

nope. I want to feel his conviction.


nope. I want to feel his conviction.


eat shit and go to hell.
I wouldn’t go onto a teen community and spout off how to make explosives even though they’re relatively safe to a trained individual.
same reason behind not allowing a hobbyist and amateur community to think that iptables and firewalld is the best/only solution.
it’s dangerous and someone will get hurt eventually.
this is selfhosted. a community that’s predominantly amateur or hobbyist.


lives are worth more than the dysfunction caused by the delay in services.
the only thing this did was to weaken the resolution of leadership when a real disaster happens.
the next time information like this comes forward, be it real or fake, it will cause a delayed reaction which will ultimately cost lives.


yes.


Jesus can eat shit from my ass. when he does that I’ll switch to jellyfin.
it’s far easier, and safer to have all your network config done in the network. from system migrations to securing/hardening. it’s far more efficient and effective to have a single source of truth that manages network routing and firewall rules. hell, you can even have a redundant or load balanced firewall configuration if you’re afraid of a single point of failure.
point is, firewalld and iptables is for amateur hour and hobbyists.
if you want to complain that “docker doesn’t respect system firewalls” then at least have the chutzpah enough to do it the right way from the beginning.


oh look, another jellyfin circle jerk.
What if you rent a bare metal server in a data center?
any msp will work with your security requirements for a cost. if you can’t afford it, then you shouldn’t be using a msp.
Or rent a VPS from a basic provider that expects you to do your own firewalling?
find a better msp. if a vendor you’re paying tells you to fuck off with your requirements for a secure system, they are telling you that you don’t matter to them and their only goal is to take your money.
Or run your home lab docker host on the same vlan as other less trusted hosts?
don’t? IDK what to tell you if you understand what a vlan is and still refuse to set one up properly to segment your network securely.
It would be nice if there was a reliable way to run a firewall on the same host that’s running docker.
don’t confuse reliable with convenient. iptables and firewalld are not reliable, but they are certainly convenient.
You may say these are obscure use cases and that they are Wrong and Bad. Maybe you’re right, but personally I think it’s an unfortunate gap in expected functionality, if for no other reason than defense-in-depth.
poor network architecture is no excuse. do it the proper way or you’re going to get your shit exposed one day.
this is the second time I’ve seen a post like this.
docker has always been like this. if it’s news to you then you must be new to docker.
if you’re using the built in firewall to secure your system on your wan, you’re doing it wrong. get a physical firewall. if you’re doing it to secure your lan then you just need to put in some proper routes and let your hardware firewall sort it out with some vlans.
don’t rely on firewalld or iptables for anything.


I had several IOT smart plugs that have GPS built in.
why? why would it need to know its exact geographic location?!
after that I created an entire hardware segmented network that’s specifically used for IOT and cameras.
last I checked the router/firewall it’s on has blocked over 11million requests a month trying to access the outside.
I will never have a “smart” device in my home that’s connected to the internet. I’ll live like it’s the 1930s if I ever have to.


I have a couple open slots in my rack waiting for the day.


I wasn’t sure how bad it was until I just checked.
last December I bought a 2x32gb DDR5 kit for $160. right now, same kit, almost $600.
this is fucking insane man.
fuck AI.





those aren’t claps you’re hearing. might just be the half that can still watch porn…


(sits in his Lamborghini Plex while a beautiful blonde gives him a handy) I’m fine, mate. Maybe later.


all the better to remove the federal internet license requirements.


can’t wait for this to start. then maybe I won’t have to hear about it from the jellyfin shills every week.
electron was a steaming pile of shit 8 years ago. still is. what’s changed?
our acceptance of shitty corporate software.