grep -rl "self-hosting" ./blog

Self-Hosting Guides

Running services on your own hardware: containers and Compose, reverse proxies, file sharing between machines, and the infrastructure that supports them.

34 articles

CrowdSec vs Fail2ban: Blocking Attackers on Linux Servers Fail2ban bans IPs that fail too often in your logs. CrowdSec does the same and shares signals with every other CrowdSec user. How each works, setup for SSH, the bouncer model, privacy trade-offs, and which to run. Docker Volumes, Bind Mounts, and Networks Explained Where container data should live and how containers talk to each other. Named volumes vs bind mounts vs tmpfs, permissions and SELinux labels, backing up volumes, user-defined bridge networks and DNS, publishing ports safely, and the firewall surprise. Gitea vs Forgejo: Which Self-Hosted Git Forge Should You Run? Forgejo began as a fork of Gitea and is now a separate project. How they differ in governance, licensing, features, and federation, how hard it is to switch, and which one fits a homelab, a team, or a public instance. sshfs and rclone mount: Mounting Remote Storage as a Local Folder Mount a server's files over SSH with sshfs, or cloud storage like S3, Backblaze B2, and Google Drive with rclone mount, and use them like any local directory. Setup, fstab and systemd mounts, caching, and when a sync is better than a mount. Syncthing Explained: Peer-to-Peer File Sync Without a Cloud Syncthing keeps folders in sync directly between your own devices, encrypted, with no server or account. How device IDs, folder sharing, and relays work, how to run it as a service on Linux, and how to avoid the mistakes that lose data. MariaDB and MySQL on Linux: Setup, Users and the Settings That Matter Installing is one command. What follows is the part that bites: unix socket authentication, why utf8 is not UTF-8, the one buffer pool setting worth changing, and a backup that actually restores. Open Source Licences Explained: GPL, MIT, and the Source-Available Problem Copyleft versus permissive is the classic split, and the live argument is now about licences like BSL and SSPL that look open and are not. What each actually requires, why AGPL exists, and what changes when a project relicenses. Unbound: Running Your Own Recursive DNS Resolver Pi-hole filters. A forwarder caches. Unbound resolves from the root servers itself, which means no provider sees your queries at all. Setup, DNSSEC, and the one setting that makes it feel slow when it is not. Valkey and Redis Basics: Caching, Persistence and Not Losing Data An in-memory store used as a cache, a queue and a session store. Why the fork happened, what persistence does and does not guarantee, the eviction policy that decides whether it is a cache or a database, and how it gets left open to the internet. Single Sign-On for Self-Hosted Services with Authelia How forward auth puts a login in front of services that have none, why that is better than exposing a dozen separate login pages, and what it does not protect. Headscale: Self-Hosting the Tailscale Control Plane What the coordination server actually does, why self-hosting it removes the one third party in a WireGuard mesh, and what you give up by leaving the commercial service. Setting Up Jellyfin with Hardware Transcoding Deploying Jellyfin properly, getting VAAPI or NVENC working so transcoding does not melt your CPU, and organising files so metadata matching actually works. Setting Up Nextcloud Properly Deploying Nextcloud with a real database, the configuration steps the installer does not do for you, and the tuning that separates a fast instance from the slow one people complain about. Running Your Own Container Registry Why Docker Hub rate limits push people to self-host, the difference between the reference registry and Harbor, and getting authentication and garbage collection right. Self-Hosted Email: Why Everyone Tells You Not To Receiving mail is easy. Sending mail that arrives is hard, and the reason is reputation systems you do not control. What SPF, DKIM, and DMARC actually do, and what it takes to run a mail server that works. PostgreSQL on Linux: Install, Secure, Back Up Getting PostgreSQL running on Linux, understanding peer and md5 authentication in pg_hba.conf, the settings worth tuning, and backups that actually restore. Running LLMs Locally on Linux with Ollama How to run language models on your own hardware, how much VRAM you actually need, what quantization costs you in quality, and an honest assessment of how local models compare to hosted ones. What Is Self-Hosting? An Honest Introduction What self-hosting actually means, what it costs in money and attention, which services are worth running yourself, and the two that almost nobody should attempt. HAProxy: Load Balancing and Health Checking for Self-Hosted Services A reverse proxy built for distributing traffic across backends with real health checks, connection limits, and a statistics page that tells you what is actually happening. k3s: Kubernetes Small Enough for a Homelab A single binary under 100MB that gives you a conformant Kubernetes cluster on a Raspberry Pi. Here is what Kubernetes actually adds over Compose, and whether you need it. Podman Quadlet: Containers as Real systemd Services Quadlet turns a short declarative file into a generated systemd unit, so containers get dependency ordering, journal logging, and restart handling from systemd instead of from a container runtime. LXC and Incus: System Containers That Behave Like Lightweight VMs Application containers run one process. System containers run a whole userspace with its own init, users, and services, starting in under a second and using a fraction of a VM's memory. Proxmox VE: A Web Interface Over KVM and LXC Proxmox packages KVM virtual machines, LXC containers, ZFS, clustering, and backups behind one web interface on a Debian base. Here is what it gives you over rolling your own. Monitoring a Home Server: Netdata, Prometheus, and Grafana One tool gives you everything in five minutes, the other gives you history and alerting but takes an afternoon. Here is which to pick and how the pieces fit together. Pi-hole and Network-Wide DNS Filtering Blocking ads at the DNS layer covers every device on the network including the ones that cannot run an extension. Here is how it works, what it cannot do, and how to avoid making yourself the network outage. WireGuard vs OpenVPN vs Tailscale: Choosing a VPN for a Homelab Three tools, three different problems. One is a protocol, one is an older protocol with more options, and one is a coordination layer that removes the hard part. Here is which to use when. Software RAID with mdadm: Levels, Setup, and What RAID Does Not Do Linux software RAID is mature, fast, and free. Here is what each level actually gives you, how to build and monitor an array, and why RAID is not a backup. ZFS on Linux: Pools, Datasets, Snapshots, and the Licensing Problem ZFS checksums everything, snapshots instantly, and replicates efficiently. It also cannot be merged into the kernel, which shapes how you install and maintain it. Here is what you need to know before committing. Immutable Distros Explained: Silverblue, Bazzite, and the Read-Only Root A growing number of distributions ship a root filesystem you cannot write to, update atomically, and roll back by booting the previous image. Here is what that buys you, what it costs, and how you install software on one. TLS Certificates on Linux: Let's Encrypt, certbot, and What Actually Happens Free automated certificates removed the last excuse for running services over plain HTTP. Here is how the ACME challenge works, how to get a certificate with certbot, and how to handle wildcards and renewal properly. Docker Compose Basics: From docker run to Declarative Stacks Docker Compose turns long docker run commands into a version-controlled YAML file describing your whole stack: services, volumes, networks, and environment. Here is the mental model plus a working template. NFS vs Samba Explained: Sharing Files Between Machines NFS and Samba both put one machine s storage on another machine s filesystem, but they come from different worlds. Here is how each works, which to choose, and minimal working configs for both. Reverse Proxies Explained: Nginx, Caddy, and Traefik for Self-Hosters A reverse proxy sits in front of your services, routing incoming requests by hostname and terminating HTTPS in one place. Here is why every self-hosted setup grows one, and how the three big options differ. WireGuard Explained: The Modern Linux VPN WireGuard is a VPN protocol built into the Linux kernel: a few thousand lines of code, public-key pairs instead of certificate bureaucracy, and configs short enough to read. Here is how it works and a working two-peer setup.