- 3 Posts
- 6 Comments
Taking do one thing, but do it good to the next level, nice!
I thought about getting a pi zero also just for the pi-hole. But my pi3b holds up pretty good, still
Cool, do you get any auth and/or ingress protection?
With cloudflare, you get some auth options, can block AI crawlers (that get recognized…) etc for free
When I looked into it first, Pangolin seemed a bit overwhelming.
Is it hard to set up?
I’m a bit stumped, what do you gain from this setup?
Or do you mean just running some services through the tunnel for easy access and “hide” others behind tailscale?
Cloudflare has some opt-in auth. Mail-OTP is a nice balance imo: You can allowlist mail addresses per service/subdomain and set expiry for each. Then for access, you first have to enter the mail address, get the OTP and then access the service.
So, nobody without access to allowed mail addresses even gets to knock on you door.
But yeah, that’s why I think about going tail scale: why bother having something exposed when not needed?
I just think, some services might be nice to provide to friends, too - and having them connect to my tailnet for this is a bit too much friction, I guess


Yeah, weekly backup to B2 or similar should be fine. Postponed setting it up myself - I paid for a year of Ente and currently sync everything both to premium Ente and my local Immich, so backup is fine for now.
For the heat: I am running it on a Pi4 with 8GB RAM and it runs pretty decently even without cooling. For the large import, I set up only the ML-container on a more potent desktop (still fiddling with GPU HW-acceleration) and added it as remote ML to Immich, so I can offload heavy ML load when e.g. importing many files.
The normal upload stream is fine with the local ML, though