Digest: r/selfhosted

ID Type Limit Status Last Update Next Update
digest-selfhosted digest 8 Enabled 3 days ago 3 days from now
Posts History Gallery Config RSS JSON

Posts (8)

Digest: r/selfhosted: Sep 18 - Sep 25, 2026

Published: 3 days ago | Author: System

Hey Portainer, Dockhand is my new home.

image

After years of solid service, it’s time for a change. I’ve moved to Dockhand in my home setup (mariushosting) and damn, it just feels right. Cleaner interface, smoother workflow, and that fresh energy the selfhosted world always needs. No hard feelings, guys, just evolution.

Thanks for everything, Portainer. Welcome home, Dockhand.

Anyone else already made the switch?

⬆️ 1,235 points | 💬 174 comments


autobrr team just announced Librarry. replacement for sonarr and radarr

From their discord

Finally some news 👀

@everyone It's been pretty quiet since we posted the 2025 Year in Review, but now there is some news about our arr alternative!

I'm happy to announce librrary! One app for movies and TV, from the team behind autobrr and qui.

It is NOT ready yet, but we are getting close to user testing!

Why? What's wrong with Sonarr and Radarr?

Sonarr and Radarr work well if your needs are simple. As soon as you want both HD and 4K libraries, you need multiple instances. Then you need to keep those in sync with everything that comes with it.

It's not uncommon for users to run 4-6 arrs to fill their needs. This means more to manage, more resources, more hits on indexers and so on.

With so much duplicated between them, it makes a lot of sense to combine movies and TV into one application.

A big thanks to everyone who posted in the feedback thread! It was super helpful! Keep it coming: Ideas discussion

What we are building

  • Multiple libraries by content type (similar to Plex), where each title can have several variants (1080p, 2160p, remux, DV)
  • Arr-like Quality Profiles and Release Scoring Rules (think to Custom Formats)
  • Torrent and Usenet support via Torznab/Newznab (will need Prowlarr/Jackett etc)
  • Users with roles, plus OIDC login
  • SQLite or Postgres
  • Notifications with your favorite services (Notifiarr, Discord, Telegram etc.)
  • Lists support
  • Go backend, React frontend, Docker images and binaries for Linux, macOS and Windows

On the roadmap

  • Built-in requests (don't worry, there is a strong user role access system)
  • Import from Sonarr and Radarr
  • Optional manual upgrade approvals
  • Trump handling: watch the torrent client for trumped/nuked tracker messages and take webhooks from external tools like qui
  • Potential Plex, Jellyfin and other media server integrations, including deleting titles after they're watched (request, dl, import, watch, delete)
  • Various features from the feedback thread

Other media type support

It's built to be modular, so dedicated anime handling, books and music are possible later, but movies and TV come first.

When?

No release date yet. Sign up for news here: https://librrary.app/ Updates will also be posted in this channel.

Support the development <:peepolove:1035253194969845890>

If you want to chip in:

https://github.com/sponsors/zze0s https://buymeacoffee.com/ze0s https://ko-fi.com/theze0s https://autobrr.com/support#cryptocurrency

⬆️ 834 points | 💬 481 comments


Finally have my family using my server!

image

Hello,

I just finished setting up a portal for my family to use, and wanted to show it off.

I Just finished setting up the gaming server using moonlight-web and Wolf so everything I host is now in a container, I thought putting it all in once place makes it easy for my family. Next im going to learn some networking!

⬆️ 816 points | 💬 95 comments


Portainer Cuts the Cord Between Its Free and Paid Editions.

https://itsfoss.com/news/portainer-community-edition-freeze/

For the people that are unaware or haven't seen the news yet.

⬆️ 725 points | 💬 286 comments


NetWatch: a network monitor for the terminal

image

Ten tabs over your network, all one keypress apart:

- Every socket with the process behind it, PID, TCP state, GeoIP, RTT and retransmits. Attribution comes from platform socket polling, PKTAP on macOS, and an optional eBPF kprobe on Linux.

- Live packet decode with display filters, stream tracking, JA4 fingerprinting and PCAP export.

- TLS 1.3 and 1.2 decryption for sessions you hold the keys to. Point a client's SSLKEYLOGFILE at NetWatch and the plaintext decodes in the Packets tab, same mechanism as Wireshark.

- A diagnostic engine that learns per-metric baselines, opens an issue when one breaks, ranks the causes by the checks that separated them, and closes the issue only once the fix has held. No model involved.

- Egress drift. It learns which hosts, autonomous systems and ports each process reaches, you promote that to a rule, and the next new destination shows up flagged. Observes only, never blocks.

- Background detection for C2 beaconing, port scans and DNS tunnelling. A critical alert freezes the flight recorder so the bundle exists before you go looking.

- Throughput, interfaces, protocol breakdown, traceroute topology, per-process bandwidth, and a timeline of connections by TCP state.

- Three layouts off one capture. V cycles them live: full ten tabs, --lite for 80x24, --view dense for four borderless boxes with braille throughput graphs.

macOS, Linux and Windows. One binary, no config. The Linux build is static with libpcap bundled in.

brew install netwatch

cargo install netwatch-tui

https://github.com/matthart1983/netwatch

⬆️ 663 points | 💬 82 comments


Minipc is just a good pick for homelab

image

They've got good performance and run well, and I've got all my stuff running on them. The DAS is a bit old, but it still works fine.
Minipc: acemagic k1 (r7 7730u, 16gb ram, 1tb ssd)
External storage: samsung t7
Das: mediasonic probox

⬆️ 488 points | 💬 68 comments


Raspberry Pi 5 EEPROM update now blocks manual RAM upgrades ("SDRAM mismatch" Error)

A heads-up for anyone doing hardware mods or custom upgrades on the Raspberry Pi 5:

As of the pieeprom-2024-09-23.bin update, the Raspberry Pi 5 now performs a hard RAM capacity check during boot:

2.41 Expected configuration 8 Gbit (0x07)
2.44 Actual configuration 32 Gbit (0x05)
2.48 USB-OTG disconnect
2.51 BOOT ERROR: code 9 - 'SDRAM mismatch'

If the EEPROM detects a RAM capacity that differs from the original factory configuration (written in OTP memory on the SoC), it throws Error Code 9 and refuses to boot.

Instead of letting skilled users repurpose loose RAM chips or upgrade their existing hardware to mitigate these insane market prices, they went out of their way to implement an artificial software wall.

It takes serious hardware skills and specialized equipment to desolder and upgrade BGA-packaged, soldered RAM on a board like this. Preventing power users who manage to do this from actually using their modified hardware. What technical or security justification is there for artificial bootloader locks on custom RAM, other than forcing customers to buy higher-margin, overpriced models? Imagine buying a desktop PC and not being able to swap the RAM or the SSD in it...

To make matters worse, any attempts on my side to bring this up or post about it on the official Raspberry Pi forums are getting deleted almost instantly.

At this rate, what’s next - serialized power supply checks on boot to block 3rd-party power bricks?

What are your thoughts on this move? Is there any legitimate stability or technical reason for hard-coding RAM limits in the EEPROM, or is this strictly anti-Right to Repair driven by corporate greed?

⬆️ 488 points | 💬 115 comments


Selfhosting is more important now than ever

image

I'v been thinking recently with the AI safety incidents (hugging face, frontier labs whistleblowers etc.) how self-hosting is more important now than ever. Basically there there are three ways self-hosting impedes an oncoming cyber apocalypse - which leaving everyday services to centralized providers would accelerate. I'v boiled this down to:

  1. Data accessibility - our data on our infra means no 3rd party has unauthorised acccess like an employer/service provider/state would have access if we gave up the infra to someone else.
  2. Operational flexibility - we can choose when to stop/start/discontinue at the flip of a switch - physically/remotely/whatever we choose.
  3. Information sparsity - because its only Joe Blogs data it doesn't represent as big a target as say Gmail does on a global scale, individuals holding their own data adds difficulty (because different setup), less worth and more time and effort targeting numerous individuals. And don't give me that the big providers are more protected - I was around when heart bleed was a thing - anyone with knowledge of that vulnerability could pull raw memory from the biggest providers until it was patched.

With AI advancing at such an incredible pace, big data repositories which are information rich (because higher numbers of individuals data, as opposed to a singular data source, say) represent a higher priority target for malicious/nefarious actors (human or non-human)...

So self-hosting our critical data, our personal data our every-day seemingly benign data - the original promise of the distributed Internet before centralized providers sucked everyone in - is a service not only unto yourself, but everyone!

Photo of 10 year old 16GB i7 1TB SSD box running undisclosed operating system that would cost me ~$100USD /month from cloud provider only costing me ~20W avg or $3USD /month.

Yes I KNOW i need to take care of backups/power loss/internet connectivity/ security updates - its really not that hard and have had 1 power loss incident in 5 years, 99.9999% uptime baby

⬆️ 460 points | 💬 173 comments


Digest: r/selfhosted: Sep 11 - Sep 18, 2026

Published: 1 week ago | Author: System

No posts in this digest period.

Digest: r/selfhosted: Sep 04 - Sep 11, 2026

Published: 2 weeks ago | Author: System

No posts in this digest period.

Digest: r/selfhosted: Aug 28 - Sep 04, 2026

Published: 3 weeks ago | Author: System

I Wanted a Dashboard I Actually Enjoy Using

image

A few days ago I posted asking for dashboard recommendations and got a lot of really helpful suggestions. I ended up going with Dynacat (Glance), and I think it was exactly what I was looking for.

I'm the kind of guy who, once I set something up, I want to forget about it. I don't really care about constantly monitoring CPU usage, DNS stats, uptime, container health, etc. If something breaks, I'll know because something I actually use will stop working.

It was important to me to keep this to 1 PAGE for the stuff I actually care about so I forced myself to consolidate everything as much as possible and only include things I actually wanted to see (the apps and sites I use most, what's happening in the news/media, my Plex activity, the Bears schedule, storage, and a few fun additions).

After 4 days of constant tweaking, an insane amount of frustration, and using ChatGPT for almost everything, I'm finally happy to call it done. I learned so much about yaml, css, formatting, and github doing this project. Thanks again to everyone who gave me suggestions on my last post, I'm so happy with the way this turned out!

⬆️ 283 points | 💬 58 comments


You can now use iMessage, SMS, Notifications, Contact sync on Linux with Tether.

https://github.com/zackb/tether

⬆️ 379 points | 💬 49 comments


BentoPDF can edit existing PDF Text and two new engines

Hello folks!

BentoPDF is an open source privacy first PDF toolkit.
Repo: https://github.com/alam00000/bentopdf/

Its been almost half a year since I last posted an update about BentoPDF. Mostly because there wasn't anything substantial lol. But I am happy to share some exciting stuff.

1. You can now actually edit text inside PDFs

BentoPDF now allows to click existing text, edit it, and have the text reflow while preserving the original fonts and styling.

It also includes the following below:

  • Bold, italic, underline, strikethrough, superscript, subscript, font family/size, colours, outlines, character spacing and line spacing
  • Left, centre, right and justified alignment
  • Bulleted and numbered lists with indentation
  • RTL and LTR text alignmentt
  • Find and replace across the document
  • Edit images by rotating, flipping, duplicating, resizing or deleting them
  • It even supports Object alignment, distribution, rotation, flipping, duplication. A feature not even commercial software like Apryse and Nutrient support.

However please note that this is a work in progress. You may encounter certain bugs, which you can report and I will definitely look into it.

2. Hyper Compress

Hyper is the best open source PDF compression engine. It was made to solve specific problems.

  • You might notice certain times PDF compression returns a file larger than the original. Hyper's result is always binary. It will either produce a PDF that is smaller than the original or just return the original PDF itself. This helps in creating predictable workflows.
  •  Hyper includes a true lossless mode for compression and it preserves searchable text and document structure and pdf conformance, rather than rebuilding the entire document from scratch like Ghostscript
  • It can run everywhere. Its available as a CLI, Node SDK, C API, self hosted service, and WebAssembly build.

Calling itself the best is a big claim. But please try it yourself and let me know how it performs on your PDFs

I also tried comparing it to Adobe's compression API. And I was only able to do around 100 PDFs where the compression results were +-5%. I couldn't test on a big corpus as its very expensive lol.

3. Kura

Kura is a PDF standards, conversion and preflight engine.

It supports:

  • All 11 PDF/A conformance levels: PDF/A-1a, PDF/A-1b, PDF/A-2a, PDF/A-2b, PDF/A-2u, PDF/A-3a, PDF/A-3b, PDF/A-3u, PDF/A-4, PDF/A-4e and PDF/A-4ffff
  • Accessibility: PDF/UA-1 and PDF/UA-2
  • Print production: PDF/X-1a, PDF/X-3, PDF/X-4, PDF/X-4p, PDF/X-5g, PDF/X-5n and PDF/X-5pg
  • Engineering and variable data printing: PDF/E-1 and PDF/VT
  • E-invoices: Factur-X, ZUGFeRD, XRechnung and Order-X
  • 396 bundled print-preflight profiles

It has also been tested against several standards suites, including the veraPDF corpus, Isartor, BFO, Ghent Output Suite 5.0, the PDF/UA Reference Suite and Cal Poly's PDF/VT suite.

Across 30,677 PDF conversions, it had zero crashes and zero timeouts, with a 0.05-second median conversion time.

Like Hyper, it also ships as a CLI, C library, npm package, Docker image and WebAssembly build.

Neither Hyper nor Kura is integrated into BentoPDF yet. I still want to do more testing and optimisation before making them part of the app, but both engines are already stable and available to try.

Also a bad news
I was also in talks with an industry leader about building another engine for BentoPDF that would be able to convert Office documents to and from PDF with very high fidelity.

Unfortunately, the project didn't work out in the end because they weren't willing to open-source their side of the technology. I completely understand their decision, but it does mean this engine won't be happening for now.

The other bit of bad news is that I broke my hand a couple of weeks ago. This release was supposed to be much bigger and include things like Measurement, an Acrobat parity comparison tool, Print Production and Accessibility. Which is also why I also wasn't able to spend as much time polishing and optimising this release as I normally would have liked. There are a lot of optimisations, improvements and cleaner implementations I had planned, but simply couldn't finish in time. However, I'll continue optimising the new editor once I am well, improving quality and fidelity, and working through everything I had to leave unfinished.

But till then please try it out and let me know how it works for you.

The releaase also contains other improvements and bug fixes and the repo for kura and hyper is mentioned in the release:
https://github.com/alam00000/bentopdf/releases/tag/v2.8.8

Thank you for using BentoPDF and have a great weekend!

⬆️ 275 points | 💬 45 comments


Framed notes from publicly available thermal printer

https://www.reddit.com/gallery/1w10mse

A couple of weeks ago I put my printer online (see https://www.reddit.com/r/selfhosted/comments/1vpskku/i\_put\_my\_receipt\_printer\_on\_the\_internet\_send\_me/). I received over a thousand notes and started framing them.

Btw, I put the service back online :D https://print.tomgroenwoldt.de

Edit: Now I'm framing the notes live!

⬆️ 260 points | 💬 24 comments


How seriously do you take the security of your self-hosted apps?

image

source: https://www.afp.gov.au/news-centre/media-release/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-global

Most self-hosting security advice is just about the basics - don't expose ports directly to the internet and use containers for basic isolation

Beyond that what level of security do you actually enforce? Do you monitor what your apps are doing in the background, like tracking outbound network traffic or checking file access on the host? When updating, do you just let it auto-pull or read the release notes for breaking changes or inspect source code and dependencies before updating?

⬆️ 285 points | 💬 93 comments


Pangolin 1.22: AI Gateway for self-hosted models + Community Edition updates

https://www.reddit.com/gallery/1w0s16a

Hello everyone!

Pangolin 1.22 introduces a new resource type: AI Gateway. These resources are identity-aware proxies in front of both cloud model APIs and self-hosted model servers, so coding agents and AI clients call a Pangolin URL. A gateway resource can be keyless by authenticating via the Pangolin client or keyed by minting virtual API keys.

We're also moving SSH, RDP, VNC, and private HTTPS resources from Enterprise to Community Edition.

Pangolin is an open-source, identity-aware remote access platform that simply and securely authenticates your users to infrastructure, apps, and AI resources.

GitHub: https://github.com/fosrl/pangolin

New AI Gateway Resources

Attach cloud providers (OpenAI, Anthropic, Gemini, Bedrock, and others) or self-hosted models over a site connector (Ollama, vLLM, and others) to a Pangolin resource, and point your agents at it instead of the raw provider. Pangolin centralizes the upstream secrets, controls who can call what, enforces restrictions, and logs usage.

This is available entirely in the Community Edition.

  • Public Gateway resources expose a public URL and authenticate with identity-scoped virtual API keys per user or service.
  • Private Gateway resources are keyless, reachable only over the Pangolin client tunnel, so tools like Claude Code and Codex authenticate with zero key management (pangolin configure claude sets it up for you).
  • Budgets, analytics, and session logs let you cap spend and see what ran, by provider, model, user, or key.

Docs: https://docs.pangolin.net/manage/ai/overview

SSH, RDP, VNC & Private HTTPS now in Community Edition

Browser-based SSH, RDP, and VNC (public resources) and SSH/HTTPS over the Pangolin client (private resources) were previously Enterprise-only since 1.19. Based on community feedback, we have moved them to the Community Edition.

Full announcement: https://pangolin.net/news/1-22-release

Available for self-hosting via Community or Enterprise editions (Enterprise is free for personal use) or on Pangolin Cloud. If you haven't starred us on GitHub yet, it genuinely helps!

⬆️ 191 points | 💬 97 comments


Digest: r/selfhosted: Aug 21 - Aug 28, 2026

Published: 1 month ago | Author: System

Does anyone still run their homelab on plain Linux + Docker Compose ?

I’m wondering how many people still run their homelab in the most basic way possible: a normal Linux install like Ubuntu Server or Debian, Docker, and one folder with a docker-compose.yml file for each service.

I’ve tried things like OpenMediaVault and CasaOS before, and I totally understand why people use TrueNAS, Unraid, ZimaOS, CasaOS, Portainer, etc. The UI is convenient, a lot of things are simplified, and it’s probably much less intimidating when you’re starting out.

But personally I always end up preferring Linux + Compose directly. I’ve also sometimes found it harder to troubleshoot problems on those other platforms.

Basically, my current setup is one folder and one docker-compose.yml file per service, with sometimes several related services in the same Compose file/folder.

I do have Portainer installed, but I barely use it. Mostly to quickly delete old images or volumes, or check something when I’m too lazy to do it from the terminal.

What I like about this setup is that everything is very explicit. If something breaks, I know where the config is, I can check the logs, edit the Compose file, recreate the container, move folders around, make backups, etc.

I also find it easier to debug because there are fewer layers between Docker and me.

AI has also made this approach much easier for me. When I run into a networking issue, permissions problem or some Docker/Compose thing I don’t understand, I can usually figure out what’s happening pretty quickly. And at the same time, it helps me learn Docker little by little instead of having an interface hide everything from me.

So over time I don’t just feel like I’m fixing problems, I also feel like I’m understanding my whole stack better.

Sometimes I look at all the newer homelab platforms and wonder if I’m becoming the weird guy who still manages everything this way 😅

So I’m curious:
Do you still run Docker directly on a normal Linux server with Compose files, or have you moved to something like Unraid, TrueNAS, CasaOS, ZimaOS, etc.?

And if you switched, what actually made you prefer the other approach?

⬆️ 615 points | 💬 790 comments


AI is making everything look and feel the same, and we should be sick of it

What started as fun, interesting use of LLMs has, it seems to me, spiraled into something completely out of control. While new apps get created at lightning speed, especially if spearheaded by developers who have an idea of what they are doing, it's made the self-hosted space from something with 2-3 options per media category into a very crowded, messy space.

Take a look, for example, at the book side : we now have Bookorbit, Grimmory. Completely new apps, and yet, somehow, they look the same. Why? Because the devs used AI during development. Take a closer look, and you'll be able to make out immediately if an app was made with AI: bright pill-shaped buttons, often green, catchy "it's not X, its' Y!" descriptions, Docs with emoji, and the somehow same settings and menu layout.

And it's not just a philosophical problem: how do people innovate if there's nobody to make new stuff? and how about the old, beloved projects, with their slightly clunkier but human-made UI? How about Kavita? Komga? Heck, even the broken mess that is Calibre-web . The UI isnt that good, but at least it was visually consistent.

Talented devs are leaving the established projects that were done tons of passion behind them to embark on a solo journey with LLMs, that starves the old projects, burns them out in months and will leave the space with old apps struggling to keep up on one side and a plethora of sleek. soulless AI-coded apps that will cycle through one after the other, making the space worse for eveyone.

So the problem, perhaps, isnt just AI, but the fact that people have to start being more humble , and accept just being a member of a thriving community instead of being the chief of a wasteland. The second option is much, much worse for the whole community.

⬆️ 397 points | 💬 136 comments


Bookorbit is incredible

I’ve been self hosting for quite some time now, I write software and I’ve seen many projects of all quality levels.

I just want to express my appreciation for Bookorbit and its developer, it’s truly a joy to use, and it clearly comes from a person that knows what they’re doing.

You built exactly the product I was eventually going to build myself, the attention to detail is incredible, it has the features I always wanted to have in other solutions, and they’re well put together.

This is also an occasion to showcase that AI is amazing in the hands of skilled engineers and we should take advantage of it in open source, hopefully while leveraging self hostable open weight models in the future (we’re slowly getting there, and we should fight for it).

⬆️ 344 points | 💬 293 comments


Why Proxmox?

I see so many people in here using Proxmox. I run Ubuntu + Docker, and my whole setup is just a list of folders with compose.yamls and supporting files (configs etc). It feels very manageable this way, fully declarative, easy to version control.

Am I missing something, that makes people recommend and use Proxmox instead?

⬆️ 276 points | 💬 329 comments


[Open-Source] FerrumPix: Photo/RAW-Editor, Viewer, Gallery, Immich and Nextcloud Client in one App

image

[Disclosure: I am the creator and maintainer of this 100% free, open-source personal project. There are no paid tiers, no SaaS upsells, and no telemetry.]

Hi everyone,

FerrumPix is a desktop photo application for Linux, Windows and macOS: a library with a viewer, a fairly extensive editor with AI functions,Immich and Nextcloud support.

My motivation behind it:

Most tools in this space tend to specialize in one area. A library app is great at organizing photos but offers little in the way of editing. A RAW converter is great for tone and color work, but stays purely parametric and never touches the pixels themselves. A pixel editor can do almost anything to an individual image, but usually has no library. And Immich and Nextcloud are great as server-side solutions, but ultimately remain browser-based, without an editor or local file management.

FerrumPix tries to bridge that gap: browse, rate, and tag your photos, then open one in an editor that supports both non-destructive adjustments and actual pixel editing. Your own Immich server sits in the same navigation tree as your local folders.The app is aimed more at hobby photographers than at professional workflows, and it really doesn't care whether you throw RAW files at it or JPGs from your phone.

It's built with Avalonia UI and .NET 10. The whole thing started as a personal project: an application that looks and works exactly the way I always wished one would. It's free and open source for anyone who can make use of it.

For transparency: yes, I use AI as part of my development workflow. That said, a project like this still involves a huge amount of hands-on work, architecture, debugging, and decision-making. I'm putting a lot of time into it, along with plenty of my own ideas and a lot of passion for the project.

Current status:

The current version is 0.9.32. The core areas are far enough along that I use the app daily myself; the focus now is on stabilization, UX and performance rather than new features.

https://www.ferrumpix.app/

I'd be glad to hear any feedback.

⬆️ 284 points | 💬 65 comments


How do you guys know if anyone’s breaking into your self hosted apps?

Recently ran into a problem that I figure isn’t unique to me.

I got into self hosting when I made a personal agent that proactively keeps me on track when I work. I hosted it on tailscale. Then I added LLM chat. And then coop games I made to play with my friends. Been a blast.

But to make it useful I put a lot of data and access in there I don’t really want others to access like realtime laptop/phone screenshots, GPS coordinates, email etc. Usually this is fine because saas will handle security for me but now I’m responsible. And tailscale and aws/gcp/azure don’t have centralized security alerts.

Basically I wanted a security camera for my network/apps so I know what’s happening in my systems in case anyone tried to break in.

Logs help a bit obviously, but there's too much and having an agent read them constantly sounds really expensive. I just want to answer: who’s trying to attack me and potentially mucking around inside?

I ended up building a security tool that runs inside my network and cloud and watches the network, VMs and auth logs, then sends alerts to me when something is off.

I know there’s tools like wazuh or elastic but they seem to be built for security professionals. I have to set up a bunch of rules and alerts which is hard and it’s a time suck to figure out what to include.

I tried using codex and claude but it just makes dumb security decisions I can’t trust at all. The tool I made scans the network and VMs to configure rules and alerts automatically and deterministically without AI at all.

If you guys have any good ideas here, lmk.

⬆️ 281 points | 💬 143 comments


PSA: Avoid self hosting AppFlowy, they patched a vulnerability in their SaaS but didn't patch the self hosted version.

There's an older thread about how they see self hosted users in r/SelfHosting so I guess it's not too surprising. https://www.reddit.com/r/SelfHosting/comments/1od9261/tried_selfhosting_appflowy_turns_out_its_not/

tldr we reported Authenticated SQL injection in their code base. After a couple of follow ups we got this response - "After investigating, we confirmed that this issue no longer applies to our commercial AppFlowy Cloud codebase."

We asked if they had any intentions of patching the self hosted version and didn't get a reply.

https://projectblack.io/blog/appflowy-authenticated-sql-injection/

⬆️ 278 points | 💬 25 comments


Still new to it all, but here's what I got so far.

https://www.reddit.com/gallery/1vuin7t

I bought this rack for like $300 (I'm still riding that high) a month or so ago and I've converted my main Win11 PC and my server thats running Ubuntu in there. The third computer will continue to be made from handmedowns from it siblings, and then I've got my Ender 3 there at the top.

I mostly at this point run AMP for hosting stuff for my friends and I. I've figured out cloudflare tunnels recently which was a godsend for trying to access my other stuff like n8n and portainer.

I have a few things that I want to do to it Hardware wise, I did buy a switch that I will be putting in there at some point.

I have been wanting to find new stuff to run in it, I want to set up PiHole and get that going, some of the other stuff sounds cool but meh (probably because I just don't understand what it will do for me) like password manager and cloud storage. But I have wanted to try and network all of the hard drives from both computers into one so I can always access anything from either computer.

If anyone has any really cool ideas or things that make their lives better please let me know!

⬆️ 282 points | 💬 58 comments


Digest: r/selfhosted: Aug 14 - Aug 21, 2026

Published: 1 month ago | Author: System

self-hosting everything

image

just kidding I love self-hosting ...

⬆️ 3,874 points | 💬 135 comments


So apparently Google will SPAM your self-hosted email just cuz **** you, that's why.

image

DKIM, DMARC, SPF, rDNS/PTR, EHLO... all correct and verified in the email "original source," BY GOOGLE. Still goes to SPAM folder because **** you, apparently. I hate Google.

EDIT - RE: Title, for the grammar gang - No, Google will not SPAM you, as in "send you SPAM." But I think everyone else got the idea....... so....

⬆️ 1,905 points | 💬 182 comments


The Self-hosted tools and apps that I rely on

image

Here is my self-hosted setup; below is a list of the hardware and apps I use daily. Overall, my setup has been rock solid and runs like a well-oiled machine; it's a very light touch, and I try to keep things simple.

The hardware

Server, Proxmox VE:

  • Supermicro X14SBM-TP4F, Xeon 6-6521P, 256GB DDR5
  • Boot: 2x 1TB NVMe mirror
  • VM storage: 4x 8TB WD_BLACK SN850X, RAIDZ1
  • Media: 10x 18TB WD Red Pro, RAIDZ2 plus a hot spare
  • LSI 9305-16i in IT mode, ICY DOCK 4-bay M.2 cage over MCIO
  • GPUs: Tesla T4 16GB and RTX 2000 Ada 16GB, both passed through to one VM
  • Dual 10GbE bonded, CX4712 4U chassis
  • Media pool goes out over NFS to whichever VMs need it

VMs:

  • Plex
  • 4x Ubuntu container VMs, 1 has 2x GPUs passed through
  • dev VM for development work
  • PBS for backups

QNAP TS-435XeU, 1U, 4x 10TB Seagate, backup target only. Nothing runs on it. It presents a 20.7TB thin iSCSI LUN that PBS uses as its datastore, and PBS syncs from there out to B2.

Network:

  • UniFi UCG-Fiber gateway
  • UniFi USW-Pro-XG-24-PoE switch
  • Three VLANs: wifi/external, internal services, lab

Media

  • Plex - All things media ~160TB
  • Sonarr / Radarr / Prowlarr / Bazarr - TV, movies, indexers, subtitles
  • qBittorrent behind Gluetun - Proton VPN over WireGuard for the whole stack
  • Unpackerr - extracts the archives the arrs cannot
  • Tautulli - Plex stats and watch history
  • Pulsarr - Plex watchlist straight into Sonarr and Radarr
  • FlareSolverr - solves the Cloudflare interstitials my indexers keep hitting
  • Pinchflat - YouTube channels pulled down as a library served via Plex
  • Labelarr - pushes TMDB keywords into Plex as searchable labels
  • PixelProbe - scans the library for corrupt files so I find out before users or I am disappointed by a broken file

Photos, documents, notes

  • Immich - replaced Google Photos; ML runs on the GPU VM
  • immich-drop - no-login upload page so family can dump photos into my Immich without an account
  • Paperless-ngx with paperless-gpt - scanned paper, LLM does the titles and tags
  • Karakeep - bookmarks, auto-tagged
  • Trilium - notes, and where most of my automation writes its output
  • MicroBin - pastebin and quick file drop
  • Syncthing - versioned file sync to my NAS that then gets synced to B2

Audio and AI (the GPU VM, T4 plus RTX 2000 Ada)

  • Audicle - turns my reading list into a podcast feed with local TTS
  • MinusPod - strips ads out of podcasts before playback, Whisper transcription on the GPU
  • Ollama and Open WebUI - local models
  • claude-code-openai-wrapper - OpenAI-compatible endpoint in front of Claude Code
  • claude-trilium-sync - dumps Claude conversations into Trilium

Infrastructure and monitoring

  • Proxmox Backup Server - two datastores, one local over iSCSI, one S3-backed straight onto Backblaze B2
  • Pulse - single pane of glass for VMs and containers
  • Grafana, Loki, Alloy - every container and host ships logs here. This has been a game changer for debugging code and other network issues, especially paired with Grafana MCP
  • Uptime Kuma - is it up
  • Healthchecks - did the cron job actually run
  • Dozzle - container logs without opening Grafana
  • Portainer - container management
  • Watchtower - image updates
  • Nginx Proxy Manager - reverse proxy on each Docker host
  • Pi-hole x2, kept in sync with nebula-sync
  • Gitea - private git
  • Apache Guacamole - browser RDP and VNC into the lab VMs
  • Ansible - config management for all of it

Off box

  • Tailscale - remote access, zero ports forwarded
  • Cloudflare - DNS, Pages (for wedding site), Tunnel for the podcast feeds
  • Backblaze B2 - offsite target for PBS and syncthing
  • Proton VPN - arr stack and general use
  • Pushover - for notifications I care about
  • autowire - disposable WireGuard endpoints on AWS when I need to exit somewhere specific

⬆️ 420 points | 💬 67 comments


Old Kindle as an e-ink homelab dashboard

https://www.reddit.com/gallery/1vq2gey

A while ago I saw some posts in r/homeassistant about e-ink displays used as dashboards and wanted to try the same but for my homelab. So I bought a waveshare e-ink panel and bricked it pretty quickly and didn't want to order another one. But I still had an old Kindle lying around which I hadn't used in years, so I tried it again with that one and this time it worked.

It shows me if something is down (Uptime Kuma), how full my media pool is, the Proxmox uptime and the weather. During the day it swaps between the dashboard and a random photo from an Immich album every 5 minutes and between 22:00 and 07:00 it only shows photos, because I don't need monitoring at night.

The Kindle itself doesn't render anything. A service on my server collects the data, draws a 600x800 grayscale PNG and serves it at /dash.png and the Kindle just runs a loop which downloads that image every 5 minutes and puts it on the screen. So it is really only used as a display.

The jailbreaking took the longest by far but in the end I am very happy with the result.

How to do it on your own:

  1. Jailbreak the Kindle. Run your serial and firmware through the wizard first and it tells you which method to use. Mine was WinterBreak. This video walks the whole sequence and worked for me.
  2. Install the KindleModding Hotfix. This is what makes any .sh file in /mnt/us/documents/ show up in the library as a tappable entry, so you can start things by tapping what the Kindle thinks is a book.
  3. Install MRPI and KUAL, both from that thread.
  4. Block OTA updates with renameotabin. An update is the one thing that can still take the jailbreak away.
  5. Set up SSH with USBNetwork (there's a good writeup here), before anything else. Starting the display loop stops the reader UI and takes the touchscreen with it, so SSH is your way back in.
  6. Run the render service on your server so it serves a finished PNG.
  7. Put the fetch loop script on the Kindle and start it.

Wrote a more detailed guide about the setup on my personal site (https://mxd.codes/articles/an-e-ink-homelab-dashboard-on-a-jailbroken-kindle). You could also show something completely different on it, like Home Assistant data or a reminder which bin has to go out this week. All you need is an image.

⬆️ 184 points | 💬 17 comments


My Homepage after 4 months on the self-hosting journey.

image

I just started my self-hosting journey in April after I got tired of my Xfinity modem. I ran what feels like miles of Cat 6, built a rack, bought the PCs and domain, etc etc and now I feel super accomplished. I knew practically nothing about all this back in March.

Possibly the most fun I’ve had is building this simple little homepage dashboard to give everything a face. I stole lots of inspiration from everyone here. It now serves as a true homepage with all the frequent sites and services I ever view. Just felt like sharing.

Truly appreciate everybody on r/selfhosted and r/homelab.

⬆️ 308 points | 💬 32 comments


SparkyFitness v1.6.2 - A Self-Hosted alternative for MyFitnessPal, Flo, Hevy, Shotsy & More

https://www.reddit.com/gallery/1vqe7qg

We just crossed 5.2k+ stars in Github and have 98 amazing developers contributing to the project. We are scaling faster than ever and estimated to 7k+ users who are using SparkyFitness. It could be even more as we don't collect anything and this count is based on active downloads in Github, Google & Apple app stores.

https://github.com/CodeWithCJ/SparkyFitness

If you haven't tried SparkyFitness yet, I'd love for you to give it a spin and let us know what you think.

Thank you all for providing your valuable feedback in my post last month. We were able to improve the workout/exercise workflow strong enough and equivalent to commercial apps out there. We are happy to include more enhancements if we missed anything.

https://github.com/CodeWithCJ/SparkyFitness/discussions/1692

I also added comparison of SparkyFitness against various other Opensource and Commercial apps as this was one of the question asked often and finally I was able to complete it. (but might have mistakes, use it as reference only)

Core Features

  • Nutrition, exercise, hydration, sleep, fasting, mood and body measurement tracking
  • Period Cycle, Pregnancy, Medication & GLP1 tracking
  • Goal setting and daily check-ins
  • Interactive charts and long-term reports
  • Multiple user profiles and family access
  • AI Chatbot & MCP Server
  • Light and dark themes
  • OIDC, TOTP, Passkey, MFA etc.

Health & Device Integrations

SparkyFitness can sync data from multiple health and fitness platforms:

⬆️ 273 points | 💬 87 comments


I put my receipt printer on the internet, send me something

https://print.tomgroenwoldt.de

You can print ascii art or just regular text. There also is a live stream.

Edit: I ran out of paper! Thanks guys, this was fun!

Edit: It's back online with a new roll of paper!

Edit: Daily limit is reset again. 200 prints to go.

Edit: Because some people asked, it's open-source and available here: https://github.com/tomgroenwoldt/posprint

⬆️ 280 points | 💬 148 comments


Aurral is about to pass 1 million downloads, and 2.5.0 is a big step toward a real self-hosted music library

image

Hey everyone! It's been a while.

Aurral is about to pass 1 million total container downloads, which is still a little hard for me to believe. That number is downloads, not unique installations, but it means a lot for a project that started as a very specific personal tool.

Quickly, if you're new to Aurral

Aurral is a self-hosted music discovery and library app. It sits alongside tools like Lidarr, slskd, and Navidrome when you use them.

You search for artists and releases in Aurral, preview music, decide what you want to keep, and then manage and play that music from Aurral's Library. You can also connect a Subsonic-compatible client and listen outside the Aurral UI.

It runs in Docker, and your music stays on your own hardware.

Discover Page

What's new in 2.5.0

The new 2.5.0 release is going out today after spending time in Nightly.

  • A native Library for browsing and playing owned music.
  • Clearer separation between Discovery and Library.
  • Hosted Subsonic support for browsing and playing Aurral's library from compatible clients.
  • Flow tracks can be favorited, kept, promoted into the Library, and added to permanent playlists.
  • Local listening history and scrobbling.
  • Better playlist imports, syncing, download matching, and playback cleanup.
  • You can import and sync Spotify, Last.fm, and Listenbrainz playlists
  • All new theme support with terminal.sexy integration

A few things worth trying:

  • Open Library and play an artist, album, or track directly.
  • Open an owned release from Discovery and move into Library for full playback.
  • Favorite a Flow track and check that it stays in your Library.
  • Connect a Subsonic-compatible client and browse your music outside the Aurral UI.
  • Import a playlist from Spotify, ListenBrainz, or Last.fm.

New Library View

Release
Documentation
GitHub repository

Thanks to everyone who has tried Aurral, filed issues, tested Nightly, or told me where the rough edges are. If you use it, I would love to hear what you are doing with it and what still needs work.

⬆️ 349 points | 💬 61 comments


Digest: r/selfhosted: Aug 07 - Aug 14, 2026

Published: 1 month ago | Author: System

Any downsides to taliscale? Seems like an incredible amount of value for free

I've recently moved all my devices to it, and added some friends/family to my network so they can play with some of my self hosted tools

Any horror stories I've missed? Am i blindly opening myself up to exploits? Are there better alternatives?

Seems too good to be true tbh

⬆️ 241 points | 💬 185 comments


Searched for Proxmox VE on the Internet

image

Shodan, searched pve-api-daemon/3.0, got 170k matches, big chunks on: - Hetzner - OVH - Linode

Many behind :3128 proxy, but 30k just like that on :8006 too.

Is this normal? Expected? Why are people doing this?

⬆️ 263 points | 💬 40 comments


PSA for maintainers: "we'd like to sponsor your project" emails through pump.fun are not real sponsorships

I maintain a self-hosted project and received an email yesterday for a sponsorship like many other companies have done. However, this one was different: https://imgur.com/a/OKGMWFx

They started off with a simple and flattering email of what my project does (probably AI description) and that they have shared it with their team and offered to sponsor me like many other companies have done in the past. They say that the sponsorship will come through "Pump.fun's GitHub Sponsorship integration" however that integration does not exist.

Here is what is actually being proposed. They launch a memecoin on pump.fun using your project name as the ticker. Every trade on that token pays a fee of ~1%. The token creator receives a share of those fees. Thats the money for the sponsor, its not them writing you a check or a wire transfer.

A five figure payout means something around a million dollars in trading volume moved through a token with your projects name on it. The token makes nothing and has no claim on anything whatsoever. Whatever money came out of it came from people who bought it and most pump.fun tokens end up near zero. Your sponsorship is literally a cut of peoples loses.

I then proceeded to tell them no and they told me I would get 100% of the fees however that was not my concern. Whether I get 1% or 100% of peoples loses that does not change the fact that I don't want it. They also mentioned they would generate trading activity themselves to make it a more attractive token for people to lose their money on.

The challenging part of this is that the money is real: https://thoughts.greyh.at/posts/pumpfun/ . Checkout this post. He received around $11,000 within a day and confirmed that they literally do pay out. However, he also said that afterwards there were no PR's, no issues, no activity, and no one wanting to test his app. His conclusion was that the whole thing was for traders rather than anyone who wanted to support open source. He also said that he probably wont do it again.

The token only draws volume because your project is real and your name is attached to it. Thats the entire product. The token, the wallet, and the fees that are given to you are permanently public and are attributed to you. So when the coin collapses, the people holding it see a coin named after your project and the maintainer who took a cut of peoples loses. After that, they move to the next repo.

My suggestion is that if you get one of these, you do not have to be rude about it, but just say that you don't consent. Know that nothing stops someone from launching it anyway so be warned about that and if you do see it happen, consider letting your community know.

I'm not trying to claim fraud and I'm not going to deliberately name the person who emailed me (they likely change their name every email since their PFP is clearly AI generated and its a gmail account).

⬆️ 227 points | 💬 20 comments


What I wish someone told me when I started

Just remember that not every self hosted application has a team of experienced devs behind it ensuring security is adequate. It’s super cool to setup 15 different services/containers and configure them exactly how you want, until it comes time to maintain and update.

Every other day I see a new self hosted program that someone made in an afternoon. Usually, there’s absolutely zero security or failsafe built in if a bad actor were to target you. Also, you never know who’s an upcoming, eager developer, versus a seasoned red black-hat trying to sneak malware into your Docker stack.

There’s been countless CVEs that affect self hosted applications. And many more we haven’t discovered yet. Last week my buddy had to take his main machine offline because the application he was hosting was unknowingly working as a botnet.

You’d have to pay me a lot of money to get me to self host some shit Bob Smith vibe coded in his basement. Even if the author doesn’t have malicious intentions, you can’t expect professional, or even an acceptable level security unless there’s a real team working on the project. Even then, no one is safe.

If you’re just starting out and aren’t too sure what you’re doing, please stick with the basics until you get your footing. Hosting is fun, but you quickly get diminishing returns when you enter the phase “Damn, what else should I host?”.

With all that being said I run lots of containers, but only ones that have been tried, tested, and proven to have responsive developer(s). Good luck!

Edit: I wasn’t expecting so many technical people to show up to this thread. It truly was awesome seeing everyone’s view on this, but just remember this post was made for people who are new to self hosting or are not technically inclined. There’s many people who started from ground zero, including myself. I wish someone would have been transparent with me and actually explain why hosting anything and everything may be a bad idea in the long term.

⬆️ 179 points | 💬 75 comments


Scored the homelab lottery

Ive always wanted to start self hosting but never had the budget to do it, i tried building a pc with spare parts i had but the price spikes for ram and storage kinds ruined it for me.

But when i least expected, i received a call from my friend telling me how the place he works had a bunch of spare pc parts and asked if i wanted it, which i obviously said yes.

Fast foward to today and now i went from a spare cpu and power supply to 3 amd fx pcs, 32gb of ddr3 ram, 12 500gb hdd and 1 240 gb sata ssd, all working!

Now i need help to decide what i should do to start building my homelab, for example i have no idea how i would connect all of those 12 hdd lol. My main focus is creating a media server with jellyfin and making a self hosted google drive like system for all my data and photos.

⬆️ 209 points | 💬 54 comments


Best OS for a server?

Trying to get into self hosting as a college student, and my brother gave me an old macbook air 2017 (intel chip) that i thought could serve as a simple server to get my foot in the door.

I've used Arch for a little while now on my school laptop, but I'm not super well versed in the options available with linux, nor do i really use most of the features Arch provides (im a larper 😔). The macbook is too old to support MacOS, and I was looking at what options i have with linux. I dont need anything bleeding edge, the easier the maintenance the better.

One of my first goals was to maybe host a minecraft server or something on it, mostly to gain some experience.

Ubuntu server seemed like a good option, I'm fine not having a gui for anything, and Debian seemed appealing as well.

Was curious what experience you guys have using these OSs for hosting things and what you would recommend I try out.

Thanks in advance for the help :)

⬆️ 178 points | 💬 490 comments


Planka removing SSO from Community edition

Planka is a snappy Web Kanban with a decent API. The company offers some additional functionality with their paid "Pro" plans.

They have now announced to move SSO/OIDC out of the Community edition into Pro.

What do you think about that?

What alternatives exist?

Anyone interested in forking?

⬆️ 190 points | 💬 93 comments


Lightweight Headless Browser With Native Rendering, No Chromium

https://github.com/h4ckf0r0day/obscura

A lot has changed since I last posted here 4 months ago. Got some harsh criticism back then and it was honestly deserved, the project was early and messy. But we kept going.

Obscura is a headless browser built in Rust for scraping and automation. V8 engine, native rendering, 30MB memory, 80ms page loads.

Works drop-in with Puppeteer and Playwright.

Just shipped rendering which includes screenshots, PDFs, live video capture. No Chromium. 20k stars now.

https://github.com/h4ckf0r0day/obscura

obscura serve --port 9222 and point your scripts at it. Happy to answer questions.

⬆️ 191 points | 💬 62 comments


Digest: r/selfhosted: Jul 31 - Aug 07, 2026

Published: 1 month ago | Author: System

The 3 Stages of Self Hosting

image

I'm lowkey on stage 4

⬆️ 576 points | 💬 32 comments


Petition to ban "I built" in post titles

When we all know it was really Claude that built it.

⬆️ 540 points | 💬 171 comments


Forgot and experienced true hell with :lastest

image

Remember to always set version numbers in your docker containers, or an unexpected update will creep up on you.

Now can you guess which popular service got a breaking change?

⬆️ 765 points | 💬 142 comments


Is it safe to use a Galaxy S20 Ultra with a detached back cover as a 24/7 Minecraft server?

image

The back cover of my phone detached. Is it safe to use it in this condition? I plan to use this phone as a Minecraft server.

⬆️ 369 points | 💬 110 comments


Reminder to BackupBeforeYouFKUP - Do you do off-site backups?

image

This is your reminder to check on your backups, setup backups and test your backups. 🙌

I'm currently using Duplicati with 2 local backup sites and hetzner/Google drive for remote. What are you using?

⬆️ 318 points | 💬 106 comments


Do other Stream Deck owners use them for selfhost shortcuts/ actions? I was thinking of throwing in some to perform diagnostics, etc

image

⬆️ 328 points | 💬 66 comments


What to do with 100s DDR3 ram?

image

So at my workplace they just replaced all old PCs with new ones and for some reason, they took the ram out of the old ones.

There’s a box with more than 100 of these 2GB ram sticks. We are just going to send them for disposal but I wanted to know if anything useful can be done with these?

⬆️ 262 points | 💬 87 comments


Tracearr v2.0.0 - Media Library, One Identity Per Title, Public API v2

https://www.reddit.com/gallery/1vgi06c

This has been a long time coming, and in progress for quite some time. Excited to see what everyone things, and what these new features allow you to learn about your server!

BACK UP BEFORE UPGRADING. This release migrates the database heavily. If you need the escape hatch, a 1.5 backup restores cleanly on 2.0.

New Media section

Browse your whole library as a poster wall with an A-Z rail and filters for library, resolution, HDR, size on disk, and watched - two-tone checkmark for "you watched" vs "someone watched". Detail pages list every copy of a title with per-file quality, library, and size. Genre breakdown, storage, and watch pages round it out.

One identity per title

The same movie on two servers is one row everywhere now - stats, leaderboards, history. Seasons and music get real identities too, and wrongly split titles heal themselves.

Every file counted

Tracearr used to read a title's first file and drop the rest. Now every version is tracked: 4K + 1080p copies, duplicate libraries, mirrored files counted once. Storage totals are honest, duplicates catches same-server copies, sessions record which version actually played, and 1440p/8K no longer count as SD.

Public API v2

Bearer tokens, rate limits, OpenAPI docs served in-app. Built so apps that use Tautulli can use Tracearr instead.

EDIT: Just want to also add that V1 is unchanged. There are no plans to ever remove it either, so there is no need to rework your integration if V1 already met your needs!

Mobile: every tab, every server

Rolling out shortly after the 2.0 app update. Server selection is global now - pick All, one server, or any subset from any tab, and it sticks across restarts. It used to be a dashboard-only trick that quietly collapsed to one server everywhere else. Navigation got rebuilt on native tabs: the tab bar survives detail pushes, and the drawer is gone in favor of a server sheet and header buttons. Also in this round: iOS 26 header buttons stop flashing white on tab switches, the stream map matches the dark theme on both platforms, and servers behind Tailscale are reachable on iOS again (App Transport Security was silently blocking them).

Under the hood

  • Plex library changes sync in seconds via server events (Jellyfin/Emby get this with the new SSE plugin release)
  • Upgrades show migration progress instead of looking dead, and a bad migration can't boot-loop the server
  • First sync is much faster
  • Fixed a silent gap in sharing detection on polled servers
  • Stale content and ROI stop double counting merged titles; duplicates stop counting mirrored files twice
  • OpenAPI specs publish as release assets, so the docs site always renders the spec for your version

Notes

  • Counts may shift after upgrade as versions and identities settle - that's the double counting going away
  • Overall trust scores move too: you now see a person's worst account, and violation totals actually count - both sat frozen before

Discord | Documentation | Website

⬆️ 232 points | 💬 82 comments