I'm not familiar with firejail, sorry. I guess that firejail (or regular containers with podman) can be ok for CLI tools which only need access to very specific paths, if any. But for graphical applications like games you probably have to grant a lot of access.
Using a separate user is simpler and it's guaranteed that the software can only write to the home dir of the user (and other temp paths like /tmp that you don't care). In case of problems, just wipe the home dir and you are good.
Flatpak sandboxing is weak. For truly untrusted software like pirated games I'd definitely go for a different user which in Linux provides a very strong isolation.
And I thought this was the cover of songs in the key of life by Stevie Wonder
I'm not familiar with firejail, sorry. I guess that firejail (or regular containers with podman) can be ok for CLI tools which only need access to very specific paths, if any. But for graphical applications like games you probably have to grant a lot of access.
Using a separate user is simpler and it's guaranteed that the software can only write to the home dir of the user (and other temp paths like /tmp that you don't care). In case of problems, just wipe the home dir and you are good.
Flatpak sandboxing is weak. For truly untrusted software like pirated games I'd definitely go for a different user which in Linux provides a very strong isolation.
I just use a different user with no privileges to run any pirated or suspicious software.
Yes, of course.
Yes
Tampax vibes
If this is true, this is very fucked up, definitely in the worst 1%. I'm sorry.
Can't wait!
Point the hostname of your service to the IP of the proxy in the DNS.
For the certs you need an internal CA. I use Step CA which has ACME support so the proxy can get certificates easily.
Add the root CA certificate to your computer certificate trust store.
Profit!!
Try to avoid installing extensions, they have too much privilege in the browser.
I have a TB of music in my Jellyfin server but I still listen steaming services mostly because it's more convenient.
This article is propaganda to normalize the enshittification of the houses. Ask any family with kids if they find the dishwasher useful.
Bicho bola in spanish
Hi, can I get an invite? Thank you.
I see, thank you.
I use Bitnami SealedSecrets. Does anyone know if that's going down the shitter too?
Spam
I have had Jellyfin directly open to the Internet with a reverse proxy for years. No problems.
Incorrect. Not run as root, but launched by root in a system service (runs as the pipewire user).