Skip Navigation

Posts
5
Comments
38
Joined
6 mo. ago

  • If you knew what was under the hood you would not say it's "just" customized nginx... It's more like customised, optimized and simplified.

    It has many enhancements builtin like automatic certificate generation and renewal, fail2ban, prebuilt optimized configs, and easily enhanced security with crowdsec and even geofencing.

    But made way easier than doing that separately with raw NGINX.

    It's much more friendly to pickup and run with then raw NGINX.

  • It can be done, just carefully. You can definitely accidentally block yourself out if you set a firewall rule up incorrectly, or in higher precedence of order for example. OPNsense (like almost every firewall known) processes rules in a "top down" order. So you put your blocks at the bottom!!!

    Reverse proxy won't lock you out, essentially that's just slapping HTTPS on a webserver/service like Jellyfin, so you can access it without requiring a VPN.

    Here's a reverse proxy explainer, pt 2 is the actual setup!

  • No worries, hope it helps, let me know if you have questions =)

  • Well hello there!

    Yes, the one and only Core Lab Joe, in the digital flesh (packets, tcp-stream!). Thanks for reading and I'm glad it helped you!

    I'm picky when writing tech guides and generally will only write (and recommend!) what I run, and what I have experience with, so that would not be traefik.

    My entire system/setup is all dockerized as well. I run 50+ dockers, and anything publicly exposed goes through my SWAG instance. It doesn't matter what reverse proxy you use, or even if the apps are containers or not really, it's all networking.

    That said I've got a good Traefik resource for you, FoxxMD Blog and his migrating from SWAG to Traefik post!

    One of the things I need to tackle fully myself, understand, break, troubleshoot and then fix is OIDC for myself, so I can write a good guide on it. A lot of apps do natively do it now, but from what I understand for those that do not, you can use Authelia and the like to slap that authentication into (over top) of it.

  • Never heard of Rayfish but just googled, it's a mesh VPN so probably wouldn't want to push that through a reverse proxy to authelia, it would just slow it down....

    I personally use wireguard as my VPN, not tailscale or headscale or any of that but I do understand some people need something that can get around CGNAT or other issues.

  • No I had no issues flipping it over to keydb. I was on redis originally so I stopped the containers, took a backup and simply changed the image I was using for my backend to keydb end it was like a drop in replacement! Didn't even need to do a dB upgrade or anything complex.

  • What you could try is an inverse sense of match rule, which by default, allows access to the internet but not to other VLANs. This is what I do and is the standard I think that should be the default!

    If you read the LAN rules at the link there, it basically has you setup RFC1918 IP space as an alias, and then setup an inverse option the logic is:

    Anything that is NOT Private IP space - ALLOW!

    So outbound from that vlan/network/subnet to internet --> Allowed!

    Then you make separate rules to actually allow whichever VLAN access to the other, that you want.

  • Thank you for taking a peek!

    Let me know if there's something you're looking for. The search function isn't to bad but sometimes the posts can get buried a bit ;)

  • Oh hello there fellow Canadian blogger! I'm just down the road from you in between Toronto and Montreal (right in the middle actually!)...

    I run a tech blog as well, but different focus than yours mostly on c omplete self-hosting, infrastructure and cybersecurity, and media servers.

    **We should make some backlinks at some point! **

    PS> This site is built off Ghost CMS.

  • This may help as well, and bridges the gap for some with all the changes from v25.x to v26.x.

    Core Lab OPNsense upgrade guide

    Your rule looks correct at first glance, but I'll take a peek further. You do need a DHCP pool setup PER VLAN though, so there's that as well.

  • Selfhosted @lemmy.world

    How to Setup Authelia in Docker with SWAG Reverse Proxy (2026)

    corelab.tech /authelia-mfa-swag-setup/
  • I'm late to the party, but feel my guides can help. I am biased towards them because I wrote them! ;)

    It's up to date for v26.x with OPN, that said these guides (3 part series) do need a bit of an overhaul but it does cover VLANs, LAGG/Trunks, DNSmasque and DHCP for each VLAN, with pictures etc...

    Core Lab OPNsense Guides

  • Yeop, this is the way, the only way to try and retain some semblance of privacy other than not using social media, or a smart phone for that matter!

    Step-by-step guide here for the uninitiated on setting up docker compose.

  • Oh this looks interesting, I'll have to gawk at this a bit! Thanks!

  • Yyeeeaaahhh this is the part I think that will surprise people the most, the bills combined are what makes things unpalatable IMO...

    I too want a safer Canada, but at what cost? The metadata collected will be paramount to a complete digital profile, with the Government knowing LITERALLY everything about every citizen. It's too much...

  • I think this is a great thing, otherwise Kingston will be missing out, big time. As the largest of all the small cities between Toronto, Ottawa/Gatineau and Montreal, it's always been somewhat of a 'mini hub' and being left out of the high-speed rail system would I think, hurt Kingston long term.

  • Canada @lemmy.ca

    Canada Is Dismantling Digital Privacy: Bills C-22, C-34 & C-9 Explained

    corelab.tech /canada-privacy-laws-bills-c22-c34-c9/
  • Like almost all FOSS and closed source software, they have analytics yes and it is covered in their privacy policy. Guessing you did not make it to that part of the review?

    The difference and it's an important one, is that they do not sell your data. No 3rd party data sharing or sales which is actually better than a lot of even FOSS software.

    Everything you use collects your usage metrics, google, your phone regardless of vendor, Microsoft, Apple etc... No different except that this dev team does not sell your data, which the others assuredly do.

  • Fair enough, all solid points.

    BTW - I am not the dev of JellyWatch.

  • Canada @lemmy.ca

    Canadian Identity Theft: Understanding the Data Leak Pipeline (2026)

    corelab.tech /where-your-identity-leaks/
  • Canada @lemmy.ca

    How to Cut the Cord in Canada (2026): The Ultimate Guide

    corelab.tech /cord-cutting-canada/
  • Selfhosted @lemmy.world

    How to Cut the Cord in Canada (2026): The Ultimate Guide

    corelab.tech /cord-cutting-canada/