I can confirm that the resource usage is quite low indeed. I only used it with Nomad instead of Kubernetes, so I can’t comment on how to best migrate PVs and PVCs.
- 0 Posts
- 6 Comments
I’m currently using Piraeus / LINSTOR and am quite happy with it: https://github.com/piraeusdatastore/piraeus
supersheep@lemmy.worldto
Selfhosted@lemmy.world•Is there a self hosted mTLS manager?English
19·9 months agoVaulTLS: https://github.com/7ritn/VaulTLS
In theory the database can end up in an invalid state when you leave the database container running. What I do for most containers is to temporarily stop them, backup the Docker volume and then restart the container.
supersheep@lemmy.worldto
Selfhosted@lemmy.world•Exposing Immich via subdomain - good or bad idea?English
52·2 years agoYou could look into mutual TLS / mTLS to protect your instance. You will need to set this up using a reverse proxy at your server (like Caddy) and then add a client certificate to your user devices. If you use the Immich app, I think it also supports adding this certificate under Settings -> Advanced -> SSL Client Certificate. Here you can find a tutorial on how to set it up: https://www.apalrd.net/posts/2024/network_mtls/
(Edit: you will need to ensure that all clients who want to receive your shared photos have a client certificate installed, so depending on the number of clients this might be okay or less useful)
I use it for Home Assistant and ntfy in combination with Caddy. Certificates are managed by Vaultls (https://github.com/7ritn/VaulTLS) which makes it quite easy to setup and use on new devices.