I have my important server stuff (docker and immich etc) duped via syncthing to an old external USB drive attached to my office mac which then has Backblaze Personal Backup running. That backs it all up with no storage limit for £70/year on their 2 year plan.
The only downside is if the drive isn't connected for a few days, it checks it all again on reconnection.
I have about 4TB of files most of the time.
This way I have 3 copies of my files: 2 local, 1 remote.
EDIT: forgot that I also have 1yr retention on the files so in theory I can grab anything that I deleted up to 1yr ago.
So this has been interesting to me as I'm travelling at the moment and wireguard has been blocked on the guest wifi I've been on across the hotels, I've had to rely on cellular instead.
I've just tried Teleport on my Unifi router and that works. I believe it uses wireguard, and it is taking up to 20secs to connect, but I'm now curious as to what it's doing to bypass the VPN restrictions that are blocking plain wireguard.
I had Infomaniak for a while, and tried the kdrive, as like you, it was the cheapest cloud drive storage. However I gave up with Infomaniak as in the end they felt a bit, er, fussy in the way they ran it all. It just didn't fill me with confidence.
For me, for all archiving, the simplest solution has always been Backblaze Personal backup. Yes its an extra cost per month, but it will also backup all of your main computer, and any external drives. You can add an encryption key too. The only downside is it being a US company.
I have a 5TB external USB that dupes all my docker stuff as well from my server to my Mac, so it's an all-in-one backup solution for me.
I recommend the Colota app for tracking. I use a mix of Reitti and Dawarich at the moment to log the info (both of which support sharing) as I can't work out which I prefer.
I use a Pangolin reverse proxy with OIDC (PocketID) for family access to services, along with CrowdSec. For the Immich app access which needs to bypass auth login through the reverse proxy, I use 'link share' in Pangolin that gives me header tokens that can be entered in to the Immich app under Advanced settings.
I've been an Immich user for over 2 years now, so it's been a journey for me to implement it to this standard.
Or as someone else suggests, try CloudFlare with something like Google Auth login. Just be aware that you are then exposing all your traffic to Cloudflare. I take that as a small sacrifice for simplicity.
Similar to your story 1: I needed to renew my mortgage and it was an instant thing if I did it via their app (for security reasons apparently), or it became a paper form and post thing.
I tried to do it via a web portal, but that didn't work. I called them up to see how else I could complete the renewal, but that opened a can of worms of speaking to a woman on the phone, utterly unable to fathom why I couldn't install their app on my Android phone: GrapheneOS (play store installed, but it denies their app on my dangerous 'rooted' phone).
The woman I was speaking to thought I was an idiot who didn't know how to use Android. FFS.
Ah thanks. I know I have scratched the surface with what MA can do, and it is one of the more useful things I self host. Music Assistant and Immich are the absolute must haves.
I've found that Music Assistant has worked well for group casting audio for me with Google Minis and Chromecast Audios. Although I've not had it running all day, but it has removed the hassle of it stopping from WiFi disconnects from my phone.
Always looking for new ways to do things, so will look out for pts 2 & 3.
You can run docker stacks with external IPs, no? I run all mine from Unraid, through Dockhand as compose stacks, with some ports on the host, others as external IPs on VLANs. But yes, like you I would actually like to move them to VMs so it's easier to backup, and service, without taking the host server offline.
It starts to get like Inception levels of depth on VMs and hosts!
Take from this anything of use to you: I syncthing my important Unraid server stuff to a MacBook running Backblaze with a 14TB external drive. DNS is handled by NextDNS in the cloud anyway, so it's just Immich and other random family oriented services for me. I use Pangolin for exposed services.
You could use syncthing (or Resilio) over a tailscale or headscale network or whateveritispeopleuse to a remote PC.
My Docker compose files and VMs are backed up once a week via plugins on Unraid, which of course get duped via syncthing to the MacBook.
I did try a Hetzner Storage Box for a while to replace Backblaze, but the hassle of having to keep an eye on the syncing was a pain and I fell back in to Backblaze on the MacBook as it's a set and forget (as long as they don't change the filetypes ignored...). I may go back to a Storage Box again.
I do also want to look into redundancy with a spare server though so it becomes quicker/easier to get it all up and running in event of failure. This is where selfhosting starts getting serious!
Just chucking this out there to help with the fediverse.
So, generate fake images of you in new clothing... does that suggest the Japan holiday photos are also meant to be fake?
Not sure that it demonstrating it's ability to render fake photos makes a good demo to show it sharing 'real' photos.
And I wonder if those Japan photos are actually real or faked for the ad. Which makes it even more of a conundrum as to why bother with anything on it if it can just make everything up for you.
I ran BI for years, but left them for a Ubiquiti device. Yes it required new cameras, and of course the investment in a UniFi device, but damn is UniFi Protect good. Does great detection and no subscription or fees of any kind, plus gets frequent updates and feature improvents. Not a solution for everyone, but I believed the hype of BI for years and thought there was nothing better. Turns out there is.
Hi mxdcodes. I have been using your app for the past month in a sort of testing phase with Darawich. I have used GPS Logger and Reitti since October last year, which is still running, but Colota offers a lot more exciting possibilities of data collection and so I'll probably switch across pretty soon. I got hit by the bug a while back of it stopping once entering a geofence, but I saw that got fixed promptly so thanks for all of this.
I love all that you and others who code for the (wider) selfhosted community offer, so let me say that for every person criticizing your app and all the effort you have put in, there are hopefully 1000x more of us who are truly grateful for what you and others do. I find it odd that people who are concerned about having their location history hacked by someone are actually wanting to record their location history in the first place. Seems the obvious answer is to... not track your location history with ANY app.
However I may have spoken too soon with Colota... it stopped registering my location after a first trip, and wouldn't restart tracking until I restarted my phone (GrapheneOS Pixel 9). I need to look at the logs and maybe raise an issue.
Dawarich has had some great updates in the past few weeks, and I'm hoping Colota + Dawarich is my future family tracker system as they both have a very nice feel to them.
GPS Logger + Reitti is my background system atm while I mess with Colota & Dawarich.
I've been using Colota this weekend sending data to a Dawarich server. I like that you can filter out inaccurate GPS readings by setting an accuracy threshold, so this removes any false points that I tend to get with other location apps.
I've tried GPS Logger for Reitti, and the new Android Dawarich app, but so far, Colota seems the best (early days). It has the nicest ui as well.
In terms of what to enter, you need to find out what HA requires for the URL to receive data, then set that in the Colota app. Colota will just store the location data until you set a remote end for it to connect to.
I haven't tried TBH. Because the VPS is restricted to my home IP for SSH using Hetzner's firewall, I wireguard to home, then SSH to the VPS direct. I've been updating Pangolin since last summer, but haven't really played with the newer features. I should have a proper look really.
I do this currently. I have a Hetzner VPS with Pangolin, giving access to family services like Immich etc, and my own nerdy services I keep locked to my home IP, and if I'm away from home, I tunnel in with Wireguard and hence then the home IP kicks in and they work.
You can issue traefik IP rules with Pangolin as well to limit what IPs can access services.
I have Pangolin and all family services behind Pocket ID with passkey only auth.
The VPS I protect with Hetzner's firewall, so only SSH is allowed from my home IP.
The whole setup is as secure as I can make it. My family would just roll their eyes at any VPN I asked them to use, so it has to be publicly accessible for some things annoyingly.
I also have private services coming direct to my home firewall away from the VPS (for speed efficiency), and for truly public services (websites), I have those tunneled through a Cloudflare tunnel that can handle Google Auth for WordPress login pages etc.
It made me uncomfortable to start with using the VPS, but in time, confidence grows.
You can try Colota as a way of recording your phone location with its own filtering before it uploads to Reitti/Dawarich
I have my important server stuff (docker and immich etc) duped via syncthing to an old external USB drive attached to my office mac which then has Backblaze Personal Backup running. That backs it all up with no storage limit for £70/year on their 2 year plan.
The only downside is if the drive isn't connected for a few days, it checks it all again on reconnection.
I have about 4TB of files most of the time.
This way I have 3 copies of my files: 2 local, 1 remote.
EDIT: forgot that I also have 1yr retention on the files so in theory I can grab anything that I deleted up to 1yr ago.
So this has been interesting to me as I'm travelling at the moment and wireguard has been blocked on the guest wifi I've been on across the hotels, I've had to rely on cellular instead.
I've just tried Teleport on my Unifi router and that works. I believe it uses wireguard, and it is taking up to 20secs to connect, but I'm now curious as to what it's doing to bypass the VPN restrictions that are blocking plain wireguard.
I had Infomaniak for a while, and tried the kdrive, as like you, it was the cheapest cloud drive storage. However I gave up with Infomaniak as in the end they felt a bit, er, fussy in the way they ran it all. It just didn't fill me with confidence.
For me, for all archiving, the simplest solution has always been Backblaze Personal backup. Yes its an extra cost per month, but it will also backup all of your main computer, and any external drives. You can add an encryption key too. The only downside is it being a US company.
I have a 5TB external USB that dupes all my docker stuff as well from my server to my Mac, so it's an all-in-one backup solution for me.
I recommend the Colota app for tracking. I use a mix of Reitti and Dawarich at the moment to log the info (both of which support sharing) as I can't work out which I prefer.
https://github.com/dietrichmax/colota
https://colota.app/
I use a Pangolin reverse proxy with OIDC (PocketID) for family access to services, along with CrowdSec. For the Immich app access which needs to bypass auth login through the reverse proxy, I use 'link share' in Pangolin that gives me header tokens that can be entered in to the Immich app under Advanced settings.
I've been an Immich user for over 2 years now, so it's been a journey for me to implement it to this standard.
Or as someone else suggests, try CloudFlare with something like Google Auth login. Just be aware that you are then exposing all your traffic to Cloudflare. I take that as a small sacrifice for simplicity.
Similar to your story 1: I needed to renew my mortgage and it was an instant thing if I did it via their app (for security reasons apparently), or it became a paper form and post thing.
I tried to do it via a web portal, but that didn't work. I called them up to see how else I could complete the renewal, but that opened a can of worms of speaking to a woman on the phone, utterly unable to fathom why I couldn't install their app on my Android phone: GrapheneOS (play store installed, but it denies their app on my dangerous 'rooted' phone).
The woman I was speaking to thought I was an idiot who didn't know how to use Android. FFS.
Ah thanks. I know I have scratched the surface with what MA can do, and it is one of the more useful things I self host. Music Assistant and Immich are the absolute must haves.
Thanks for that. Read Pt1 and it all makes sense.
I've found that Music Assistant has worked well for group casting audio for me with Google Minis and Chromecast Audios. Although I've not had it running all day, but it has removed the hassle of it stopping from WiFi disconnects from my phone.
Always looking for new ways to do things, so will look out for pts 2 & 3.
You can run docker stacks with external IPs, no? I run all mine from Unraid, through Dockhand as compose stacks, with some ports on the host, others as external IPs on VLANs. But yes, like you I would actually like to move them to VMs so it's easier to backup, and service, without taking the host server offline.
It starts to get like Inception levels of depth on VMs and hosts!
Take from this anything of use to you: I syncthing my important Unraid server stuff to a MacBook running Backblaze with a 14TB external drive. DNS is handled by NextDNS in the cloud anyway, so it's just Immich and other random family oriented services for me. I use Pangolin for exposed services.
You could use syncthing (or Resilio) over a tailscale or headscale network or whateveritispeopleuse to a remote PC.
My Docker compose files and VMs are backed up once a week via plugins on Unraid, which of course get duped via syncthing to the MacBook.
I did try a Hetzner Storage Box for a while to replace Backblaze, but the hassle of having to keep an eye on the syncing was a pain and I fell back in to Backblaze on the MacBook as it's a set and forget (as long as they don't change the filetypes ignored...). I may go back to a Storage Box again.
I do also want to look into redundancy with a spare server though so it becomes quicker/easier to get it all up and running in event of failure. This is where selfhosting starts getting serious!
Just chucking this out there to help with the fediverse.
So, generate fake images of you in new clothing... does that suggest the Japan holiday photos are also meant to be fake?
Not sure that it demonstrating it's ability to render fake photos makes a good demo to show it sharing 'real' photos.
And I wonder if those Japan photos are actually real or faked for the ad. Which makes it even more of a conundrum as to why bother with anything on it if it can just make everything up for you.
I ran BI for years, but left them for a Ubiquiti device. Yes it required new cameras, and of course the investment in a UniFi device, but damn is UniFi Protect good. Does great detection and no subscription or fees of any kind, plus gets frequent updates and feature improvents. Not a solution for everyone, but I believed the hype of BI for years and thought there was nothing better. Turns out there is.
Hi mxdcodes. I have been using your app for the past month in a sort of testing phase with Darawich. I have used GPS Logger and Reitti since October last year, which is still running, but Colota offers a lot more exciting possibilities of data collection and so I'll probably switch across pretty soon. I got hit by the bug a while back of it stopping once entering a geofence, but I saw that got fixed promptly so thanks for all of this.
I love all that you and others who code for the (wider) selfhosted community offer, so let me say that for every person criticizing your app and all the effort you have put in, there are hopefully 1000x more of us who are truly grateful for what you and others do. I find it odd that people who are concerned about having their location history hacked by someone are actually wanting to record their location history in the first place. Seems the obvious answer is to... not track your location history with ANY app.
Keep up the good work!
Good to hear!
However I may have spoken too soon with Colota... it stopped registering my location after a first trip, and wouldn't restart tracking until I restarted my phone (GrapheneOS Pixel 9). I need to look at the logs and maybe raise an issue.
Dawarich has had some great updates in the past few weeks, and I'm hoping Colota + Dawarich is my future family tracker system as they both have a very nice feel to them.
GPS Logger + Reitti is my background system atm while I mess with Colota & Dawarich.
I've been using Colota this weekend sending data to a Dawarich server. I like that you can filter out inaccurate GPS readings by setting an accuracy threshold, so this removes any false points that I tend to get with other location apps.
I've tried GPS Logger for Reitti, and the new Android Dawarich app, but so far, Colota seems the best (early days). It has the nicest ui as well.
In terms of what to enter, you need to find out what HA requires for the URL to receive data, then set that in the Colota app. Colota will just store the location data until you set a remote end for it to connect to.
I haven't tried TBH. Because the VPS is restricted to my home IP for SSH using Hetzner's firewall, I wireguard to home, then SSH to the VPS direct. I've been updating Pangolin since last summer, but haven't really played with the newer features. I should have a proper look really.
I do this currently. I have a Hetzner VPS with Pangolin, giving access to family services like Immich etc, and my own nerdy services I keep locked to my home IP, and if I'm away from home, I tunnel in with Wireguard and hence then the home IP kicks in and they work.
You can issue traefik IP rules with Pangolin as well to limit what IPs can access services.
I have Pangolin and all family services behind Pocket ID with passkey only auth.
The VPS I protect with Hetzner's firewall, so only SSH is allowed from my home IP.
The whole setup is as secure as I can make it. My family would just roll their eyes at any VPN I asked them to use, so it has to be publicly accessible for some things annoyingly.
I also have private services coming direct to my home firewall away from the VPS (for speed efficiency), and for truly public services (websites), I have those tunneled through a Cloudflare tunnel that can handle Google Auth for WordPress login pages etc.
It made me uncomfortable to start with using the VPS, but in time, confidence grows.