com

    Then you add authentik which does SSO for many app like nextcloud, immich, linkwarden etc. For apps that don’t integrate, you can still use his with reverse proxy authentication (sonarr).

    Naturally this is more complex to setup but nothing beats the versatility.

    I can choose extra protection for things like vaultwarden (need to connect via wiregaurd). Make things external for other users to access easily (immich, jellyfin, etc). Everything is based on users that are made in authenticatik and they all have the same password with single sign on.

    You would approach this is pieces. get the domain and reverse proxy working first. Then authentik. this is only realistic with docker compose.


  • Lem453@lemmy.catoSelfhosted@lemmy.worldgoodbye plex
    link
    fedilink
    English
    arrow-up
    2
    ·
    3 hours ago

    Assuming this is all true, sure its not great but how much does it matter?

    Most have jellyfin in a docker. My jellyfin can’t only has read only accses to the media folder. Only the config folder has write access. Assuming the worst case scenario here, how much damage can than do?




  • I have traefik running with all config done via the docker compose files and I just couldn’t figure out how to get the bouncer middleware to work without causing problems. Doesn’t help that most examples seem to be based on the static yaml based config so I’m trying to convert jt. Would appreciate anyone who might know of a resource that explains with docker compose environment tags.

    I also have middle ware for things like authentik which complicates things.



  • Lem453@lemmy.catoSelfhosted@lemmy.worldManage things "To be Read"
    link
    fedilink
    English
    arrow-up
    8
    ·
    edit-2
    2 months ago

    The thing I like most about linkwarden is that it integrates with my existing single sign on (authentik). After you get to a certain number of apps, it becomes extremely annoying to not have this so I now look for SSO as a major factor when deciding what app to use.

    The small android app that allows android share button to send links to the app and full archive options also make it fantastic