Some time ago, I built a box to track ADS-B data in my location. Since then, I’ve added more Pi’s and SDRs and had been planning an upgrade for some time, but my hand was forced after some hardware failures we’ll get into. The New Box Here it is before mounting and without the mess of antenna cables: And here is is in its final home: The format is generally the same as before,…
The current mess in the Linux world is dirtyfrag . A new LPE bug using Kernel modules but the twist here is someone broke the normal embargo to let systems patch, so there’s currently no published packages with fixed versions. If you’re like me and adopt the Cattle Not Pets philosophy, you’re running some kind of configuration management system, and that makes it easy to roll out…
At the end of last year, I made a post talking about how I don’t need no stinkin’ HA in my homelab. That post is still largely true, but I did make some changes and re-implement a High Availability cluster within Proxmox, but did so without adding another heavy server node back into the cluster. Eating My Words About HA In that post I talked a bit about how my workloads didn’t…
I’m approaching about a year since I reconfigured my backup strategy to rely on Proxmox Backup Server. Initially, I was drawn to the deduplication Proxmox VE backups could make use of, but upon trying it, I decided to migrate my entire backup stack to it. What’s Proxmox Backup Server (PBS) If you’ve never seen it before, PBS is an appliance that you deploy on your network to…
This is a rambling tale about redundancy, understanding needs, and the sunk cost fallacy. After upgrading my router to a Unifi Dream Machine Pro, I was able to comfortably eliminate two aging servers from my stack and save several hundred watts of power in the process. I did this for a number of reasons, but after some reflection I’m more confident in my set up even with less redundancy now.
I have a very, very old Polycom Soundpoint IP 321 in a drawer. This phone works, and was really only replaced after I migrated to 3CX. Since migrating back to a local FreePBX install, I wanted to use the phone in our basement for an extra landline. I fumbled through the menus of the phone to reset the configuration and found an option called “Format Filesystem” and pushed it thinking…
For the past few months, I’ve been test-driving T-Mobile’s Backup Home Internet that’s based on their cell network. The experience so far has been … fine, but I wanted to share some quirks and my experience so far. None of this review is sponsored in any way. What The Backup Plan Is T-Mobile offers a plan for $25 per month ($20 when on autopay) where you get 130-ish GB of…
A while ago, I highlighted a design in my homelab where I kept core services running on a low power core to get longer runtimes on my UPS. I talk about it in this post , and that setup worked well for a long time. But as my network grew and more things became important, I started to lose some of the runtime of that UPS. Recently, I’ve upgraded my NVR to a full Unifi NVR appliance, added a TV…
After it was announced that data from Government sites such as the CDC and FDA were being removed, I did what any good Data Hoarder does and started hoarding more. I have a fairly small instance of TubeArchivist to keep a list of niche channels downloaded, but I turned it to a number of Government channels to try and save as much content as I could in fear that it would be removed.
Last Year I showed my system and talked about how I use Trunk Recorder to monitor P25 radios. The second phase of that is monitoring the system, and thanks to the prometheus metrics Trunk Recorder exports, we can use tools like Zabbix to get data about the messages we’re seeing. Metrics We Care About There’s a few fairly important metrics we want to look at to monitor the health of our…
As I write this, it’s January 17, and the fate of TikTok in the United States is very much uncertain. I generally avoid politics, but this case is an interesting case of several political feelings I have intersecting with technology, so I’m here writing about it. Clearing The Air I am a TikTok user, but I have no financial incentive to do so. Though invited, I never opted into payments…
With the maybe looming ban of TikTok in the US, here’s how to download all your likes, favorites, and even entire creators you follow. Add this extension to Chrome. Go to TikTok and sign in. You should now have a sidebar with three options: Download likes, Download Favorites, Download Accounts Click on one, then chose a folder. This folder can be used for any of the downloads and can also be…
Coming later this month, I have a post on monitoring my Trunk Recorder installation with Zabbix and Prometheus. It’s written, but released later for pacing. In the meantime, Kansas got hit with Winter Storm Blair, which lead to some interesting finds on my Trunk Recorder Instance. Other than local fires, this was the first large scale event that really stressed my recorders and setup. Every…
One good practice for most environments is centralized logging. This is recommended in a number of security benchmarks, but the idea is largely to keep logs outside a device that can get compromised. If a device does get taken over, even if it’s wiped clean, the logs and traces of what went wrong can hopefully survive. Even in my homelab, I still see benefit. Some network gear, namely my…
A few months back, I set up an ADS-B plane tracker to watch airplanes that were in the area. So far that has seen a few really neat things, including aerobatic competitions and a few emergency landings. In my quest to be even nosier, I wanted to also listen in on the local P25 radio system, and used the hardware design from before to accomplish this. The software, though, is a bit more…
If you’re like me you have a problem with keeping nearly every cable you come across. From patch cables that ship with new devices, to old phone chargers that still work and have a micro USB slot, to your stash of new USB-C cables, you’ve accumulated several boxes worth. Once your collection passes a dozen or so cables, you’ll inevitably run into a few issues: namely that the…
I recently figured out a solution to a problem I’ve long been battling. When rebooting a server after it’s forced to shutdown to losing power and the UPS battery running low, it’d enter a cycle of starting, starting the NUT service, then immediately shutting down. Symptoms There were a few clues that you may see on your environment as well: The issue manifested as nodes powering…
This is the first hardware based project I’ve shared, but this is how I built my ADS-B Tracker. What’s ADS-B and Why Track It Most (not all) airplanes are required to broadcast their position as they fly around. This is intended for ATC and other planes primarily, and is another data point in a complex system used to keep these things from running into each other. These signals can be…
This is a post that’s largely going to be me complaining about shitty cable internet that I’ve lived with since its inception. Making the change myself, and now seeing others complain in forums has really soured me to most of the connectivity options out there. I won’t name the specific company, but a lot of this complaining will be focused around my experience with them and the…
One thing that is a key asset in any environment is reliable, thorough monitoring. Once as you add more redundant layers to your infrastructure, automated monitoring is frequently the only way to tell if something has failed, short of manual checking. When setting up monitoring for my OPNSense routers, though, I wasn’t super thrilled with the default options. There’s an SNMP template…
After Ubiquiti’s recent security faux pas, I started to question the best way to access my Unifi Protect cameras. By default, the Unifi Protect uses your Ubiquti account to log in, and disabling remote access breaks this. This can be bypassed with a little work, and if you’re using OPNSense, it’s pretty easy. Motivation I won’t comment on the recent security issues Ubiquiti…
One project I recently invented for myself is cleaning up my jumbled mess of firewall rules. The issue is that as time has gone on, I’ve created more VLANS, which has led to more rules that I’ve never really formally organized. It finally reached a tipping point, and after some experimentation, I found a new system that improves my security and makes things much more simple. My Problem…
Trigger Warning: This post talks generally about human mortality and loss of your home. One ting I’ve recently started considering is how my Homelab can survive if I’m not around. At first, everything in the lab was pretty low value so losing things wasn’t a huge deal. Recently though, I’ve started archiving family photos and other important things that need to survive…
When you have a homelab, you’re going to start having a number of internal websites and services you use. You’ll learn to live with HTTPS warnings when navigating to these sites, but these warnings can still be a problem. What if we wanted to have valid HTTPS everywhere? HTTPS Primer HTTPS encrypts your traffic so things that intercept it (routers, attackers, etc) can’t decode…
Hanging out in subreddits like /r/homelab , /r/servers , and /r/datahoarder , I see this question asked too many times: I have extra space in my home server, how can I sell this for other people to use? My answer (and a lot of other people’s answer): don’t . We’re Really Not Trying To Ruin Your Dreams If you come across this post, or if this was sent to you, know that we…
If you’ve poked your head outside in the last few weeks, you’ve noticed that LastPass had a security breach where customer vaults were exposed and downloaded. I’ve been hanging around in /r/lastpass and seeing the mixed reactions has been interesting. Why I’m Leaving I’m leaving LastPass, and had been looking at solutions for the last few months. While the security…
If you ave a homelab, you’ve probably collected a few TB of data that needs backed up. Recently in /r/datahoarder and /r/homelab I’ve seen a lot of posts that ask about backups. I’ve talked about my strategy in the past , but I figured I dive a bit more into offsite backups. If you’re not familiar with why you should be keeping backups or some general rules of thumb, I have…
One thing that quickly becomes annoying is disruptions to my main home internet. This is annoying for the obvious reasons: I can’t use remote services, home automation that needs the cloud breaks, etc, but is also frustrating because it’s something I largely can’t control. I’m at the mercy of my ISP to detect outages and resolve them, and sitting around and waiting is one…
This site isn’t anything too special, but I figured I’d share how I host things for others who may be interested in owning their words. Motivation For Self Hosting I’ve run this website (in some form or another) for the last 6+ years. The idea was to share some stuff I do that I think is cool with others and maybe remind myself of projects past. I’ve always just shared…
There’s an old joke in Programming that 90% of your time is spent naming things, and I think this extends into Homelabs and any other computer environment. Names are there give your systems identifiable places, can describe where they are and what they do, and are the easiest way to identify something, so giving some thought into a naming system is worth it. Styles of Naming Naming schemes,…
One critical thing for any environment, in my opinion, is monitoring. Being able to detect problems and get an understanding of them is crucial to solving them. One thing that is important to monitor is your network. This is not just an important to get a sense of its health an performance, though. Detecting when client machines talk to potentially malicious hosts is a pretty quick way to pick up…
I double NAT my home network. And the funny part is I designed it that way. Let me explain. Why This is Bad If you’re a network person, you’ve already groaned. If you haven’t groaned, you probably should. Network Address Translation (NAT) is a service that most consumer routers perform by default. Essentially, it’s what lets you connect your privately addressed network to a…
I recently made a design change to my homelab that paid off in leaps and bounds, and just secured my homelab as a part of my critical infrastructure during emergencies. This change was a pretty simple idea, but recently proved itself during a recent tornado near my home. This post will largely be tooting my own horn, sharing why I think this is a good idea, but will also talk about severe weather…
I really like filtering my mail. I tend to only need to act on a very small set of messages coming in, so I filter everything such as Ads, FYIs, Cron Jobs, etc to folders and just leave the important stuff in my inbox. Unfortunately though, I now have a few hundred rules, as I keep things separated out to let me have multiple conditions for single senders and keep everything fairly organized. I…
One challenge of running servers, especially if you have more than a few, is keeping all of the software up to date on them. Patches are released constantly, and keeping software updated is a major security concern. One great tool that can help automate this is apt-dater , a text based utility that lets you interactively update packages on systems. Installing apt-dater is included in the main…
If you’ve been on the Internet at all today, you’ve probably heard that there is a pretty nasty RCE issue with log4j , a logging package for Java applications. The CVE is CVE-2021-44228 , and is a pretty scary RCE bug that is already being exploited in the wild. Update: I originally had comments in this post stating Ubiquiti should update the NVR software. I’ve since learned…
After some light Google-ing, I couldn’t find a simple example for Emby running behind an Nginx reverse proxy. I built this config using some boilerplate config I have and some config snippets from other config examples. If you’re brand new or not sure exactly what you need, it can be a bit confusing to see older threads with lots of comments and suggestions, and it may be hard to tell…
Obvious Disclaimer: I’m not a professional security researcher. I dabble in these things and more pursue these things out of curiosity. Let me know what I got wrong. Today I read that there was another victim of a Supply Chain attack, a NPM module author had a few of their modules compromised, one of which (the one I read about) was ua-parser.js . This module provides detection of various…
This is a quick how-to showing my procedure for setting up new drives with LVM. What is LVM LVM stands for Logical Volume Manager and is a newer way to manage partitions and disks in Linux. If you’ve never used LVM, it makes adding partitions, resizing things, adding disks, and more easy and slick on Linux. Basically, it’s an abstraction layer between your disks and partitions. You can…
I’m pretty protective of my data. I like to make sure all my important file are backed up, and I employ a 3-2-1 backup strategy for basically everything. What are 3-2-1 Backups This is a term that is floated around frequently when talking about backups. It basically boils down to these rules: You have 3 independent copies of your data. Of those 3 copies, 2 of them are on different systems…
One of the most important parts of keeping data safe is offsite backups. One excellent tool for this is Rclone, a tool that copies data to local and remote locations with ease. I don’t use Rclone for all my backups, which I’ll get into, but I use it for some cases and it’s a great tool. Why I Use Rclone I operate a dedicated server where the hardware is managed by a third-party.…
If you’re installing Debian on a regular basis, or want to automate the installation a bit more, building a custom Debian installation ISO can be quite handy. You can automate some of the more tedious parts of the installation, install extra packages and run additional setup, or even completely automate the installation! Why? In my case, I’m working with some automated provisioning…
In the past, I showed how to add a firewall rule in Debian 9 . For Debian 10, these instructions still work but installing the firewalld package is a bit more involved. Why There is a bug in iptables (which is how firewalld applies rules) that causes it to crash on start up. Thanks to this GitHub Issue , I was able to track this down to the specific version of iptables that ships with Debian 10 (…
One tool that is pretty neat for anyone who manages more than one machine is Puppet. In it’s simplest form, Puppet is designed to codify actions you may take on your server and run them automatically. The typical deployment for Puppet relies on a central Puppet server (the “Puppetmaster”), and clients distributed around your network. What if, say, we wanted to run Puppet without…
Meta Information: This is a room I recently completed on TryHackMe. I figured I’d do a write up of what I found, how I got in, and things that a potential sysadmin would want to do to fix their server. I’m writing this from the point-of-view of a independent security consultant. Description of Server The machine in question appears to be an Ubuntu Linux machine, with a number of open…
This is a minor inconvenience that I’ve dealt with for far too long. When using Virtualmin as a reverse proxy, it doesn’t handle Let’s Encrypt verification records correctly and forwards them to the upstream service. In my case, this would cause certificates to issue correctly initially, but then fail to renew after three months is up. Since every request that hits the server was…
In Part One we looked at how to download our photos from Google Photos to a local drive. But now we’ll look at how to archive them into human readable folders that can be included in daily snapshot backups. Our Problem Now we have all our photos downloaded, but I really wanted things to live on my NAS with the rest of my important files. This would also let me potentially delete photos from…
One service that I’ve come to rely on is Google Photos. For the last number of years, I’ve had photos on my phone (which is now my primary camera for trips) automatically backed up and categorized. It’s a slick service, but I feel most comfortable having local copies of photos and keep them in a snapshot backup system. Why I Did This Google Photos is great, and I don’t…
I suffered a pretty hard burn out a couple of years ago. I ended up changing jobs, and only then did I realize just how exhausted I was. I wanted to share my experience, what happened, how I think it could have been prevented, and remind everybody that their mental well being important. Quick Disclaimer: I’m not writing this to place any blame on what happened. This was mostly the result of…
I’m not a huge fan of meta posts, but this seemed like a fairly major change so I’m making one. I’ve updated my site to use Hugo rather than Wordpress. Wordpress is nice and all, but it’s fairly complex for this site and with horror stories of rouge plugins, I didn’t feel it was the best choice. Also, the new static site is a lot faster and a lot easier to work with,…