Proxmox is a virtualization solution: let it do its job and run a vm with opnsense.
It is simple both from a virtualization and a networking perspective; your hypervisor is 'hypervisoring' and the firewall is firewalling, easier to maintain and debug, no custom thinkering required.
If you are at home go with #1, more fun and lots of discoveries; if you have to pay the bills, go with #2, tested, solid, easier to handoff to your colleagues.
IMHO you should look/ask for such a feature in a google group because big g may have a business case for such a feature: it would pull back in those users who try to escape.
and that should not be an immich feature but a google one.
as a self-hoster I prefer to have control on my data; a solution to feed my data to google through a third party (that may do whatever it wants while performing the transfer) is the exact opposite of what i'm trying to achieve and would have little to no value for me.
If the main site gets compromised the credentials there must be considered lost and known to che attackers.
with a pull backup that's not an issue because the main site has no access to the remote system; it is a process on the remote site that has credentials to access the main site and not the other way around.
the remote system may receive retrieve a compromised copy of the data, but the attacker cannot tamper with previous backups so recovery is still possible.
last thing missing in your post is a complaint for slow migration on a 1gbit link...
you can complain as much as you want because proxmox is not vmware or you can embrace proxmox and make the effort to move/update/refresh your knowlwdge on to the new environment.
sarebbe bello se oltre a prevedere e mitigare/intercettare il comportamento stupido dell'utente (stupido?) con la soluzione tecnica si puntasse anche alla formazione.
ma la soluzione tecnica costa meno, richiede meno risorse, fa fare bella figura più alla svelta.
Add a second node using the new drive, move all vm to the new node, decommission old node, rebuild the old node with the new drive.
You can get away with a disk clone but in my opinion a vm move is the proper way to go.
Adding a new node you start with a clean install, any quirk you have on the old hw will be finally washed away (or will bite you back and be properly documented), you have a quick way back should anything go sideways (the clone too provides a quick way back, but i like this way much more ^^), you get some hands on multi node experience that will be useful for ha setup.
Accidenti, mi hai colto alla sprovvista.
Non me l'aspettavo veramente.
Sembra quasi che gli statunitensi abbiano fatto quello di cui accusavano i cinesi.
Incredibile.
Sconvolgente.
(Da leggere con il tono di Natolia/Marina Massironi mentre presenta i mimi)
I wouch for the VPN route...
VPN servers are built to be exposed, are hardened/engineered to resist the harshness of the net and are somewhat safe even with default settings.
Should you publish on the wild a few web apps, you would have to harden, monitor and manage a bunch of environments and/or frameworks with a load of quirks each.
A VPN is easier to maintain and safer for your data with a lower effort.
Maybe there is some relation with orange man erratic behaviour, canadian pm speech in davos, europe considering to abandon usa cloud and other countries that may follow suit?
For me it depends on the hw on site; if it is properly setup and in an adequate environment i have no issue anywhere.
(me too i did #2 at home...)
Proxmox is a virtualization solution: let it do its job and run a vm with opnsense.
It is simple both from a virtualization and a networking perspective; your hypervisor is 'hypervisoring' and the firewall is firewalling, easier to maintain and debug, no custom thinkering required.
If you are at home go with #1, more fun and lots of discoveries; if you have to pay the bills, go with #2, tested, solid, easier to handoff to your colleagues.
IMHO you should look/ask for such a feature in a google group because big g may have a business case for such a feature: it would pull back in those users who try to escape.
and that should not be an immich feature but a google one.
as a self-hoster I prefer to have control on my data; a solution to feed my data to google through a third party (that may do whatever it wants while performing the transfer) is the exact opposite of what i'm trying to achieve and would have little to no value for me.
If the main site gets compromised the credentials there must be considered lost and known to che attackers.
with a pull backup that's not an issue because the main site has no access to the remote system; it is a process on the remote site that has credentials to access the main site and not the other way around.
the remote system may
receiveretrieve a compromised copy of the data, but the attacker cannot tamper with previous backups so recovery is still possible.Fifa Agent Platform -> FAP
pun intended?
Furry equipment FTW
https://fursonafy.com/fursuit-cooling-vests-everything-you-need-to-know/
last thing missing in your post is a complaint for slow migration on a 1gbit link...
you can complain as much as you want because proxmox is not vmware or you can embrace proxmox and make the effort to move/update/refresh your knowlwdge on to the new environment.
sarebbe bello se oltre a prevedere e mitigare/intercettare il comportamento stupido dell'utente (stupido?) con la soluzione tecnica si puntasse anche alla formazione.
ma la soluzione tecnica costa meno, richiede meno risorse, fa fare bella figura più alla svelta.
magari in questo caso faranno entrambi.
ecco cosa succede quando chi fa le regole non ha idea di cosa sta regolando...
dato che il problema sono le persone che si fanno fregare, cambiare strumento non risolve il problema.
così come gli utenti cliccavano a caso facendosi fregare gli account signal, così si faranno fregare gli account della nuova app governativa.
This is the way. 🤭
The second install should be easier since is done just after a test one.
Add a second node using the new drive, move all vm to the new node, decommission old node, rebuild the old node with the new drive.
You can get away with a disk clone but in my opinion a vm move is the proper way to go.
Adding a new node you start with a clean install, any quirk you have on the old hw will be finally washed away (or will bite you back and be properly documented), you have a quick way back should anything go sideways (the clone too provides a quick way back, but i like this way much more ^^), you get some hands on multi node experience that will be useful for ha setup.
Normal background noise. ssh is a well known protocol/port and scanning is automated.
Accidenti, mi hai colto alla sprovvista. Non me l'aspettavo veramente. Sembra quasi che gli statunitensi abbiano fatto quello di cui accusavano i cinesi. Incredibile. Sconvolgente. (Da leggere con il tono di Natolia/Marina Massironi mentre presenta i mimi)
my home router is the stock one from my isp and have no vpn capabilities.
I put a port forward on the router and then configured everything on the internal node; in my case it is an opnsense vm running on proxmox.
I wouch for the VPN route... VPN servers are built to be exposed, are hardened/engineered to resist the harshness of the net and are somewhat safe even with default settings.
Should you publish on the wild a few web apps, you would have to harden, monitor and manage a bunch of environments and/or frameworks with a load of quirks each.
A VPN is easier to maintain and safer for your data with a lower effort.
The article is on a 'pay or ok' site.
Leggendo l'articolo vengono un paio di domande... La nuova piattaforma europea di gestione in che ambiente gira? Si appoggia a qualche servizio cloud?
Maybe there is some relation with orange man erratic behaviour, canadian pm speech in davos, europe considering to abandon usa cloud and other countries that may follow suit?
Just sayin'...
Se vi è possibile, togliete leganerd dal vostro giro di pubblicazioni.
Hanno una policy dei cookies 'pay or okay' che è tutto tranne che ok.
Ci sta che campino di pubblicità, non ci sta che ti obblighino ad accettare quella profilata.
Un articolo a caso che spiega la questione: https://i-law.it/privacy/il-modello-pay-or-ok-alla-prova-del-dma-la-sanzione-della-commissione-europea-a-meta-e-la-ricerca-di-una-terza-via/