‹ BackHN Continuity

Thread

Custom home server built from spare parts

91 points · 54 comments · sotilrac

  1. drnick1 · · focus · HN ↗
    > So the NAS runs Kubuntu 24.04 with ZFS

    My experience is similar. I no longer use dedicated NAS, firewall, or other exotic distributions. I run plain Debian, and add what I need through standard repo packages. My "NAS" is simply a Samba daemon. The same box runs countless other services including hostapd (WiFi), DNS (Unbound), an email stack (Postfix/Dovecot), multiple game servers, and Podman.

    > everything else in Docker Compose

    I would suggest Podman instead. It is far more secure by design (rootless) and is unable to silently alter the firewall's configuration.

    1. Oxodao · · focus · HN ↗
      > is unable to silently alter the firewall's configuration

      I'd like more informations about this as I'm not too familiar with firewall setup but every time I tried to setup iptables / nft it was indeed bypassed by docker. Recently I found out in the docs that docker adds a DOCKER-USER table, isn't it enough to put your rules in it to prevent the outside world to reach containers ?

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.