pleksi

u/pleksi@sopuli.xyz
1 posts · 42 comments

Recent posts

Recent comments

No formal education in IT, I'm a GI surgeon.

I built my own gaming pc's in mid-late 00s and i also knew some basic html just by the virtue of being on the internet as a kid and trolling at bulletin boards/trying to build some websites.

In 2018 i was miserable as a GP after finishing my medical decree. I was thinking about changing careers and I did most of the online version of Harwards CS50 course for fun. In the end i did become a surgeon and not an engineer.

In 2025 Trump II happened and seeing that the tech billionaires were in on it, I lost faith in the USA as a country. I wanted to get off all of my subscriptions and american big tech services, which I'm happy to say ive almost completely achieved. As i was searching for the best replacements for all the services I realized the cleanest and most future-proof path is to host my own.

I run nextcloud, immich, jellyfin, matrix, home assistant, paperless, ollama etc etc. There's still a whatsapp account unfortunately. It is mirrored to my matrix instance so the (grapheneOS) phone i use daily doesnt have a whatsapp client but a matrix client instead. Nothing is happening on the phone whatsapp runs on.

This.

And graphene actually makes things very easy for you: every profile can have regular and private version of any given app.

The private side is essentially a different user with its own set of vpn options but you can easily navigate in between provate and normal apps.

Im using the regular profile for staying connected to home. All traffic is routed to home and then to proton.

Everything in the private section goes through regular proton vpn(the app on the phone) so any traffic to the web also has a different exit node to my "home" traffic (albeit a proton one).

I then have a separate profile called incognito with only proton pass, vpn and onion browser on it.

I’ll add pangolin to the list of things to think about trying. It was relatively easy to set up and it can run locally or on a vps. If it’s on a vps you dont need a constant IP or ddns because your hone server will connect to pangolin on the vps and the vps will serve the apps. youll point the dns records to your vps.

It’s what i use for my extended family to reach my immich instance. No complaints yet whatsoever. It’s traefik+crowdsec+wireguard under the hood but all abstracted into a maintained, easy to use GUI. Youll have granular control over which users can use which services/subdomains and geoblocking etc is effortless.

I put a centralised authentication layer (pocket id) on top of it for easier enrollment across various apps im running but for homeassistant only the built in 2FA should be enough.

on Confirmed: Cancer Free! · c/world · 4 pts · 200d

Yea in get that, i was talking in terms of total costs.

E: actually looked it up, most likely the whole thing wouldve been max 10000euros to the taxpayer around here (Finland). Workup+surgery+hospital stay.

on Confirmed: Cancer Free! · c/world · 10 pts · 200d

Congrats! Sounds like an excellent prognonsis!

Also, Jesus fucking christ a 100000 dollars for a workup+surgery? A similar case is propably no more than 10-15k€ in northern europe (paid by the taxpayer of course).

This is what i did but on the router. I have openwrt on the router. You can install an extension called PBR (policy based routing) on it.

Then you set up one wireguard interface that’s in the same firewall zone as your LAN to your lan and another that’s in the WAN. You can create policies to route any outbound connections (including the ones from your mobile client devices) through the commercial WAN wireguard connection.

In addition for family members access i set up a pangolin instance (kind of like tailscale but selfhosted) on a Hezner VPS and a very simple oauth provider (pocket id) for authentication. Ive got a bunch of users and nobody had any problems with the signup process after i sent them the invite link.

That way i can always be directly in my lan but other users can access without accessing my lan at all.

Surgeon.

Seeing tech ceo’s at the trump inauguration got me sick in the stomach. I unsubscribed from everything out of spite and nausea and learned to selfhost over the course of what is almost a year now. At first it took up all my spare time and made my wife crazy. Now it’s been several weeks since i last had to sudo anything.

It also opened my eyes to how stupid everything IT related in my country is. My municipality for example bought for what has now become a billion fucking euros a digital health record system from Epic. It’s the shittiest piece of software ive ever used, fully closed source and there’s ongoing customization costs trying to get it to work. We’re also a 100% onboard with office360 (copilot and all).

As a phycisian ive used AI to check if i have missed anything in my train of thought. Never really changed my decision though. Has been useful to hather up relevant sitations for my presentations as well. But that’s about it. It’s truly shite at interpreting scientific research data on its own for example. Most of the time it will parrot the conclusions of the authors.