2025-11-13 15:54:06
HERE WE GO BLYAT https://kubernetes.io/blog/2025/11/11/ingress-nginx-retirement/
HERE WE GO BLYAT https://kubernetes.io/blog/2025/11/11/ingress-nginx-retirement/
Here is some useful and wise advice for living in the 21st-century surveillance-state epoch: https://aphyr.com/posts/395-geoblocking-multiple-localities-with-nginx
I losing faith in myself when it comes to client-auth and nginx
Just a note for anyone doing patches this weekend. I had a site not come up (didn't notice until this morning). It was throwing this error. Of COURSE this site was front ended with a nginx proxy, so I spent a little wasted time thinking it was related to that. It wasn't. Apache now likes to have a full FQDN hostname in <VirtualHost name:port> directive. This one just had "_default_". I simply out FQDN there, apachectl restart and all is well again.
Hey @… thanks for https://atevans.com/2012/12/12/nginx-config-try_files-for-s3.html - your 13! year old article got me out of a hole today 🙌
I have bought a plate of beer and have started building my own CA, with offline Root and all that fun.
Just because I wanted to try client-cert authentication in nginx
I spent the weekend making a fun DevOps pipeline because I felt like it and am now quite pleased.
I'm hosting gitea, n8n and docker registry in my lab. I now have a webhook in gitea for certain repos so that when I push to them, it triggers n8n to pull the repo and build the dockerfile. This image is then pushed to the registry, and watchtower will pull it when it runs.
Naturally have all my own DNS things for these app web guis which go through nginx. All of this is in pro…
RE: https://watzmann.social/@watzmann/115660166363499433
Lange hat mich dieses Problem beschäftigt. Viele Dinge wurden ausprobiert mit Referrern in der NGINX Konfiguration von Mastodon, etc. Nichts half. Jetzt bin ich auf die Lösung gestoßen, die
#Cloudflare just got faster and more secure, powered by #Rust
https://blog.cloudflare.com/20-percent
Der Hauptschuldige diesmal war Metas meta-externalagent und geholfen hat nur alle von Meta Crawlern verwendeten IPs zu blacklisten. Geht in dem Fall relativ einfach:
/usr/bin/whois -h whois.radb.net -- '-i origin AS32934' | grep ^route | sed 's/route6\?:\s*/deny /' | sed 's/$/;/' > /etc/nginx/conf.d/ip_blacklist_meta.conf
Alright, time to kick the tires on Vaultwarden. Got it installed, SSL and SMTP configured as well as proper `nginx` rules. The export from 1Password imported perfectly fine, and it's running great on a 2 vCPU/4 GiB of RAM VM. I did run Bitwarden for a short while, but I'd rather have a PostgreSQL backend than the MSSQL one.
Satisfied so far.
#vaultwarden
Je cherche des personnes s'étant inscrit sur #Peertube).
Il y a un peu moins de 4 moins j'avais essayé de upload des vidéos sans succès (Š chaque fois le % revenait Š 0%).
A kid wanted a Minecraft-server, so I installed Linux on a Dell Optiplex and gave it to him.
Used Linux for the first time, and had no problem what so ever installing minecraft, setting up backups, nginx reverseproxy and all that.
He did that in one hour, despite never touching Linux before
Bright future
@dawid@social.craftknight.comUstawiłem mediaproxy na swojej instancji #pleroma i ustawiłem przed nim cache CDN - muszę powiedzieć, że miało to obecnie największy pozytywny wpływ na czasy wczytywania tablicy.
Działa to tak, że wszystkie obrazy wszystkich instancji są hostowane z ścieżki /proxy na pleroma i jednocześnie obrazki są przez nginx cachowane w folderze /tmp, a ponadto cloud delivery network wystawia je …