r/selfhosted 45m ago

Self Help self hosting a DNS server on old android phone

Upvotes

Guys anyone have any idea about selfhosting a DNS server on an old android phone? Android 4.4.2 with root access, idk if it possible or can be done, or even how, all rests I got was just "how to change the phone's DNS" but I want to use the phone AS A LOCAL DNS?


r/selfhosted 1h ago

Need Help How safe is it to expose my stack to internet?

Upvotes

Hi guys,

I'm pretty new to selhosting. I have a basic stack with Jellyfin and the *arr tools.

I'm also using Radicale, Vaultwarden, Immich and Caddy.

Currently I'm connecting with Tailscale, and I feel like this is the safest thing to do. However I would like the stack to be very accessible for my friends and family, and make it so they don't have to turn Tailscale on each time they want to watch a movie or something.

So I was thinking of exposing on internet directly, but how safe is it? I think if Caddy is in front, it could be ok? Since I also have the passwords and everything. Is it worth the risk?

Is there any general recommendation, doc on that?

Thanks a lot for your help


r/selfhosted 1h ago

Solved PSA WordPress Core had Critical Vulnerability. Patch released on Friday. Immediately update

Thumbnail
slcyber.io
Upvotes

7.0.2 got released on Friday. Exploits are already happening.
4 of my customers websites got hacked. I was busy the last days and weren’t up to date.
Good time to notice that 2 backups failed without me noticing it. Fml


r/selfhosted 1h ago

Need Help Public services on local internet during outage

Upvotes

I have a selfhosted server which works quite well. A while ago we had an internet outage and realized a lot of the services didn't work due to DNS.

There's two DNS records we have, *.example.tld and *.home.example.tld

The "home" subdomain is local only. If we host our own DNS, it would likely work in case of an outage, though I'm unsure about certificates (currently they're done using Cloudflare ACME) but from what I remember they persist a while.

The problem is public services exposed to the WAN (yes I know, I have done as much as I can for security, and I know the risks). When outside of the local network, I'd want it to point to the public IP (through a proxy), but on the local network, have it point to the server hosting the proxy.

Self-hosting a DNS seems like the solution for this as well, but I feel like having a domain pointing to two different addresses depending on where you are would cause issues with cache. I've been told this is also a "Split DNS" but also to avoid it when possible

I could perhaps have it on both the regular DNS record, as well as the self hosted "home" DNS, but then I have the issue of the same service being served on two different addresses. It would maybe work for a TV, but dealing with it on a phone or a laptop you'd have to swap it every time there's an outage, which isn't very often so it's likely it would just be unused.

Everything is behind two reverse proxies, one for local-only and one for public


r/selfhosted 1h ago

Need Help Advice on selfhosted audio setup

Upvotes

Hello !

After Jellyfin full and super neat setup, I’m thinking of getting off YouTube Music to selfhosted music.

Navidrome is installed with Lidarr (very questionable in the setup), slskd and Aurral.
Nothing is definitive and I’m looking for solutions.

I’d like first to get all my liked music and playlists off YouTube Music in my library. Either by downloading from YT or through any other provider.
Some tracks I want are long mix and concert so for those I’ll need to get them from YouTube. Any flow to get it done automatically or half automatically ? (Like Seer : request it will download organise and put the right meta tags).

And for the follow up and discovery what do you use and how to work it everyday ? Discover the. Download then organise then listen.
I started downloaded all the discography of each artist in one playlist of one type of music and was overwhelmed with 850 albums… if I go to all styles I like I’ll end up with 10K albums of music I’ll not listen for most of it.

Well the way YT and Spotify and Deezer works is quite fine, any advice on getting a smooth transition experience ?

Or should I go through albums and just listen them as if I was back in my childhood in the 90’s ?

Thanks !


r/selfhosted 2h ago

Personal Dashboard My Glance Dashboard Setup

Post image
45 Upvotes

I must say, i spent way too long tweaking the glance configuration, but i think it resulted in something i am pleased with. Here is my very basic homelab setup:

  • Immich - Photo and Video management, my replacement to google photos.
  • Beszel - Insanely lightweight server monitoring
  • Dockhand - A pretty neat way to manage my docker containers. Don't really use it much since (out of old habits), i just use the terminal.
  • Nginx Proxy Manager - Makes it much easier to access my homelab
  • Scrutiny - A really easy way to view my drives' information like health or temps.
  • Pihole - Simple network-wide adblocker. I am too scared to use technitium so i use this lmao.
  • Jellyfin - Media streaming. A replacement to paying thousands to rent something i don't even own.
  • Arr Stuff - I have far too much arr stuff so i bundled it into one section. Sonarr, Radarr, Lidarr, Seerr, and Prowlarr paired with qBittorrent.

This is all powered on my TerraMaster F4-423. I will get an extra mini computer to run most of the containers and let the NAS handle the media things, but i am kinda broke so i probably won't for a while :/


r/selfhosted 3h ago

Wednesday Exceptions PMDA...It started as a script to find duplicate albums in my Plex database. It got a bit out of hand. :)

0 Upvotes

First of all, moderators, I hope this falls under the "Wednesday exception", if not, feel free to remove the post and I will repost it on Friday ! (PMDA exists for approx. 2 years by the way...)

A while ago I wrote a small tool for one job: detect duplicate albums in my Plex music database. That's it. That's what PMDA was, and the name stuck from that first life.

But I'm a music hoarder with decades of rips, downloads and transfers, and once the dupes were found I kept hitting the next problem, then the next: albums with no usable tags showing as "Unknown Artist", incomplete rips hiding in the library, missing covers, no way to know what was worth upgrading. I've used and genuinely like Plex, Jellyfin, Navidrome, Roon, foobar2000, and the usual tools like beets, SongKong, Picard. Each one covers a slice, but none of them understands the collection. So the dupe script kept growing, and at some point I accepted it had become something else: a self-hosted server that takes care of the library itself, and plays it.

The librarian part (what makes it different):

  • Identifies albums even without usable tags, using folder structure, track durations, cover OCR and acoustic fingerprints. When it isn't sure, it says "I don't know" instead of guessing.
  • Cross-checks MusicBrainz, Discogs, Last.fm, Bandcamp, Deezer and iTunes. Fetches covers, artist images, bios, reviews and public ratings.
  • Detects duplicate albums and editions, compares them (format, bitrate, completeness) and quarantines the losers. Everything is reviewable, nothing is deleted without you.
  • Flags incomplete rips and broken albums instead of letting them pollute the library.
  • Shows each artist's full discography, including the albums you don't have, so you can see what's missing at a glance.
  • Sorts a messy intake folder into a clean Artist/Album tree, one folder per release, compilations correctly filed under Various Artists. It can export that cleaned copy to feed Plex, Jellyfin or Navidrome if you want to keep your player.
  • Ships an MCP server: plug Claude (or any MCP client) into your own library and ask it things like "which albums did I add this month that have no cover" or "find the box sets". Your data stays home; you bring your own assistant if you want one. Nothing AI is baked into the server itself.

How the intake works: you point PMDA at two folders, a messy intake and a clean library. Everything you drop in the intake gets identified and moves out on its own merit: verified matches are filed into the clean Artist/Album tree, albums whose tags you chose to trust follow the same path, and duplicates or incomplete rips land in a review quarantine instead of polluting the library. The intake empties itself over time, the library only ever receives clean albums, and nothing is deleted without your say.

The player part:

  • Full web player: queue, volume leveling (EBU R128), 10-band EQ, synced lyrics, smart playlists, internet radio, and personal radios built from your own listening history.
  • iOS app: offline downloads, background playback with lock-screen controls, AirPlay 2 and Chromecast, translated into 17 languages.
  • OpenSubsonic API, so your favorite Subsonic client (DSub, Symfonium, play:Sub...) works out of the box.
  • ListenBrainz scrobbling per user.

The multi-user part:

  • Invite family and friends by email; they get a small onboarding wizard and their own history, likes and recommendations.
  • Users can recommend albums to each other inside the app.
  • Optional weekly email digest per user: "what landed in the library this week", with covers and reviews.
  • 2FA, per-user permissions, and a request system so guests can ask for what's missing.

Everything is self-hosted: no cloud, no telemetry, no account with anyone. It runs as a single Docker container (PostgreSQL and Redis inside; sqlite-based tools tend to struggle once you get past 1M tracks).

Native Linux and macOS installs are what I'm working on next.

More info, the full feature tour and the documentation are on the website: https://pmda.muteq.eu (docs: https://pmda.muteq.eu/docs).

The iOS app is on the App Store as of today: https://apps.apple.com/app/pmda/id6788288960

Android: the Play Store listing is still on my todo list, but the APK is ready. Say the word in the comments and I'll share it.

Full transparency: I built this with Claude as a coding assistant. I've been building software and products for 15+ years, I know exactly what I'm doing, and I use the best tool available for the job. The spec, the architecture, the reviews and the testing are all mine. Judge the product, not the workflow.

It's free: https://pmda.muteq.eu (Docker Hub: meaning/pmda).

It's a passion project by one person, so be gentle, and I'd genuinely love feedback from people with big messy libraries.

P.S. if you actually made it all the way down here (congratulations): there's a small Discord for PMDA users, discord.com/invite/2jkwnNhHHR

Screenshots (web UI):

Home, personalized per user
Artists grid
Artist page: hero, bio, discography with the albums you're missing
Album page: tracks, editions, review
Full-screen player with synced lyrics
Duplicate review: side-by-side editions, nothing auto-deleted
Enrichment: bios, reviews and ratings pulled from public sources
Internet radio and personal stations
Library statistics
Search across artists, albums, tracks and labels
Label pages
Recommendations between users

Screenshots (iOS app):

Home, Now playing, Artists, Discovery
Search, Recommendations, Why PMDA

r/selfhosted 3h ago

Need Help Self Hosted Solution for Comms

2 Upvotes

Hey y’all!

I have a server where I host Plex and some game servers for family and friends. Every once in a while I have to take it offline for general maintenance and it’s becoming a hassle to individually text everyone about the status.

Any self hosted solutions for mass communication? If it includes something that can be used as a newsletter that would be even better honestly. A lot of the users like to know what was added.


r/selfhosted 3h ago

DNS Tools Does a Adguard Home DNS Rewrite entry always override a Custom Filtering Rule for the same domain?

1 Upvotes

I have a domain configured both in Filters → DNS Rewrites (global answer) and as a Custom Filtering Rule using `$dnsrewrite` + `$client` (meant to give a different answer to my WireGuard clients only).

In practice, the DNS Rewrite entry always wins, the client-specific Custom Filtering Rule never seems to apply as long as the DNS Rewrite entry exists for that domain.

Is this expected behavior? Is there a documented priority order between the two rewrite systems, and is there any way to make the Custom Filtering Rule win instead (without removing the DNS Rewrite entry)?


r/selfhosted 4h ago

Personal Dashboard Deepseek V4 Flash configure my Grafana dashboard

Post image
0 Upvotes

So I've been putting off setting up proper monitoring for my self-hosted stuff for way too long. Finally sat down this weekend, but instead of doing it all by hand, I figured I'd see how far an LLM could get me.

Turns out DeepSeek V4 Flash is honestly not bad at configuring Grafana dashboards. I described what I wanted to keep an eye on across my services, and it gave me a config to work from. Still a good bit of work left on this one. Some panels need fixing, and the layout isn't perfect, but I'm pretty impressed. Would've taken me way too long to do all this from scratch.

It also made me realize I need to account for a lot more parallel streams than I was tracking. It surfaced stuff I wasn't even monitoring and probably should've been.

I'm self-hosting the usual pile here: some containers, a couple of databases, the network stuff, and having it all in one view instead of checking things individually is already a big improvement, even in this rough state.

Not saying replace yourself with an LLM or anything. I still had to understand what it gave me and tweak it. But as a starting point to get off zero, it was genuinely useful.

How's everyone else doing their monitoring? Still tweaking this, so I'm curious what panels or metrics you consider must-haves for a homelab setup. What am I missing?


r/selfhosted 4h ago

Product Announcement I built a system that builds systems. Figured this group might appreciate it.

0 Upvotes

Hey everyone!

Lullabeast is a self-hosted autonomous dev pipeline. You describe an app, and planner/executor/reviewer agents build it phase by phase against a real git repo, with deterministic Python gates (no LLM) verifying every handoff before anything advances. It runs on cheap cloud models or fully local ones, your choice. As of this release it's one docker compose up: a single container, published to loopback only, no accounts, no telemetry, nothing phones home, and there's nothing to buy from me since it's MIT and runs on your own machine against your own model provider. That GIF is the dashboard and a run in progress.

For just under a decade I've been building, improving, and automating systems. Last year I left a stable job at a well-known tech tech company to do independent research and build on my own (fun hobby if you ever want to pull your hair out!). Now, I'm a very technical person. I loved program management and architecting systems, but I never used to consider myself an engineer. Regardless, I had a lot of building to do and this time I had to do it all myself. So after hitting some major hurdles early, I decided to just build a process to simplify the eng work.

Maybe obvious, but I landed on a plan/execute/review loop, and it worked great. It's a pattern a lot of people arrived at independently around the same time. The new frustration was that I was running it by hand: run the planner, review, add feedback, pass to the executor, run the reviewer on the uncommitted output, then either advance or loop back for fixes. It worked, but I was spending most of the day waiting, and I kept telling myself I shouldn't have to babysit this this closely. So I tried to automate it and failed. I'm pretty persistent, so I tried again and hit integration blockers. I also have OCPD (look it up if you're interested lol), so I kept trying, and on the 6th rework of the architecture I finally built Lullabeast, then open sourced it to hopefully save you the same headache.

It's still in beta, and as a perfectionist I see so many things I still want to add: letting the pipeline run enhancements on a project after the first build, more deterministic checks at the gates and at project completion, a companion eval/testing harness for the pipeline that's in the works but still needs polish before I hand it to anyone, a mobile view for quick check-ins, and much more. However (and this is not normally like me to say) I'm still very proud of the progress this system has made over the last year.

I soft launched a few weeks ago and most feedback was good, but engagement sucked, largely because of the old inconvenient install process. That's containerized and down to one command now. If you want to see it work before touching anything, I had it build the same app twice from one spec, once fully local and once on cheap cloud models, and both builds are live and playable side by side: https://lullabeast.ai/living-proof

So if this sounds at all like a structure that appeals to you, please try and break it! Tell me where it falls over, tell me what's obvious that I'm missing. That's genuinely what I'm after.

Repo: https://github.com/bigbraingoldfish/lullabeast Site: https://lullabeast.ai (click-through walkthrough of the dashboard if you want to see it work before installing)


r/selfhosted 5h ago

Media Serving I posted Parker here late last year after I launched. Just wanted to give an update post as it’s become a much more complete self-hosted comic server

Thumbnail
gallery
0 Upvotes

Hey all!

I posted Parker here in December last year. Since then I’ve kept building it, so I wanted to share an update here rather than just link to my old post. Definately had some rough edges at launch and I definitely made some mistakes but I'm still plugging away and committed to making this a viable alternative self hosted comic server.

Parker is an open-source, self-hosted comic server for personal CBZ/CBR libraries. It does not provide, download, scrape, or link to comic files; it’s for organizing and reading a collection you already have.

Since my original post, Parker now has:

- More complete OPDS support

- Smart lists, reading lists, collections, story arcs, and stacks

- Insight pages for seeing relationships in your collection: Writer <-> Penciller, Writer -> Character, Penciller -> Character and Chracter Chemistry

-  Library Timeline pages for character and team tags, making it easier to explore a character or team’s reading history across your library.

- User ratings on comics

- A faster reader with manga mode, double-page spreads, long view (web comics), bookmarks, and resume behavior with many settings overridable on a per book basis.

- Reports for missing issues, duplicates, metadata health, storage analysis, and corrupt/low-page-count files

- Added a volume-level Following workflow so users can track future issues of a specific run without implicitly subscribing to every historical volume in a series like you would in a real comic shop.

- Optional parallel thumbnail generation and metadata parsing for much faster scans

- Multi-user library access and age-rating-aware permissions

- Better home/discovery rails like Continue Reading, Trending, and New from Following

- Improved layout for settings page in Admin

- A new admin diagnostic page to aid in troubleshooting as well as a bootup health check to alert the user of any major issues.

My philosophy is still “filesystem is truth”: Parker reads metadata from ComicInfo.xml inside your archives instead of trying to own or rewrite your library. This was the impetus of me starting to create Parker. The better the metadata is the better Parker will show insights and enhance discoverability.

GitHub:

https://github.com/parker-server/parker

Docs / Getting Started:

https://github.com/parker-server/parker/wiki/Getting-Started

I’d especially love feedback from anyone with a larger library, OPDS clients, manga/RTL collections, web comics or a Docker/NAS setup. The main things I’m trying to improve next are documentation, OPDS compatibility, migration tooling, and multi-folder library support.

Original launch post for context:

https://www.reddit.com/r/selfhosted/comments/1pk78gl/comment/oij4q61/

Thanks again to everyone who gave feedback the first time around. It was very helpful!

PS: There are screenshots in the original post to look at. I attached some new ones here of some of the newer functionality (bookmarks, insights, etc).


r/selfhosted 5h ago

Need Help Am I being safe enough with my server?

11 Upvotes

hi all! I am new to self hosting and I'm wondering if my server is set up securely. I currently run the following docker containers:

- Jellyfin

- NGINX Proxy Manager

- authelia

- lldap

- homarr

- Dropped Needle (formerly musicseerr)

the only exposed ports I have are 80 and 443, and I forward everything to a cloud flare managed domain through npm. I use an SSL certificate on cloud flare for https and require authelia (with lldap) login to access any page.

am I being safe? what further steps can I take to secure my IP?

EDIT: I do not use cloud flare tunnels, just DNS hosting. From my understanding, cloud flare does not allow use of their tunnels for media. If I should seek out a different domain host, let me know.

EDIT 2: I was actually using cloudflare tunnels, they are turned off now.


r/selfhosted 5h ago

Need Help Help me decide if Storage or Proxmox should be migrated to different hardware.

0 Upvotes

Hi,

tldr: Which needs ECC memory more Proxmox or TrueNAS media storage?

Help me choose which one gets 16GB of DDR4 ECC memory and which one gets 64GB of non-ECC DDR4 memory.

\
I have proxmox installed on a HP Z440 with a Intel Xeon E5-1630 with 4 cores, 8 threads, and 16GB of DDR4 ECC memory.

I have have quite a number of containers on it, which live on an SSD. There are also two 8 TB HDDs for media file storage for Jellyfin, Audiobookshelf, and such.

\
I recently borrowed an old computer from one of my brothers in law, that was just collecting dust in a basement.
I have been told I can buy it off him if it suits my needs.

It has a Intel Core i7-6700 with 4 cores, 8 threads, and 64GB of DDR4 memory (non ECC).

\
I have wanted to have my media file storage on a NAS for a long time, but I haven't been able to afford one.

So I was going to install TrueNAS on the Core i7, but then I thought: Isn't it better to have the file storage on ECC memory?

\
So the full question is: Should I move my storage on to the Core i7 with no ECC memory, or should I migrate proxmox on to it instead?


r/selfhosted 5h ago

Wednesday Exceptions Sutra is back in Europe! + Sneak Peek at CBZ & Panel-by-Panel Comic Support

Post image
5 Upvotes

Hey everyone, good news for those who asked: Apple finally approved the updated forms, and Sutra (my iOS reader for Calibre, Kavita and other OPDS feeds) is officially back in the European App Store!

Sneak Peek: CBZ & Smart Panel Support
I’m currently deep in the weeds building panel-by-panel comic support. As you can see in the attached comparison image, tapping the bottom-right icon isolates individual panels to fit your screen natively, making reading on smaller devices dramatically better.

Comics have wildly different panel definitions and chromas, so getting this consistent across my test bench is taking up all my free time outside of my day job and family. Because this is the core feature of the next update, I want it to be close to perfect before shipping - so the release may slip to next week.

Thanks to everyone using the app, and do let me know if you have any feedback on the preview!

Download Sutra here


r/selfhosted 6h ago

Meta Post Codeberg bans vibe coded projects

Thumbnail news.ycombinator.com
397 Upvotes

Codeberg seems to ban vibecoded Projects; reason might be german copyright law

It looks like Codeberg want only copyrighted material in their service, so it is reliable in the future that e.g. licenses must be followed (e.g. GPL), and copyright doesn't suddenly get declared as being of the model owner, and it isn't a copy of something else.
That is a cautious reasonable position - in early days of LLM coding (3 years ago!) indemnity from model companies was a major issue globally because of the lack of clarity of the law around this. The US specifically has settled on it being (effectively?) public domain. But I don't think that is fully settled, and it certainly isn't settled in international copyright law.
The goal of the vague "mostly" in the Codeberg change is to ensure there is enough human input to the code they host, to be reasonably sure under German copyright law it is copyright of the person sharing it.

edit: link to poll that caused it (might be down due to high traffic) https://codeberg.org/Codeberg/org/pulls/1253#issuecomment-19820434

edit 1: i dont defend/oppose this move, i just find it interesting


r/selfhosted 6h ago

Guide Scaling voice agents breaks in a different place at each layer — here's the one that usually caps you first

Thumbnail
medium.com
0 Upvotes

I run self-hosted LiveKit voice agents, and I kept hitting the same trap: add more workers, calls still drop. Wrote up what I learned about why.

The core idea: a voice agent isn't one system with one capacity number. It's a stack — media/SFU, worker pool, inference (STT/LLM/TTS), telephony, your own app calls — and each layer has its own independent concurrency ceiling. Your real capacity is the *lowest* one. So the bottleneck is usually not compute; for a lot of teams it's the STT/TTS concurrency cap or the SIP channel count, which no amount of extra workers fixes.

The write-up goes layer by layer with the actual numbers (worker sizing from LiveKit's load test, the autoscaling-threshold gotcha, a 500-concurrent-call capacity table, and a rough cost-per-call-hour model). Self-hosted / Kubernetes focused.

Curious what layer bites others first in production, for me it's almost always inference concurrency. What's yours?


r/selfhosted 6h ago

Need Help weird DNS(i guess) issue

1 Upvotes

I cant access a jellyfin container that is hosted on my machine, if I use my local DNS record to reach it.

For context :

- I host pihole , OpenSpeedTest , and jellyfin

- pihole is hosted on : mini (which is linked to my LAN as the nameserver)

- jellyfin is hosted on : pc

- open speed is hosted on both

- this is a recent issue

For some weird reason, I can only access jellyfin UI if i use "localhost" or "pc IP" in the URL bar.

I use google chrome, and previously was able to use the local DNS record with no issue.

Like this: "pc:8096" and that stopped working for jellyfin only

"pc:3000" "localhost:3000" "pc-ip:3000" for OpenSpeedTest, work

-----

As to the 'mini' machine all ways work fine

"mini:80" "mini-ip:80" for pihole, work

"mini:3000" "mini-ip:300" for openspeed, work

-----

What I tried

- restarting all containers several times

- resetting jellyfin (re-running docker run after deleting the config files)

- flushing chrome DNS ('chrome://net-internals/#dns')

- rebooting both machines

Here is a bunch of screenshots demonstrating said issue

The issue im recently facing
Local DNS Table
using host ip (same machine)
using localhost
pihole using local dns record
pihole using machine ip

r/selfhosted 6h ago

Docker Management Docker Directory

0 Upvotes

So, im looking to re-organise my dockers on my server. I am trying to come up with my own standards of where on the file system to put the docker compose/configs and persistant data.

I see the consensus points toward using either /opt/docker/service or /srv/docker/service.

But looking at the descriptions for the /opt/ and /srv/ directories on FHS:

/opt is reserved for the installation of add-on application software packages.

/srv contains site-specific data which is served by this system.

Would it not make sense to store the docker compose/software configs on /opt/docker/service and the persistent data in /srv/docker/service?

Im clearly overthinking this, but im interested on peoples thoughts on this method? Am I overlooking something fundamental that makes this organisational scheme over complicated and unnecessary?


r/selfhosted 7h ago

Meta Post Harper: Self Hosted Alternative to Grammaly by Automattic (WordPress)

16 Upvotes

While watching better stack youtube channel I came to know about Harper, which is a decent alternative to Grammarly. It runs offline and they claim that it takes 1/50th of RAM as compared to Language Tools, which you can also self host by the way. It seemed genuinely nice self hosted tool so I thought I share here.

https://github.com/automattic/harper


r/selfhosted 7h ago

Release (AI) I work in security and self-host everything at home. Built an open source linter to catch my compose mistakes.

42 Upvotes

Everything in my homelab runs on Docker Compose, but it wasn't up to the security standards I wanted. I wanted something small and compose-only that just runs, so in April I started building one.

It checks for the important stuff against OWASP and the CIS Docker Benchmark: privileged containers, the Docker socket mounted into a container, host network mode, containers running as root, etc. There's a fix command that handles the safe edits as a dry-run diff.

pip install compose-lint, or Docker Hub. github.com/tmatens/compose-lint

This is my first open source project. I built it because I needed it. Wondering if it's useful to anyone else, and where you'd disagree with the severity calls.


r/selfhosted 7h ago

Wednesday Exceptions [Tool] ImmiChange – Android companion app for Immich that automatically sets your photos as wallpaper

0 Upvotes

I've been running Immich on my home server for a while, and it's great — but I realized I almost never actually saw my photos unless I opened the app on purpose. Thousands of memories just sitting on a drive in the closet. Felt like a waste.

So I built ImmiChange — an Android app that pulls photos from your Immich albums and rotates them as your wallpaper automatically. Your own Immich server is the backend; the app is just the thing that puts those photos in front of you every time you pick up your phone.

I wanted it to be something I could set up once and forget. The annoying part turned out to be Android itself — battery optimizations love to kill background jobs — so a lot of the work went into making rotation actually reliable without draining your battery or eating mobile data.

How it works:

  1. Create a dedicated album in your Immich instance
  2. Select it in ImmiChange (Pro: multiple albums)
  3. App downloads photos only over Wi-Fi, respects a storage cap you set (default 20MB)
  4. Wallpaper rotates through cached photos; refreshes the pool when the cache runs out and Wi-Fi is available

Because it runs off that local cache, wallpaper changes keep working even when the server is down or you're away from home.

Features worth knowing about:

  • SSID restriction — only syncs on your home Wi-Fi, so it never touches mobile data
  • Home-screen widget — pause rotation or lock the current view without opening the app
  • TopShot — when a wallpaper looks just right, freeze it and upload it back into an Immich album as a real asset
  • Live wallpaper with smooth parallax as you move the phone (tilt/gyro, adjustable sensitivity)
  • Smart date overlay — stamps the shooting date from EXIF, and the text color auto-adjusts to the photo's brightness so it stays readable
  • Shared albums from other Immich users show up in the picker too, not just your own
  • Everything stays local. API keys are stored encrypted on-device and never leave it.

Free to use, with a few extras behind Pro. Android only for now.

More info and setup: https://zero-webcreate.com/lp/ImmiChange.html

Would love feedback, especially from anyone running a big library — curious how it holds up.


r/selfhosted 9h ago

Release (AI) Will Be Done v0.10 released: offline-first self-hosted task planner with weekly timeline

0 Upvotes

New version of Will Be Done is released! Will Be Done is offline-first, self-hosted task planner with visual weekly timeline.

The main idea is pretty simple: collect tasks, put them on week timeline. It works local-first, so tasks are stored locally in browser/desktop app. You can open app and use it even when your server or homelab is down. When server is back, sync will catch up between devices.

Main features right now:

  • Offline-first task management
  • Fast sync between devices
  • Self-hosted server with SQLite
  • Visual weekly planner
  • Stash for tasks you want to keep in focus
  • Projects with categories/columns
  • Drag and drop
  • Recurring tasks
  • Task descriptions and checklists
  • Vim-style keyboard navigation
  • Desktop app for macOS, Windows and Linux
  • Global quick add in desktop app
  • Mobile PWA
  • Todoist and TickTick import

And here is what changed since my last post:

  • Added Stash feature. You can store tasks that don’t have exact date yet, but you still want to keep them in focus.
  • Replaced floating task window with right sidebar. I think this is much less annoying and task details are easier to manage now.
  • Added task checklists, including in card details.
  • Added mobile card details page.
  • Improved task action menu, with scrollbar support and Vim-style navigation.
  • Added some timeline/project polish, including indicators for tasks that are already scheduled.
  • Added PWA update notifications with better update toast.
  • Added IndexedDB support for faster and more reliable local persistence. New installs use IndexedDB by default. Existing users can turn it on in settings page.

Links:

Demo: https://demo.will-be-done.app/

GitHub: https://github.com/will-be-done/will-be-done

Download desktop app: https://github.com/will-be-done/will-be-done/releases

Self-host with Docker:

docker run -d \
  -p 3000:3000 \
  -v will_be_done_storage:/var/lib/will-be-done \
  --restart unless-stopped \
  ghcr.io/will-be-done/will-be-done:latest

Then open http://localhost:3000/.

Would love to hear feedback, especially from people who care about self-hosting, offline-first apps, local-first sync, or replacing Todoist/TickTick with something open source.


r/selfhosted 10h ago

Solved UGOS Pro forced update broke Docker permissions

0 Upvotes

UGOS Pro forced update broke Docker permissions (Nextcloud “apps directory not found”, MariaDB crash loop) — root cause was UGOS’s opaque ACL management, not Docker itself

NAS: UGREEN DXP4800 Plus OS: UGOS Pro (forced update, previous version flagged as obsolete) Docker Engine: 26.1.0 → 29.4.3 (docker-compose-plugin 2.26.1 → 5.1.3)

Symptom

Right after a forced UGOS Pro system update (1.17.0.0095, ~July 4 2026, which bumps Docker Engine to 29.4.3 for a security fix — CVE-2026-31431), my self-hosted Nextcloud (LinuxServer.io image) became unreachable with:

apps directory not found! Please put the Nextcloud apps folder in the
Nextcloud folder.

Shortly after, MariaDB (also LinuxServer.io image) went into a continuous crash loop with:

/usr/bin/mariadbd-safe-helper: Can't create/write to file
'/config/databases/xxxx.err' (Errcode: 13 "Permission denied")

What did NOT change

Before assuming anything, I checked (and ruled out) all of the following:

  • Docker bind mounts — correct and unchanged (/config, /data mapped exactly as before)
  • File ownership — correct everywhere (docker_user:docker_group, UID/GID 1005:1001)
  • Classic POSIX permissions (rwx) — looked correct at every level (0755/0770) when inspected with stat/getfacl, even as root
  • config.php syntax — valid (php -l passed)
  • Environment variables — unchanged, consistent with the compose file
  • AppArmor — no DENIED entries in kernel logs, even after a full reboot
  • SELinux — not active
  • userns-remap — not configured in daemon.json
  • The problematic symlink (/app/www/public/apps → /config/www/nextcloud/apps, used internally by the LinuxServer.io image) — verified intact; the exact same failure happened even accessing the real path directly, bypassing the symlink entirely
  • OOM kill / container restarts — none (RestartCount: 0, OOMKilled: false) So: correct ownership, correct classic permissions, no MAC framework blocking anything — and yet, testing as the actual unprivileged user the containers run as (docker exec --user abc ... stat ... / touch ...), every operation failed with Permission denied.

Root cause

UGOS treats its Control Panel → Shared Folders → Permissions screen as the single source of truth for ACLs — not the raw Linux filesystem. The forced system update silently rewrote the real on-disk ACLs for the Docker shared folders involved, without the panel necessarily showing any obvious inconsistency.

Critically: manual ACL fixes from the CLI did not durably work. I tried both:

sudo setfacl -R -b /path/to/folder # strip ACLs sudo setfacl -Rm u:1005:rwX /path/to/folder # explicitly grant the UID rwX

Both commands completed with no errors, and getfacl confirmed the rule was written — but the actual access as the unprivileged UID kept failing afterward. UGOS appears to resync/enforce its own ACL state on top of (or instead of) whatever raw POSIX ACL you set manually, especially after events like a forced major update.

This matches a pattern independently reported by another user with the exact same NAS model (UGREEN DXP4800 Plus) hitting a nearly identical issue with Syncthing’s filesystem watcher — permission denied despite the panel showing Read/Write, resolved only by fixing the ACL, with the same conclusion: “UGREEN/UGOS handles ACLs in a non-standard or opaque way.”

What actually fixed it

Only fixing the permissions from the UGOS Control Panel itself worked — and the propagation mode matters:

  1. Open File Manager → navigate to the specific folder (not the shared folder root, to limit blast radius)
  2. Right-click → Properties → Permissions tab
  3. Find the individual row for the relevant user (e.g. docker_user — it may appear under multiple groupings, e.g. “General User” and its Unix group; check it in both, UGOS treats it as one identity)
  4. Check Read/Write only on that individual user’s row (not the aggregated group/category row)
  5. Before confirming, open the “Apply permission to” dropdown at the bottom and select “Overwrite: overwrite all permission settings of sub-levels” — NOT “Merge” (Merge leaves whatever broken state already exists in deep subfolders untouched, which is the actual problem)
  6. Only then click Confirm

This forced a real recursive rewrite down to the deepest subfolders and immediately resolved access for the affected containers.

Side effect to watch for

The “Overwrite” ACL operation on the MariaDB folder reset custom.cnf to world-writable (777). MariaDB silently ignores world-writable config files for security reasons:

Warning: World-writable config file '/config/custom.cnf' is ignored

Fixed with a plain chmod 640 on that single file (confirmed only mariadbd reads it, so this is safe) + container restart. Worth checking this every time you have to re-apply ACLs on a MariaDB data folder on this platform.

Takeaway / operational rule going forward

On UGOS, treat the panel as the only durable way to manage ACLs on anything living inside a Shared Folder — including Docker volumes. setfacl/chmod/chown from SSH may look like they worked (no errors, getfacl confirms the rule) but can be silently overridden. If you hit Permission denied errors after a UGOS update despite ownership and classic rwx bits looking completely correct, this opaque ACL layer is the first thing to suspect — not AppArmor, not SELinux, not Docker itself.

Posting this in case it saves someone else the two days of diagnosis it took me.

Environment: UGREEN DXP4800 Plus, UGOS Pro, Docker Engine 29.4.3, Nextcloud + MariaDB + Redis + Nginx Proxy Manager (LinuxServer.io images), Portainer.


r/selfhosted 11h ago

Need Help Remote access to usb memory stick on tp-link router

0 Upvotes

Hi folks, we have a tp-link router at our local community sports club. I have inserted a memory stick into the usb port. I store a slideshow on the drive and show this on one of the tvs. I would like to update the slideshow remotely, ie. outside the club’s network.

I’ve enabled “sftp(via internet)” with the standard port 22. and then tried to access it and get timed out. I’ve delved a bit deeper and the ole interweb suggests I create a port forwarding setting to redirect traffic to my internal sftp address. But this concerns me from a security point of view.

Does anyone have any experience/suggestions please?
Do I make the port forwarding setting?
Do I make another setting to make the sftp work?
Do I try something completely different?

Thanks in advance for your attention and advice.