Earlier quoted context omitted.
Even better, set up Tailscale. It's far easier to set up, is much more reliable (e.g. when devices are behind firewalls), and uses direct (encrypted) connections when possible. You can get it to do what you want with just a few clicks. Things like exposing a IoT VLAN on your Tailnet or setting up an exit node to tunnel all internet traffic through your home are super easy. You can even share specific devices with fri…
> If you aren't comfortable with trusting them with control over your network Wrt the possibility of Tailscale being compromised, there's the in-beta tailnet lock feature: > Tailnet lock lets you verify that no node is added to your tailnet without being signed by trusted nodes in your tailnet. When tailnet lock is enabled, even if Tailscale infrastructure is malicious or hacked, attackers can't send or receive traff…
Ditching Obsidian and building my own
261–270 of 570 posts
Re: Ditching Obsidian and building my own
#262Re: Ditching Obsidian and building my own
#263Earlier quoted context omitted.
Even better, set up Tailscale. It's far easier to set up, is much more reliable (e.g. when devices are behind firewalls), and uses direct (encrypted) connections when possible. You can get it to do what you want with just a few clicks. Things like exposing a IoT VLAN on your Tailnet or setting up an exit node to tunnel all internet traffic through your home are super easy. You can even share specific devices with fri…
Or, for those who are paranoid about relying on a company, setting up headscake is relatively quick and painless too - currently using it to sync between devices across multiple cities.
Re: Ditching Obsidian and building my own
#264> Since my PKMS is hosted online to manage notes across devices, I have multiple layers of security to ensure my notes are kept private. {Screenshot of a login form} The biggest life hack I can recommend for a self hoster is to set up a VPN on your local network and then just never expose your services on the public internet unless you're specifically trying to serve people outside your own household. Before I did th…
Re: Ditching Obsidian and building my own
#265Re: Ditching Obsidian and building my own
#266Earlier quoted context omitted.
> If you aren't comfortable with trusting them with control over your network Wrt the possibility of Tailscale being compromised, there's the in-beta tailnet lock feature: > Tailnet lock lets you verify that no node is added to your tailnet without being signed by trusted nodes in your tailnet. When tailnet lock is enabled, even if Tailscale infrastructure is malicious or hacked, attackers can't send or receive traff…
The pricing page suggests this is only for the "enterprise" plan.
> Tailnet lock is available for the Personal, Personal Plus, and Enterprise plans.
Re: Ditching Obsidian and building my own
#267Re: Ditching Obsidian and building my own
#268> Since my PKMS is hosted online to manage notes across devices, I have multiple layers of security to ensure my notes are kept private. {Screenshot of a login form} The biggest life hack I can recommend for a self hoster is to set up a VPN on your local network and then just never expose your services on the public internet unless you're specifically trying to serve people outside your own household. Before I did th…
Apps are blocked to the public by default but accessible using a Tailscale client.
It's built on top of NixOS and completely configurable through a single module.
Still in heavy development but I've replaced an entire rack in my closet with an Intel NUC.
Re: Ditching Obsidian and building my own
#269Re: Ditching Obsidian and building my own
#270Earlier quoted context omitted.
Even better, set up Tailscale. It's far easier to set up, is much more reliable (e.g. when devices are behind firewalls), and uses direct (encrypted) connections when possible. You can get it to do what you want with just a few clicks. Things like exposing a IoT VLAN on your Tailnet or setting up an exit node to tunnel all internet traffic through your home are super easy. You can even share specific devices with fri…
> If you aren't comfortable with trusting them with control over your network Wrt the possibility of Tailscale being compromised, there's the in-beta tailnet lock feature: > Tailnet lock lets you verify that no node is added to your tailnet without being signed by trusted nodes in your tailnet. When tailnet lock is enabled, even if Tailscale infrastructure is malicious or hacked, attackers can't send or receive traff…
I've had the Device approval setting on, and wished there were more robust lock features, but not enough to want to run my own coordinator. So Tailnet lock seems like a good security upgrade.