If you want to setup a mbin instance. Just let me know.
melroy
Replying to @beep@piefed.world
Don't trust any government. Period.
Replying to @superglue@lemmy.dbzer0.com
These are the most dangerous developers..
Replying to @XLE@piefed.social
Facts. How good you are as a developer. Ai is a really useful tool. Especially the latest frontier models. I don't like the companies behind them. But the models are very powerful.
Replying to @sanitation@lemmy.today
Just respawn if you die.
Replying to @smallserverdata@lemmy.ml
Fail2ban is definitely using too much cpu and ram for me now! I will switch to fail2ban-rs soon.
With my setup. It's using currently about 2gb of ram. And way too many cpu cycles.
Replying to a post on adultswim.fan
Ow jeej. I'm sorry for you.
But does it also work in powershell? Haha just kidding. Nobody is using that.
Replying to @Kekzkrieger@feddit.org
Under Linux mint in I have an applet for that. Next to the clock.
Replying to @trilobite@lemmy.ml
I also still want a 3 node setup for high availability as well! With the recent ram prices etc. I postponed it.
However the idea is simple. You setup a ceph cluster so the vm storage etc is shared across the cluster or your nodes. Then you can configure for each vm where it should start and where it can fallover to. Eg. Start a vm on node 1, but also allow it to start on either node 2 or 3 in case node 1 is down. Ceph cluster takes care of the rest.
Replying to @Imaginary_Stand4909@lemmy.blahaj.zone
- Unbound can override custom domain names if you want.
- I migrated from Nginx to Angie's to get more features for free. And also has builtin let's encrypt support.
- If the services are public configure fail2ban and something like Angie Guardian see: https://angieguardian.org to reduce ddos and bots.
Replying to @xavier666@lemmy.umucat.day
Proxmox down. Whole internet down? No thank you.
Replying to @yesman@lemmy.world
Then boot Linux usb. Format your disk. And install Linux instead.
Replying to @mesamunefire@piefed.social
Good :)
Replying to @mesamunefire@piefed.social
Dammit YT.
Replying to @hirihit640@sh.itjust.works
The scrapers most likely don't use the VPN providers AFAIK. But these cloud providers have dozens of datacenter locations where you can rent your own virtual server (VPSes) and those datacenters are also often used by VPN providers.
Its actually often coming from separate IP addresses. Which makes it actually even harder, its not just 1 or 2 IP addresses. Meaning both good and bad traffic has 100.000+ of unique IP addresses per IP range. At that point I block the whole ASN: https://www.cloudflare.com/learning/network-layer/what-is-an-autonomous-system/
Meaning I basically block the whole datacenter and mark them as bad actors. Cloud server providers F*K up the internet, since before you can easily block one, two or ten IPs and be done. Today, those bad actors and scrapers or DDos attackers can use millions of unique IP addresses, because it can rely on the whole cloud provider IP ranges (ipv6 is even more insane ofc).
Replying to @hirihit640@sh.itjust.works
Yea so the same servers and IP addresses VPN provider use (which are again just cloud providers) are also used for other purposes mainly by scrapers and DDos attacks indeed. Too bad all those cloud providers do not act accordingly in the past 5 - 10 years. Since its getting worse and worse. With the increase of datacenters and centralization, I consider it a duty of these companies to take action to stop these scammers, spammers, scrapers, and attackers.
However, that is often not the case. Now I must say, I created Angie Guardian myself (alternative to Anubis). So hopefully soon I can slowly open some of ASN bans. And see how it goes.
GitHubGitHub - AngieGuardian/angie-guardian: WAF + PoW Angie sidecar: protect against bots and DDoS attacksWAF + PoW Angie sidecar: protect against bots and DDoS attacks - AngieGuardian/angie-guardianReplying to @hirihit640@sh.itjust.works
I block some misbehaving data centers. Which are often also used by VPN providers. So it's more collateral damage.
No I fully block some data centers not just rate limit.
Replying to @hirihit640@sh.itjust.works
nah its not down.. maybe you use a VPN.
Replying to @hirihit640@sh.itjust.works
- I run 50+ websites
- MariaDB instances
- PostgreSQL instances
- Docker containers
- Mbin, Nextcloud, GitLab, GitLab runners, gitea, bitcoind, fulcrum, grafana, prometheus, influxdb, Synapse, Angie, telegraf and various other services like fail2ban etc. etc.
All optimized for performance and fine tuned as well, eg. lets say you run mariadb vs how I run it:
innodb_buffer_pool_size = 8G
innodb_flush_log_at_trx_commit = 2
innodb_log_file_size = 2G
innodb_log_buffer_size = 32M
innodb_max_dirty_pages_pct = 90
innodb_io_capacity=5000
innodb_io_capacity_max=20000
innodb_read_io_threads=8
innodb_write_io_threads=8
query_cache_type = 1
query_cache_limit = 2M
query_cache_min_res_unit = 2k
query_cache_size = 128M
tmp_table_size= 128M
max_heap_table_size= 128M
[mysqld]
max_connections = 200
character_set_server = utf8mb4
collation_server = utf8mb4_general_ci
transaction_isolation = READ-COMMITTED
binlog_format = ROW
innodb_file_per_table=1
# Increase open files based limits.conf value
open_files_limit=65535
Same idea for Postgresql.. You can run "postgres" or.. actually run postgresql in production correctly like:
shared_buffers = 6GB
work_mem = 20MB
maintenance_work_mem = 2GB
maintenance_io_concurrency = 200
max_worker_processes = 14
max_parallel_workers_per_gather = 4
max_parallel_maintenance_workers = 4
max_parallel_workers = 12
synchronous_commit = off
commit_delay = 300
checkpoint_timeout = 30min
max_wal_size = 60GB
min_wal_size = 4GB