Containers for home network

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
35,563
Reaction score
11,944
Last edited:

lobukong

Member
Joined
Jun 16, 2011
Messages
365
Reaction score
200
bitwarden +1.
rclone, to create webdav server for google drive, so that can easy access contents across home network.
tried pi-hole on RPi4 docker, not as effective as ublock-origin, then will cause bilibili thumnail fail to load. Not sure if it can be further configured to match ublock-origin.
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
35,563
Reaction score
11,944
bitwarden +1.
rclone, to create webdav server for google drive, so that can easy access contents across home network.
tried pi-hole on RPi4 docker, not as effective as ublock-origin, then will cause bilibili thumnail fail to load. Not sure if it can be further configured to match ublock-origin.

ublock-origin is still needed. For example, Pi-hole can not block streaming site ads like Youtube ads.
 

firesong

Supremacy Member
Deluxe Member
Joined
Jan 17, 2001
Messages
8,868
Reaction score
4,883
bitwarden +1.
rclone, to create webdav server for google drive, so that can easy access contents across home network.
tried pi-hole on RPi4 docker, not as effective as ublock-origin, then will cause bilibili thumnail fail to load. Not sure if it can be further configured to match ublock-origin.
Different strokes, I think. If you only have PCs on your network, then yes you can probably just live with uBlock. But pfBlocker/PiHole also blocks ads from other devices connected to your network, including your tablets, phones, SmartTV and all other internet connected devices on your network. Even on your PC, it blocks ads in other apps outside of your browser, so it has its usefulness.

As for the effectiveness, you also need to see what filter lists you use. There are decent ones out there that are more effective. I use oisd among other lists, and continue to use it in pfBlocker now.

Stopped using piHole since it's only a DNS-based blocker, whereas pfBlocker also blocks at the IP address level. Both together give more effective blocking, and not only ads but malware and other unwanted things. It's not perfect, but any added protection for my non-techy family members is always welcome.

PS: No one said you can't run both. ;) Set up a DNS blocker, and add a browser based blocker to block whatever slips through the DNS based one. You can even configure an upstream DNS service that gives added protection for unwanted elements such as malware. It's the internet, where anything bad can happen. Stacking these won't cost you much but could be helpful. It's not quite the same thing as trying to run 2-3 Antivirus programs simultaneously on your PC (if you really want to, try it just once).
 
Last edited:

firesong

Supremacy Member
Deluxe Member
Joined
Jan 17, 2001
Messages
8,868
Reaction score
4,883
Just saw a decently priced N3150 45W box on Carousell - going for $100. Am thinking of getting one to move my server over from the ARM box, and to run Nextcloud on it. 😂 It has expandable RAM (2x DDR3L slots) and storage (1x M.2 NVMe/SATA and 1x 2.5" drive). Probably not so good an idea for pfSense ROS because it's got a Realtek NIC according to the spec sheets.

For those who want a fairly low priced box and don't mind learning, can look for the Asus UN45H.

PS: I have no link with the seller. Just SIC cos it's a decent priced box with plenty of power for this kind of small home server setup. :D
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
35,563
Reaction score
11,944
Just saw a decently priced N3150 45W box on Carousell - going for $100. Am thinking of getting one to move my server over from the ARM box, and to run Nextcloud on it.

It has expandable RAM (2x DDR3L slots) and storage (1x M.2 NVMe/SATA and 1x 2.5" drive). Probably not so good an idea for pfSense ROS because it's got a Realtek NIC according to the spec sheets.
For those who want a fairly low priced box and don't mind learning, can look for the Asus UN45H.
PS: I have no link with the seller. Just SIC cos it's a decent priced box with plenty of power for this kind of small home server setup.
:D

That is really cheap.

I paid S$240 for the Chuwi J4125 mini PC with one Intel I225V B3 2.5G NIC, 8GB RAM and . Now I use it as my Linux Desktop (boot Windows 10 once and then totally removed it and only use Linux).

Previously I bought a Chuwi Herobox Pro Intel N4200 mini PC at S$260, same 8GB/256GB configuration but with lousy Realtek gigabit NIC. That was a bad buy. They have since discontinued it. The N4200 is actually lower performance dual core vs the quad core J4125. Anyway I have installed ESXi and a few VMs as a backup machine (Not powered up as of now) if my Intel J4105 mini PC (router and LXC containers) is down.

Chuwi got Lazada and Shopee official shop.

Check out CHUWI Official HeroBox Mini Desktop-PC | Intel Celeron J4125 quad-core four-threaded 8GB+256GB SSD 2.4G/5G WiFi Bluetooth 4.2 windows 10 | 4K | Small and portable | 1 Year Warranty at 28% off! $259.00 only. Get it on Shopee now! https://shopee.sg/product/316130767/7394956407?smtt=0.568370204-1648650939.9
 
Last edited:

lobukong

Member
Joined
Jun 16, 2011
Messages
365
Reaction score
200
Just an update, I change to use PVE 7.1 and LXC containers, so no longer using dockers.

RIght now, I use the following two Debian LXC containers only.
1) LXC container 1: running as Pi-hole, also as ad-hoc iperf3 server and librespeed server
https://github.com/librespeed/speedtest-go
2) LXC container 2: running Smokeping with nginx, also as ad-hoc iperf3 server and librespeed server
https://sleeplessbeastie.eu/2021/08/27/how-to-install-smokeping-on-debian-bullseye/
Recently setting up pve also. May I know how do you achieve failsafe for pihole? Like if my PvE is off I need my router to use 1.1.1.1 instead of pihole for example.
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
35,563
Reaction score
11,944
Recently setting up pve also. May I know how do you achieve failsafe for pihole? Like if my PvE is off I need my router to use 1.1.1.1 instead of pihole for example.

I am not considering fail safe now. Previously I used two Pi-hole installations, one on local PVE LXC container, the other on the free Google Cloud. I have since decommissioned the Pi-hole installation on the Google cloud.

You can try your Pi-hole as the primary DNS server and then 1.1.1.1 as the secondary DNS server. However last time I tried this method, the Asus router was using Round Robin so it kind of defeated the purpose of Pi-hole. Your router may have different behaviors.

Edit to add:
1) BTW, I have two home networks, one is using Asus RT-AX82U (with Pi-hole). The other is using OpenWRT/pfSense. When I use pfSense, I will use pfBlokerNG and not Pi-hole. When I use OpenWRT, I tend to use Pi-hole.
2) PVE is pretty stable and it has never been down -- even survived several power trips.
3) But my two Pi-hole installations were dead once. Using LXC container makes things very easy as I have cloned the containers and saved the Pi-hole configurations.
4) My pfSense PVE installation was also very stable and never went down.
5) My OpenWRT PVE installation was also very stable. The only time it was down was due to the dead Pi-hole.
6) My Smokeping container was dead and I need to figure out how to get it back.
 
Last edited:

lobukong

Member
Joined
Jun 16, 2011
Messages
365
Reaction score
200
I am not considering fail safe now. Previously I used two Pi-hole installations, one on local PVE LXC container, the other on the free Google Cloud. I had decommissioned the Pi-hole installation.

You can try your Pi-hole as the primary DNS server and then 1.1.1.1 as the secondary DNS server. However last time I tried this the router was using Round Robin so it kind of defeated the purpose of Pi-hole.
Yes, I think then need 2 pihole setup, which is also a bit troublesome to also setup sync between them.
May I know why you decommissioned pihole? Got alternative?
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
35,563
Reaction score
11,944
Yes, I think then need 2 pihole setup, which is also a bit troublesome to also setup sync between them.
May I know why you decommissioned pihole? Got alternative?

I decommissioned Pi-hole on the free Google Cloud, I still run the Pi-hole container locally.

Alternative -- running pfSense and then use pfBlockerNG-devel. It seems to be more powerful than Pi-hole. The user interface is not as good though.
 
Last edited:

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
35,563
Reaction score
11,944
1) I am still using PVE and LxC containers. Not using Pi-hole now but switched to Adguard Home. I am also running other Linux containers to play with Tailscale and Zerotier.

2) Restarted my docker experiment since I need to use docker for some open source projects.

Then using this chance, I want to learn more about Docker with networking.

One thing to learn -- Docker and Tailscale.

 
Last edited:

d3adc3II

Senior Member
Joined
Nov 27, 2006
Messages
700
Reaction score
64
Just an update, I change to use PVE 7.1 and LXC containers, so no longer using dockers.

RIght now, I use the following two Debian LXC containers only.
1) LXC container 1: running as Pi-hole, also as ad-hoc iperf3 server and librespeed server
https://github.com/librespeed/speedtest-go
2) LXC container 2: running Smokeping with nginx, also as ad-hoc iperf3 server and librespeed server
https://sleeplessbeastie.eu/2021/08/27/how-to-install-smokeping-on-debian-bullseye/
Im running rke2 on top of proxmox, storage managed by Rook ceph connect to external ceph storage, I also have separated docker swarm for testing purpose ibut i rarely use it nowadays.

Applications im running include:

rke2:
1. Network
- Technitium DNS: probably is the best open source dns server nowadays
- Backup stack: netbox + unimius + github
unimius: free version, simply said its best of the best backup app for network. On schedule, it backup config of all network devices include opsense, mikrotik switch, tplink switch
unimius : retrieve info from netbox > backup config > push to github hourly
- Zabbix: logging and monitoring
- Twingate: yea, i tried tailscale , netbird, zerotier and settled with twingate. Its closed source but its so good, even subscribe and use for work.
- Virtualized Truenas: home NAS, my porn depends on it (jk)

2. Application
- Stirling pdf: alternative for adobe acrobat pro
- CyberArk Conjur: secret management app
- Kopia + Proxmox backup: backup to local storage, encrypt and push to wasabi. Wasabi is amazing and fast , backup total of 200GB took like 10-15 mins after first backup
- Meshcentral: a poorman solution when couldnt afford blikvm
- Eve-ng: use it for work, use it as home as well
- Scutiny: extremely important

Other fun apps include:
- Immich
- Firefly3
- Hoarder
- netAlertx
- Homeassistant

Thanks to rke2 highavailability, it make sure all the apps are running, its almost impossible to down unless I dont pay for pub. The cluster need to up 24/7, i couldnt work without them at this point.
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
35,563
Reaction score
11,944
Just an update, I change to use PVE 7.1 and LXC containers, so no longer using dockers.

Still using PVE (8.x version) and mainly LxC containers, along with OpenWRT/pfSense/OPNsense/IPFire VMs and various Linux/BSD VMs.

I was only using Docker Containers occassionally for non-networking related stuff (Open Source Projects testing).

I just set up an Ubuntu 24.04 virtual serve on PVE and I will use it for my Docker container experiments.

First one: OpenSpeedTest
https://github.com/openspeedtest/Docker-Image

Asus TUF-BE6500 router, Acer Swift Go 14 2024 laptop with Intel BE1750 WiFi 7 adapter (Intel BE200 chipset), 3m away.

I tend to think the number is a bit infrated (higher than iperf3 and OOkla SpeedTest).

r7vbSrL.png


xUoeETw.png
 
Last edited:

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
35,563
Reaction score
11,944
First one: OpenSpeedTest
https://github.com/openspeedtest/Docker-Image

Asus TUF-BE6500 router, Acer Swift Go 14 2024 laptop with Intel BE1750 WiFi 7 adapter (Intel BE200 chipset), 3m away.

I tend to think the number is a bit infrated (higher than iperf3 and OOkla SpeedTest).

Installed another Debian 13 virtual server and the number is even higher.

cCXbeHs.png


uvo5SUy.png
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
35,563
Reaction score
11,944
Nginx Proxy Manager -- most of the tutorial seem to require your own domain and use Cloudflare DNS Challenge. I am trying to use DuckDNS DNS Challenge now as I do not have my own domain.

As mentioned in the video, DNS is important.



Another more detailed tutorial using Nginx Proxy Manager and Pi-hole (as DNS server).

 
Last edited:

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
35,563
Reaction score
11,944
Actually domain is really cheap thru cloudflare. Somehow .uk is the cheapest of all, only 5.21 usd/yr.

Indeed the paid Domain name is not expensive from Cloudflare. It is just that I do not really host anything to others and do not really need a top level domain yet. Maybe I should get one just to play with things like Cloudflare Tunnel and other things. I still got free Google Cloud and Oracle Cloud instance.

Last time I used FreeNOM free domain names to play with some stuff (WireGuard VPN servers, Shadowsocks, V2Ray and Trojan) on Oracle Cloud, when Freenom was working.

Just did a quick check for one domain name I had in mind back in the DotCom years. Not really into this thingy after the bubble.

Per year pricing.

.org
US$7.50
Renews at $10.11

..com
US$10.44
Renews at $10.44

.net
$11.84
Renews at $11.84
 
Last edited:
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top