Single node K3s is it worth it?

Been running my homelab using docker compose files with bootstrap scripts to create the directories with correct permissions for bind mounts, shared docker networks, install utilities on the host, backup scripts and some other small automated tasks.

But I'm thinking about running a single node k3s cluster. Why? I want to learn about kubernetes (we use them at work, but we have a fancy interface over it so besides main concepts I didn't learn anything else), I want declarative configuration, better security, maybe learn about helm charts, maybe make it easier in the future when I'll add multiple nodes (but that's very far in the future because first I want to upgrade my network infrastructure, get a NAS).

What are your thoughts? I'll just waste time or is it worth it?

reddit.com
u/sikupnoex — 22 hours ago

Anyone downloading from Youtube?

There's an album I couldn't find on physical media. The only rip that I found online is a 128 kbps mp3 that sounds worse than what I found on youtube.

And I was wondering, do people here rip from YouTube as a last resort?

reddit.com
u/sikupnoex — 5 days ago

Running Tailscale on host and on sidecar containers

There are lots of gaps when talking about tailscale and Docker on the internet. For example most tailscale sidecar docker compose files add NET_ADMIN and other capabilities, but by default Tailscale runs in user space and it doesn't need those capabilities.

Anyways, I want to address another issue.

Sidecar containers are great because you can create one for each service and each one of them gets a MagicDNS name. But, it's also great to run Tailscale on the host because of Tailscale SSH.

Also Tailscale has ACLs. I can tag each container and control who (users/groups or even other tagged machines) can access the container at which ports.

But I noticed that the containers are accessing other tailscale nodes using the host's tailscale network interface, basically bypassing the ACLs (only the host ACL is restricting access). I configured the host firewall to drop the outbound packets to the tailscale interface (and configured the host tailscale node as a peer relay because there was an issue where direct connections couldn't be established).

I'm a programmer and at work there are smarter people figuring out networking and security, and those issues were not that obvious to me (actually I discovered this by mistake and yes, I used tailscale in my homelab for a long time).

I want to learn more about those things. Do you recommend any articles/guides other than "copy this compose.yaml and be done with it"?

reddit.com
u/sikupnoex — 7 days ago
▲ 102 r/bucuresti

La fiecare furtuna cad/se rup zeci de copaci și e în mare măsură vina primăriei că în loc să toaleteze copacii pur și simplu îi mutilează

reddit.com
u/sikupnoex — 2 months ago