Digest: r/selfhosted

ID Type Limit Status Last Update Next Update
digest-selfhosted digest 8 Enabled 6 hours ago 6 days from now
Posts History Gallery Config RSS JSON

Posts (8)

Digest: r/selfhosted: Aug 07 - Aug 14, 2026

Published: 6 hours ago | Author: System

Any downsides to taliscale? Seems like an incredible amount of value for free

I've recently moved all my devices to it, and added some friends/family to my network so they can play with some of my self hosted tools

Any horror stories I've missed? Am i blindly opening myself up to exploits? Are there better alternatives?

Seems too good to be true tbh

⬆️ 241 points | 💬 185 comments


Searched for Proxmox VE on the Internet

image

Shodan, searched pve-api-daemon/3.0, got 170k matches, big chunks on: - Hetzner - OVH - Linode

Many behind :3128 proxy, but 30k just like that on :8006 too.

Is this normal? Expected? Why are people doing this?

⬆️ 263 points | 💬 40 comments


PSA for maintainers: "we'd like to sponsor your project" emails through pump.fun are not real sponsorships

I maintain a self-hosted project and received an email yesterday for a sponsorship like many other companies have done. However, this one was different: https://imgur.com/a/OKGMWFx

They started off with a simple and flattering email of what my project does (probably AI description) and that they have shared it with their team and offered to sponsor me like many other companies have done in the past. They say that the sponsorship will come through "Pump.fun's GitHub Sponsorship integration" however that integration does not exist.

Here is what is actually being proposed. They launch a memecoin on pump.fun using your project name as the ticker. Every trade on that token pays a fee of ~1%. The token creator receives a share of those fees. Thats the money for the sponsor, its not them writing you a check or a wire transfer.

A five figure payout means something around a million dollars in trading volume moved through a token with your projects name on it. The token makes nothing and has no claim on anything whatsoever. Whatever money came out of it came from people who bought it and most pump.fun tokens end up near zero. Your sponsorship is literally a cut of peoples loses.

I then proceeded to tell them no and they told me I would get 100% of the fees however that was not my concern. Whether I get 1% or 100% of peoples loses that does not change the fact that I don't want it. They also mentioned they would generate trading activity themselves to make it a more attractive token for people to lose their money on.

The challenging part of this is that the money is real: https://thoughts.greyh.at/posts/pumpfun/ . Checkout this post. He received around $11,000 within a day and confirmed that they literally do pay out. However, he also said that afterwards there were no PR's, no issues, no activity, and no one wanting to test his app. His conclusion was that the whole thing was for traders rather than anyone who wanted to support open source. He also said that he probably wont do it again.

The token only draws volume because your project is real and your name is attached to it. Thats the entire product. The token, the wallet, and the fees that are given to you are permanently public and are attributed to you. So when the coin collapses, the people holding it see a coin named after your project and the maintainer who took a cut of peoples loses. After that, they move to the next repo.

My suggestion is that if you get one of these, you do not have to be rude about it, but just say that you don't consent. Know that nothing stops someone from launching it anyway so be warned about that and if you do see it happen, consider letting your community know.

I'm not trying to claim fraud and I'm not going to deliberately name the person who emailed me (they likely change their name every email since their PFP is clearly AI generated and its a gmail account).

⬆️ 227 points | 💬 20 comments


What I wish someone told me when I started

Just remember that not every self hosted application has a team of experienced devs behind it ensuring security is adequate. It’s super cool to setup 15 different services/containers and configure them exactly how you want, until it comes time to maintain and update.

Every other day I see a new self hosted program that someone made in an afternoon. Usually, there’s absolutely zero security or failsafe built in if a bad actor were to target you. Also, you never know who’s an upcoming, eager developer, versus a seasoned red black-hat trying to sneak malware into your Docker stack.

There’s been countless CVEs that affect self hosted applications. And many more we haven’t discovered yet. Last week my buddy had to take his main machine offline because the application he was hosting was unknowingly working as a botnet.

You’d have to pay me a lot of money to get me to self host some shit Bob Smith vibe coded in his basement. Even if the author doesn’t have malicious intentions, you can’t expect professional, or even an acceptable level security unless there’s a real team working on the project. Even then, no one is safe.

If you’re just starting out and aren’t too sure what you’re doing, please stick with the basics until you get your footing. Hosting is fun, but you quickly get diminishing returns when you enter the phase “Damn, what else should I host?”.

With all that being said I run lots of containers, but only ones that have been tried, tested, and proven to have responsive developer(s). Good luck!

Edit: I wasn’t expecting so many technical people to show up to this thread. It truly was awesome seeing everyone’s view on this, but just remember this post was made for people who are new to self hosting or are not technically inclined. There’s many people who started from ground zero, including myself. I wish someone would have been transparent with me and actually explain why hosting anything and everything may be a bad idea in the long term.

⬆️ 179 points | 💬 75 comments


Scored the homelab lottery

Ive always wanted to start self hosting but never had the budget to do it, i tried building a pc with spare parts i had but the price spikes for ram and storage kinds ruined it for me.

But when i least expected, i received a call from my friend telling me how the place he works had a bunch of spare pc parts and asked if i wanted it, which i obviously said yes.

Fast foward to today and now i went from a spare cpu and power supply to 3 amd fx pcs, 32gb of ddr3 ram, 12 500gb hdd and 1 240 gb sata ssd, all working!

Now i need help to decide what i should do to start building my homelab, for example i have no idea how i would connect all of those 12 hdd lol. My main focus is creating a media server with jellyfin and making a self hosted google drive like system for all my data and photos.

⬆️ 209 points | 💬 54 comments


Best OS for a server?

Trying to get into self hosting as a college student, and my brother gave me an old macbook air 2017 (intel chip) that i thought could serve as a simple server to get my foot in the door.

I've used Arch for a little while now on my school laptop, but I'm not super well versed in the options available with linux, nor do i really use most of the features Arch provides (im a larper 😔). The macbook is too old to support MacOS, and I was looking at what options i have with linux. I dont need anything bleeding edge, the easier the maintenance the better.

One of my first goals was to maybe host a minecraft server or something on it, mostly to gain some experience.

Ubuntu server seemed like a good option, I'm fine not having a gui for anything, and Debian seemed appealing as well.

Was curious what experience you guys have using these OSs for hosting things and what you would recommend I try out.

Thanks in advance for the help :)

⬆️ 178 points | 💬 490 comments


Planka removing SSO from Community edition

Planka is a snappy Web Kanban with a decent API. The company offers some additional functionality with their paid "Pro" plans.

They have now announced to move SSO/OIDC out of the Community edition into Pro.

What do you think about that?

What alternatives exist?

Anyone interested in forking?

⬆️ 190 points | 💬 93 comments


Lightweight Headless Browser With Native Rendering, No Chromium

https://github.com/h4ckf0r0day/obscura

A lot has changed since I last posted here 4 months ago. Got some harsh criticism back then and it was honestly deserved, the project was early and messy. But we kept going.

Obscura is a headless browser built in Rust for scraping and automation. V8 engine, native rendering, 30MB memory, 80ms page loads.

Works drop-in with Puppeteer and Playwright.

Just shipped rendering which includes screenshots, PDFs, live video capture. No Chromium. 20k stars now.

https://github.com/h4ckf0r0day/obscura

obscura serve --port 9222 and point your scripts at it. Happy to answer questions.

⬆️ 191 points | 💬 62 comments


Digest: r/selfhosted: Jul 31 - Aug 07, 2026

Published: 1 week ago | Author: System

The 3 Stages of Self Hosting

image

I'm lowkey on stage 4

⬆️ 576 points | 💬 32 comments


Petition to ban "I built" in post titles

When we all know it was really Claude that built it.

⬆️ 540 points | 💬 171 comments


Forgot and experienced true hell with :lastest

image

Remember to always set version numbers in your docker containers, or an unexpected update will creep up on you.

Now can you guess which popular service got a breaking change?

⬆️ 765 points | 💬 142 comments


Is it safe to use a Galaxy S20 Ultra with a detached back cover as a 24/7 Minecraft server?

image

The back cover of my phone detached. Is it safe to use it in this condition? I plan to use this phone as a Minecraft server.

⬆️ 369 points | 💬 110 comments


Reminder to BackupBeforeYouFKUP - Do you do off-site backups?

image

This is your reminder to check on your backups, setup backups and test your backups. 🙌

I'm currently using Duplicati with 2 local backup sites and hetzner/Google drive for remote. What are you using?

⬆️ 318 points | 💬 106 comments


Do other Stream Deck owners use them for selfhost shortcuts/ actions? I was thinking of throwing in some to perform diagnostics, etc

image

⬆️ 328 points | 💬 66 comments


What to do with 100s DDR3 ram?

image

So at my workplace they just replaced all old PCs with new ones and for some reason, they took the ram out of the old ones.

There’s a box with more than 100 of these 2GB ram sticks. We are just going to send them for disposal but I wanted to know if anything useful can be done with these?

⬆️ 262 points | 💬 87 comments


Tracearr v2.0.0 - Media Library, One Identity Per Title, Public API v2

https://www.reddit.com/gallery/1vgi06c

This has been a long time coming, and in progress for quite some time. Excited to see what everyone things, and what these new features allow you to learn about your server!

BACK UP BEFORE UPGRADING. This release migrates the database heavily. If you need the escape hatch, a 1.5 backup restores cleanly on 2.0.

New Media section

Browse your whole library as a poster wall with an A-Z rail and filters for library, resolution, HDR, size on disk, and watched - two-tone checkmark for "you watched" vs "someone watched". Detail pages list every copy of a title with per-file quality, library, and size. Genre breakdown, storage, and watch pages round it out.

One identity per title

The same movie on two servers is one row everywhere now - stats, leaderboards, history. Seasons and music get real identities too, and wrongly split titles heal themselves.

Every file counted

Tracearr used to read a title's first file and drop the rest. Now every version is tracked: 4K + 1080p copies, duplicate libraries, mirrored files counted once. Storage totals are honest, duplicates catches same-server copies, sessions record which version actually played, and 1440p/8K no longer count as SD.

Public API v2

Bearer tokens, rate limits, OpenAPI docs served in-app. Built so apps that use Tautulli can use Tracearr instead.

EDIT: Just want to also add that V1 is unchanged. There are no plans to ever remove it either, so there is no need to rework your integration if V1 already met your needs!

Mobile: every tab, every server

Rolling out shortly after the 2.0 app update. Server selection is global now - pick All, one server, or any subset from any tab, and it sticks across restarts. It used to be a dashboard-only trick that quietly collapsed to one server everywhere else. Navigation got rebuilt on native tabs: the tab bar survives detail pushes, and the drawer is gone in favor of a server sheet and header buttons. Also in this round: iOS 26 header buttons stop flashing white on tab switches, the stream map matches the dark theme on both platforms, and servers behind Tailscale are reachable on iOS again (App Transport Security was silently blocking them).

Under the hood

  • Plex library changes sync in seconds via server events (Jellyfin/Emby get this with the new SSE plugin release)
  • Upgrades show migration progress instead of looking dead, and a bad migration can't boot-loop the server
  • First sync is much faster
  • Fixed a silent gap in sharing detection on polled servers
  • Stale content and ROI stop double counting merged titles; duplicates stop counting mirrored files twice
  • OpenAPI specs publish as release assets, so the docs site always renders the spec for your version

Notes

  • Counts may shift after upgrade as versions and identities settle - that's the double counting going away
  • Overall trust scores move too: you now see a person's worst account, and violation totals actually count - both sat frozen before

Discord | Documentation | Website

⬆️ 232 points | 💬 82 comments


Digest: r/selfhosted: Jul 24 - Jul 31, 2026

Published: 2 weeks ago | Author: System

I self-host a tunnel in a country that actively hunts them. Here's what survives, and what keeps breaking.

Threat model first, because it changes everything about the design.

I’m in Russia. My adversary isn’t a random scanner — it’s the ISPs themselves, operating under a regulator that does nationwide DPI and can null-route foreign IP ranges by geography. Assume the network operator is hostile, has full visibility of my traffic shape, and can actively probe any endpoint I stand up. I self-host a tunnel for myself and a handful of people under those conditions. I used to work at one of the ISPs, which is how I know roughly what the other side sees.
Sharing the current architecture because most self-hosted tunnel advice quietly assumes a neutral network, and none of it survives here.
Why the usual stack is dead on arrival
OpenVPN and WireGuard are both gone. Not blocked by IP — detected by shape. WireGuard’s handshake has a fixed message layout and a distinctive packet size distribution; DPI doesn’t need to decrypt anything, it just needs to recognize the silhouette. Same for OpenVPN’s opcode structure. Obfuscation wrappers buy you weeks, not months.

Layer 1: VLESS + Reality (Xray-core)

Reality is the part worth understanding if you’ve never had to hide a tunnel:
• Client opens a normal TLS handshake, but sets SNI to a large real site (www.microsoft.com in my case)
• The auth material rides inside the ClientHello — an X25519 public key plus a short ID. To DPI it’s bytes in a service field
• Server checks it. Valid → completes the handshake itself and proxies. Invalid or absent → silently forwards the whole connection to the real Microsoft
• So active probing returns a genuine Microsoft response. Real cert, real chain, real content. There is no fingerprint to find, because in that moment the box is a Microsoft mirror
• No certificate of my own to leak, no domain of my own to get registry-listed. You don’t need a domain at all
The important consequence for self-hosters: your endpoint stops being distinguishable by content inspection. So the adversary switches to the layer below.

Layer 2: the part that actually matters — IP

Reality solves inspection, not geography. A VPS in the Netherlands is trivially blockable — you don’t need to know what it does, you just need to know it’s foreign.
So the client never touches the foreign box directly. Entry point is a relay on a Russian provider whose IP range sits inside the state whitelist — the set of ranges that stay reachable even when mobile internet gets cut regionally, because government and banking services live there. From the relay, traffic cascades out to the Netherlands box.
From the outside, the connection is a request to approved domestic infrastructure. Killing that range takes down a pile of legitimate business on shared address space with it. Collateral cost is the actual defense mechanism — not stealth.
Operational reality
• Something breaks every couple of months and gets rebuilt. Plan for rebuild speed, not permanence
• Stack: Xray-core 26.3 on Ubuntu 24. VPS is nothing special — 2 GB RAM, 2 cores, on vdsina.com. Reality is cheap; the box sits idle most of the time
• Latency cost of the extra hop: ~120 ms through the cascade. Fine for browsing and voice, noticeable in games. That’s the price of not getting null-routed by geography
• Monitoring: self-written script that checks tunnel state across all servers and emails me the status. Crude, but it means I find out from a mail instead of from a user
• Currently migrating the fallback path to XHTTP over CDN — moving uplink into HTTP headers so it reads as ordinary request traffic

Questions for anyone doing similar

Is anyone else fronting a foreign endpoint with a domestic relay, rather than trying to obfuscate the endpoint itself? Specifically curious about relay failover — right now mine is a single point of failure and I don’t love it.

⬆️ 1,045 points | 💬 173 comments


RomM 5.0 is live! Ground-up UI redesign, new Save Sync engine, 10k+ GitHub stars & more!

image

Website | Github | Discord | Demo

Never in my wildest dreams did I think I'd be writing a release announcement for RomM 5.0, but here we are! It’s been an incredible journey building RomM alongside this amazing community, and today we’re dropping what is easily our biggest, most ambitious update yet.

Ground-up UI redesign

We've rebuilt the UI from scratch, with a new design system and fresh visual language. Also included are:

  • Full controller and touch input support
  • QR code pairing for devices
  • Server-side ROM patching
  • Interactive 3D boxart
  • Play session tracking
  • Built-in music player for your OSTs
  • CRT shader mode for that authentic nostalgic aesthetic

Save sync engine

This is the first release to feature the new save sync engine, which allows you to sync your progress across devices. Cloud saves are currently limited to Argosy Launcher and Cannoli on Android, Grout on handhelds and Decky RomM Sync on the Steam Deck, but we are actively working on expanding support to more platforms and devices.

10,000 stars

We're so fucking hyped to announce that we've surpassed 10K stars on GitHub! This is a huge milestone for our project, and it wouldn't have been possible without you, sharing the good word far and wide.

Ecosystem growth

The number of apps built exclusively for us just keeps growing:

Mobile

  • Argosy: Native Android client for installing and launching games
  • romm-ios-app: Native iOS app

Desktop

Handhelds

  • Grout: Download and manage games on your Linux based retro handheld (Allium, Batocera, Knulli, MinUI, muOS, NextUI, Onion, ROCKNIX, Spruce, TrimUI)
  • DeckyRommSync: SteamOS downloader and syncer
  • SwitchRomM

Other

Finally, thank you

How do you even wrap up an announcement of this magnitude? The best way is simply to say thank you. Thank you to our core dev team, all the app developers, our alpha/beta testers, our financial supporters, and every team we work with in the retro gaming space. And thank YOU, /r/selfhosted, for supporting this project and keeping us motivated every single day.

Give 5.0 a spin, let us know what you think, and happy gaming! ✨

⬆️ 905 points | 💬 206 comments


I stopped leaving my self hosted apps running all night. Now the first request wakes them

image

Nine of the apps I self host scale themselves to zero when nobody's using them. Three are down right now, and all nine go down overnight. It's all one public repo if you want to poke around, github.com/mortennordbye/homelab
KEDA does the scaling and its HTTP interceptor does the waking. Each app's route points at the interceptor instead of the app, so the first request is held open while the pod starts, then forwarded. A cron trigger keeps the ones I use daily warm through the day so I'm not cold starting every visit. Over the two days on that dashboard it's about 302 pod-hours not spent.

21 apps and 22 infra components in there. Steal whatever's useful, and tell me what you'd do differently. The KEDA side is in k8s/talos/apps//scaledobject.yaml

⬆️ 585 points | 💬 106 comments


Piwigo is a bot trap 💀 685 legit requests, 266k from scrapers PER DAY

image

I have a very small german Piwigo site. Only a small amount of images are hosted there, not very relevant for any search engine. Less than 100 images I think.

In the last 24h: 685 requests from germany, 266000 from the US 😂

Its like 95% Meta, according to the user agents. Now I have to check how I can block them. Cloudflares AI Crawl Control doesnt even list it.

Its crazy how they are wasting their resources :D

And surprisingly my little 6€ VPS has no problem with the workload, so I only noticed it now.

Apparently piwigo is very good at trapping the Meta-Webindexer bot lol. Its so hilariously stupid that I wanted to share it.

I have sites with WAY more content, scrapers are no problem at all there.

⬆️ 556 points | 💬 41 comments


What's an incredibly good but not well known self hosted program?

I'm very new to self-hosting, and I've been searching for stuff I could put on it, though I've gotten to the point where I've seen all the biggest ones and I'm just curious if there are any that are good and useful but that get talked about less.

⬆️ 518 points | 💬 425 comments


Do i just accept my fate?

image

I have tried flaresolverr,Byparr and even trawl. It seems that my ip is blocked or flagged, routing it through a vpn doesnt help either.

Error: Cloudflare has blocked this request. Probably your IP is banned for this site

seems that having a static ip is the most probable cause, https://github.com/ThePhaseless/Byparr/issues/303 this is what i was able to find but discussions seems to not lead anywhere.

Setup:

  • Ubuntu Server, Prowlarr running in Docker
  • Gluetun (ProtonVPN) + qBittorrent, Sonarr, Radarr
  • FlareSolverr and Byparr both installed as indexer proxies
  • Static home IP

⬆️ 470 points | 💬 279 comments


What are your coolest or most utilized selfhosted services?

I finally got my server working. Tailgate, Docker. Jellyfin. Immich. Some selfhosted IRC channel because why not?

...what are some other small projects or things I could explore to both learn more about what the server is capable of for me, and have some cool utility/replacement for existing online stuff?

Auto-download offline installers from GOG? Link up my IRC channel to a Discord channel? Family Dropbox file folder? Just a website, capable as I want it to be, damn-the-speed? Private, secure, encrypted chat somehow? Torrent remote/manager?

⬆️ 410 points | 💬 411 comments


Switched to lightweight monitoring stack (from Grafana and Prometheus)

https://www.reddit.com/gallery/1vbjxgh

Hey guys. Just a quick review after replace my monitoring apps

I run a homelab with multiple hosts (4 Servers, ARM SBCs and x86s) and monitoring was a necessity

I started with Grafana, Prometheus (and node exporter, cAdvisor) and used it well. But I found myself spending more time on managing dashboards. Started from presets, and at some point it felt like overkill. and also they are quite heavy for my homelab

before

Grafana, Prometheus, Node exporter, cAdvisor,

after

Beszel, Dockhand, beszel agent, hawser(node proxy for dockhand)

Built-in dashboards are quite good for general use.

All after that I got free memory space around 1GB so I think it's worth it

But there's trade-off too. now I got separate dashboards so I had to type different URLs.

Both support SSO in free tier, but I'm a single user so I didn't bother setting that up.

and I still have no idea what to replace loki with if I need logging. any recommendations?

This is not the right answer for everyone. It's good because I am a single user on a personal homelab. If I had a team, I would have built a unified Grafana setup instead haha.

and

It's not an ad or marketing or anything. Just wanted to share my experience for anyone looking into lighter options

⬆️ 374 points | 💬 83 comments


Digest: r/selfhosted: Jul 17 - Jul 24, 2026

Published: 3 weeks ago | Author: System

No posts in this digest period.

Digest: r/selfhosted: Jul 10 - Jul 17, 2026

Published: 4 weeks ago | Author: System

No posts in this digest period.

Digest: r/selfhosted: Jul 03 - Jul 10, 2026

Published: 1 month ago | Author: System

No posts in this digest period.

Digest: r/selfhosted: Jun 26 - Jul 03, 2026

Published: 1 month ago | Author: System

No posts in this digest period.

Digest: r/selfhosted: Jun 19 - Jun 26, 2026

Published: 1 month ago | Author: System

No posts in this digest period.