

Or just a cheap laptop.
Canadian software engineer living in Europe.


Or just a cheap laptop.


Given that sort of description I’d bet that it is DNS actually. If you run a DNS lookup from your LAN for your domain, do you get the external IP or the internal one? You can try this with dig in Linux or nslookup in Windows (I think).
If I’m right and you’re getting the external IP even when querying from your LAN, then what you need is either a separate DNS for your LAN or what they call a “split DNS” whe are a your domain server returns a different value depending on the originating IP.
You can check for this by editing your hosts file. If you add your domain and local IP there and then try to ping that domain on that machine, it should work. If you’ve got a small network, you might even just copy the hosts lines between machines (this is what I do for example).
This wasn’t nearly as interesting as the headline made it sound.
It’s a physical box you purchase to effectively break the law, so some of the architecture is going to be shady because it has to be.
There’s nothing special or nefarious here. Indeed I’ve worked on projects that had to take the same considerations into account.
The “someone else’s Hulu account” claim sounds like bullshit to me because it doesn’t make sense from a business perspective. They’d want to control the accounts in question and rotate the passwords regularly, again to avoid freeloaders. More likely they’ve paid for 25ish Hulu subscriptions in every region (hence the initial call for IP geolocation) and are then relaying credentials to a box based on this info.
The only really sketchy thing in this whole video was the disabling of TLS checking, which was likely done to get around sketchy pirate websites with bad or nonexistent certs. It wasn’t clear though which part of the OS this applied to. If it’s only doing this for the pirate streaming, that’s sort of a bullet you have to take if you want the service. So long as the only data being sourced unencrypted/unverified is some audio and video, you’re fine (assuming you’ve already accounted for streaming such data in your jurisdiction, ie. you’ve got a VPN). If you’re pulling down software updates though, you’re gonna have a bad time.


At my first-ever tech job back in 2000, I was given a little Celeron desktop computer to do my work: mostly writing some ColdFusion and cutting up images in Photoshop. For the most part, the machine worked fine, except whenever I scrolled down on a webpage in Netscape, the box’s PC speaker would start screaming. I tried to ignore it, but I was in a small room with two other nerds and it was getting really annoying.
One day, my frustrated colleague decided it was time to investigate. As part of the process, he noticed that there was very little air coming out of the power supply fan port. “Must be a busted fan and that’s causing an overheating alarm” he declared. We unplugged the box, popped it onto my desk, and opened it up. The internals were pristine. No dust, nothing. The computer was practically brand new after all.
We were just about to crack open the power supply (not recommended, but we were getting desperate) when my colleague noticed that something was wedged inside the fan… it was the biggest (dead, thankfully) cockroach I have ever seen, at least 10cm long. For context, this was in Vancouver, Canada. Those just don’t exist there.
My colleague jammed his screwdriver in there to grind up the cockroach carcass, then plugged the box back in. After a shittone of dessicated cockroach guts spewed out the back, my little computer was operating normally.
As best we could guess, the monster crawled into the fan in Malaysia when as was assembled and somehow got pinned in there, died of starvation, and then stowed away to Canada.


There’s a nifty project on Mastodon where someone is running an instance entirely on solar (and I think a battery?). They’ve been tinkering with some of the code to do things like optimise images for reduced weight or CPU cost.
The project is called @solaradmin@solarcene.community and the account for the person running it is on a separate instance, presumably so people can message them about problems: @smallsolar@techhub.social.


The right time to look elsewhere was when Microsoft bought it.
The next best time was when viable alternatives like GitLab and later, Codeberg appeared.
The next best time was when it became clear that they were stealing your code to feed into their sparkly autocomplete and were going to sell it back to you.
The next best time was when they dumped a bunch of vibecoded garbage into the codebase and killed the uptime.
The next best time is now.
You don’t even have to migrate all your stuff. Just start all your new projects on Codeberg, or GitLab, or something self-hosted. Once you get used to the new place, you can migrate your old stuff when you’re ready.


I look at the number of (hopefully recent) committers and whether they’re human or not.


That was a frustrating read. Dude gets screwed by Microsoft who effectively steals his code and rebrands it as theirs and then he goes on to talk about why he prefers MIT.


That’s understandable, though one of the other commenters suggested the LGPL which might make for a good fit for your case. Here’s a comparison with the other two if you’re interested.
The AGPL is just the GPL with extra rules requiring sharing the code even if you expose it exclusively via a service.


Ooh, yes for for this case, the LGPL would be a good middle-ground for OP’s concerns.


A simple comparison between the two via interoperable-europe.ec.europa.eu says that they’re almost identical save for one clause around trademarks:
https://interoperable-europe.ec.europa.eu/licence/compare/BSD-3-Clause;MIT
But I’d be remiss if I didn’t advocate for a license that better protected your project from corporate theft. The AGPL and GPL are excellent licenses that protect your work and that of the community from companies that would copy it, improve it exclusively for themselves and then ship your work exclusively in binary form:
You might want to look into Gemini (not Google’s “AI” offering, despite the name). It’s an internet protocol for sharing text-only communication. There’s a whole community out there working with it.
I’ve been using the FOSS version of Kvaesitso and I quite like it.


I’ve had a really hard time figuring out how to get cloud native pg working 'cause I couldn’t get longhorn working for disk space.
So instead I went with a separate Raspberry Pi that isn’t part of the cluster to host a single Postgres instance.
It’s inelegant, but has worked for years. Still, I’d rather host a separate pg instance for each project… I just have to figure the above out first.


Neat project, but it appears to be using (L)GPL code in a bunch of places while being licensed under MIT. That’s a big no-no.


#Solarpunk!
Wow, Markdownr is fantastic! Thanks for sharing!
I couldn’t abide such a wall of text, so I reformatted everything into a Markdown table:
| Name | Description |
|---|---|
| LocalSend | Send files on a local network easily |
| Obtainium | Alternative to F-Droid, allows installation from more sources |
| Aegis | 2FA manager |
| CoMaps | OpenStreetMap client |
| Tasks | Astrid was a popular cross-platform productivity service that was acquired and discontinued in 2013. The source code from Astrid’s open source Android app serves as the basis of Tasks. |
| ZipXtract | A fully open-source Android application designed for comprehensive archive management. It allows you to effortlessly extract and create a wide variety of archive files directly on your device. |
| disky | Find your biggest diskspace thieves! |
| WallFlow Plus (Alpha) | A wallpaper app for Android with beautiful wallpapers from wallhaven.cc, Reddit. Designed with Material Design 3 and supports wide screen devices like tablets. |
| Droid-ify | Alternative to F-Droid, allows installation from more sources |
| Aves Libre | A gallery and metadata explorer app. It is built for Android, with Flutter. |
| Phone | It’s a phone dialer |
| OpenTracks | A sport tracking buddy that respects your privacy. |
| Eden | A free and opensource (FOSS) Switch 1 emulator, derived from Yuzu and Sudachi |
| DAVx⁵ | CalDAV/CardDAV synchronization for Android (and other features) |
| Open Camera | A feature rich camera application |
| Obsidian | Alternative store for Android. Not FOSS. |
| kitshn | An unofficial multiplatform client for the self-hosted Tandoor recipe management software |
| Calculator | It’s a calculator |
| Jellyfin | Official Android client for Jellyfin |
| Nextcloud | A safe home for all your data. Access & share your files, calendars, contacts, mail & more from any device, on your terms. This is the official Nextcloud Android app. |
| WiFiAnalyzer | Interrogate devices on your WiFi network |
| Thunderbird | A powerful, privacy-focused email app |
| Breezy Weather | A feature-rich free and open source Material 3 Expressive weather app |
| addy.io | Easily create and manage your addy.io aliases, recipients and more from your device |
| mpv | A video player for Android based on libmpv |
| Paperize | A dynamic wallpaper changer that keeps your device’s aesthetic fresh and exciting |
| M3U | A simple IPTV player for Android phones, tablets, and TV. |
| FairScan | An Android app to scan your documents |
| Harmonic | A Hacker News client |
| SpamBlocker | Blocks unwanted calls & SMS messages without replacing your default call/SMS app. |
| Material Files | An open source Material Design file manager, for Android 5.0+ |
| FUTO Keyboard | A good modern keyboard that stays offline and doesn’t spy on you |
| KeePassDX | Lightweight password safe and manager |
| Signal | Privacy-friendly instant messaging software |
| Bitwarden | Official client for the Bitwarden password manager |
| Audiobookshelf | A self-hosted audiobook and podcast server |
| KDE Connect | Integrates your smartphone and computer |
| GameNative | Allows you to play games you own on Steam, Epic and GOG directly on Android devices, with cloud saves. |
| MJ PDF | A fast, minimalist, powerful and totally free PDF viewer |
| Firefox Beta | It’s Firefox |
| Summit | A mobile client for Lemmy |
| Catima | Card management app |
| ArrMatey | A modern, all-in-one mobile client for managing your *arr stack. Built using KMP with native Jetpack Compose UI for Android and SwiftUI for iOS. |
| OpenKeychain | Encrypt your Files and Communications. Compatible with the OpenPGP Standard. |
| NotallyX | Minimalistic note taking app |
| WG Tunnel | An alternative FOSS Android client for WireGuard and AmneziaWG |
| Bluesky | Alternative to X, developed by the same rich assholes who brought you Twitter (sorry, this is my bias coming through) |
| Mental Math | A simple and clean Android app for mental arithmetic training |
| Fossify Calendar | Your private & powerful schedule planner |
| Moshidon | A fast, highly customizable, up-to-date fork of megalodon adding important features such as a fully federated timeline, unlisted posting, drafts, scheduled posts, bookmarks, and alt text warnings. |
| Memories | Photo Management for Nextcloud |
| AntennaPod | Easy-to-use, flexible and open-source podcast manager and player |
| Home Assistant | This is the official Android app for Home Assistant, a powerful open-source home automation platform |
| Off Grid | The Swiss Army Knife of On-Device AI |
| Tubular | A fork of NewPipe that implements SponsorBlock and ReturnYouTubeDislike |


I’ve used FluxCD in the past and have looked into ArgoCD, but honestly, I’ve not seen any big benefit from either to be honest. I use k8s both at home and at work, and in both cases, we do “imperative” deploys: you run helm install ... either directly or via the CI and stuff is deployed.
So for example at my last job, our GitLab CI just had a section triggered exclusively for merges into master that ran helm install ... for all three environments. We had three values.yaml files, one for each environment, and when we wanted to deploy a new version, the process was:
1.2.3) and push it to the repo. This would trigger a build and push the resulting image into the container registry.1.2.3 to development but not yet to staging or production, then the tag: value in each of the environment files would look like this:k8s/chart/environments/development.yaml: tag: 1.2.3k8s/chart/environments/staging.yaml: tag: 1.2.2k8s/chart/environments/production.yaml: tag: 1.2.2Once that change is pushed, the CI will automatically apply it with helm install ... and make sure that all three environments are what they’re supposed to be.
As for dependent services, that should all be in your Helm chart so they’re stood up and torn down together. The specific case you mention about “Service A” being dependent on “Service B” but stood up before “Service B” is ready is a classic problem, but easily solved:
The dependent service (“A” in this case) should have an entrypoint that checks for everything else before starting. Here’s what I’m using right now in a project:
#!/bin/sh
while ! nc -z "${POSTGRES_HOST}" 5432; do
echo "Waiting for postgres..."
sleep 0.1
done
echo "PostgreSQL started"
touch /tmp/ready
exec "$@"
I’ve even got some code that checks that all the Django migrations have run first for the same situation. The Kubernetes philosophy is that any container should be able to die at any time and be eventually be brought back up and that every container needs to be prepared for this. Typically this means that your containers should operate on the basis of “if I can’t work, die, and hope the problem is solved by the time Kubernetes redeploys me”.
Just get one of these and set everything up in a few browser tabs. Either that or use an OS with workspace support and put the different apps you want on separate workspaces.
In our livingroom, our old laptop runs Arch Linux with GNOME. Jellyfin is on desktop 1, and Firefox is on desktop 2. Firefox runs Netflix, Spotify, and YouTube in separate tabs and switching between all of these is a keyboard shortcut on the above remote. Frankly, it’s simpler than most “smart” TVs I’ve had to work with.