#termius — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #termius, aggregated by home.social.
-
Als jemand, der viel zwischen Servern, SSH-Sessions und Remote-Hosts jongliert, ist ein gutes Terminal für mich etwas Elementares. Mein persönlicher Favorit ist Termius. Die plattformübergreifende Sync der Hosts und Keys ist Gold wert, SFTP direkt integriert, und das UI macht SSH-Verbindungen endlich weniger nach "Textdatei pflegen und hoffen". Für Teams mit vielen Zugängen ist der Vault-Sync ein echter Zeitgewinn. Und bei euch?
-
Als jemand, der viel zwischen Servern, SSH-Sessions und Remote-Hosts jongliert, ist ein gutes Terminal für mich etwas Elementares. Mein persönlicher Favorit ist Termius. Die plattformübergreifende Sync der Hosts und Keys ist Gold wert, SFTP direkt integriert, und das UI macht SSH-Verbindungen endlich weniger nach "Textdatei pflegen und hoffen". Für Teams mit vielen Zugängen ist der Vault-Sync ein echter Zeitgewinn. Und bei euch?
-
So I find myself suddenly needing to get everything off my work laptop and make sure the toolchain I was accustomed to for years works on my own hardware.
THis is proving pretty complicated, particularly since I need something that can run Premiere for my videos. I realized the best choice is my #Windows gaming laptop, so I'm tooling that up to do the job.
Windows is... a weird world. First up, ssh client. #termius Looks good. $10/mo?!? For an #SSH client? Eff that. #putty it is.
-
So I find myself suddenly needing to get everything off my work laptop and make sure the toolchain I was accustomed to for years works on my own hardware.
THis is proving pretty complicated, particularly since I need something that can run Premiere for my videos. I realized the best choice is my #Windows gaming laptop, so I'm tooling that up to do the job.
Windows is... a weird world. First up, ssh client. #termius Looks good. $10/mo?!? For an #SSH client? Eff that. #putty it is.
-
-
我将从Screen切换到Tmux ()
相见恨晚,其实是之前懒得了解,果然有需求才有动力(https://github.com/tmux/tmux
https://github.com/gpakosz/.tmux -
我将从Screen切换到Tmux ()
相见恨晚,其实是之前懒得了解,果然有需求才有动力(https://github.com/tmux/tmux
https://github.com/gpakosz/.tmux -
Hmm, that's kind of annoying... The android app Termius seems to be really bad at maintaining background connections, so I've just discovered I have dozens of old dangling mosh sessions on my VPS.
It's actually just easier to do Termux->emacs->vterm->mosh... 🙄
-
Hmm, that's kind of annoying... The android app Termius seems to be really bad at maintaining background connections, so I've just discovered I have dozens of old dangling mosh sessions on my VPS.
It's actually just easier to do Termux->emacs->vterm->mosh... 🙄
-
Tận dụng máy tính văn phòng cũ, mình đã xây dựng một hệ thống HomeLab hoàn toàn quản lý từ điện thoại qua Termius và Portainer. Chi phí ~0đ, tối ưu năng lượng và tích hợp ứng dụng kiếm thu nhập thụ động để bù tiền điện. Chi tiết về cấu hình, docker stacks và hướng dẫn truy cập từ xa: [GitHub repository]. Cần gợi ý thêm dịch vụ nhẹ phù hợp phần cứng cũ. #HomeLab #SelfHosting #Termius #Portainer #Docker #DIY #IoT #LowPower #VietnameseTech #TựLàmMáyChủ
-
Tận dụng máy tính văn phòng cũ, mình đã xây dựng một hệ thống HomeLab hoàn toàn quản lý từ điện thoại qua Termius và Portainer. Chi phí ~0đ, tối ưu năng lượng và tích hợp ứng dụng kiếm thu nhập thụ động để bù tiền điện. Chi tiết về cấu hình, docker stacks và hướng dẫn truy cập từ xa: [GitHub repository]. Cần gợi ý thêm dịch vụ nhẹ phù hợp phần cứng cũ. #HomeLab #SelfHosting #Termius #Portainer #Docker #DIY #IoT #LowPower #VietnameseTech #TựLàmMáyChủ
-
exploring this, might have to set it up
don't see how it's any different to a regular ssh session over termius or something with tailscale, but i'm curious anyway 👀
-
13 Popular #Software That Feel Like #OpenSource But They Are Not
#Obsidian: Personal knowledge base
#Termius: Modern SSH client
#MobaXterm: Accessing Linux from Windows
#Warp: AI-terminal
#DockerDesktop: Easy container management
#VSCode
#Discord: Developer community hub
#Vivaldi: alternative browser
#VMWare Workstation
#Ukuu: Easy kernel management on Ubuntu
#Plex: Media server
#Tailscale
#SnapStore: Open front, closed backend
#Steam: The backbone of Linux gaming
https://itsfoss.com/popular-software-open-source-feel/ -
13 Popular #Software That Feel Like #OpenSource But They Are Not
#Obsidian: Personal knowledge base
#Termius: Modern SSH client
#MobaXterm: Accessing Linux from Windows
#Warp: AI-terminal
#DockerDesktop: Easy container management
#VSCode
#Discord: Developer community hub
#Vivaldi: alternative browser
#VMWare Workstation
#Ukuu: Easy kernel management on Ubuntu
#Plex: Media server
#Tailscale
#SnapStore: Open front, closed backend
#Steam: The backbone of Linux gaming
https://itsfoss.com/popular-software-open-source-feel/ -
termius上还可以将fido2作为keychain
突然想起来大一上学期买了一个TrustKey T120
试着配置突然想起来自己忘记了PIN
去官网找到了reset方法和管理软件
PDF:https://www.trustkey.jp/manual/biomanager_user_manual_eng_v3.3.pdf
Download:https://www.trustkeysolutions.com/en/sub/support.formok重置好pin🔒和指纹了
-
termius上还可以将fido2作为keychain
突然想起来大一上学期买了一个TrustKey T120
试着配置突然想起来自己忘记了PIN
去官网找到了reset方法和管理软件
PDF:https://www.trustkey.jp/manual/biomanager_user_manual_eng_v3.3.pdf
Download:https://www.trustkeysolutions.com/en/sub/support.formok重置好pin🔒和指纹了
-
Holy hell, #Termius wants to bill me $10/month for the same pro features I paid once for JuiceSSH. That's a big nope.
-
Holy hell, #Termius wants to bill me $10/month for the same pro features I paid once for JuiceSSH. That's a big nope.
-
Well, here’s another app I am removing from all my devices. “Termius” seemed like a very good ssh client for iOS devices. Had lots of good features, was relatively stable.
But their licensing is batshit. $10/mo for a HOBBIEST license. Forever. Never ending. For a fucking terminal program.
Eat shit guys. The company I work for has a staggeringly complex pair of programs that are the top tools in the industry, and they license THOSE for $10/mo.
-
Well, here’s another app I am removing from all my devices. “Termius” seemed like a very good ssh client for iOS devices. Had lots of good features, was relatively stable.
But their licensing is batshit. $10/mo for a HOBBIEST license. Forever. Never ending. For a fucking terminal program.
Eat shit guys. The company I work for has a staggeringly complex pair of programs that are the top tools in the industry, and they license THOSE for $10/mo.
-
Anyone else finding #termius extremely unstable these last few days??
-
For SSH client on Linux I'm using Tilix (default client in Ubuntu Budgie). For my phone I'm using Termius, which is very feature rich. On my newly acquired tablet this client is even better. And today a new version of the app came out, making it even slicker. Now I only need to get myself a bluetooth fold-able keyboard and I'm golden for on the road.
-
For SSH client on Linux I'm using Tilix (default client in Ubuntu Budgie). For my phone I'm using Termius, which is very feature rich. On my newly acquired tablet this client is even better. And today a new version of the app came out, making it even slicker. Now I only need to get myself a bluetooth fold-able keyboard and I'm golden for on the road.
-
I remembered this afternoon that I needed to turn off a #cron job. So I did. I edited root's crontab during half time of the #EnglandA vs #AustraliaA #rugby match. I don't use it often, but #Termius seems to have sprouted an "AI" predictive text tentacle so typing was much easier than it had any right to be. Knowing how to navigate in #vim really helped though. It was a good game too.
-
I remembered this afternoon that I needed to turn off a #cron job. So I did. I edited root's crontab during half time of the #EnglandA vs #AustraliaA #rugby match. I don't use it often, but #Termius seems to have sprouted an "AI" predictive text tentacle so typing was much easier than it had any right to be. Knowing how to navigate in #vim really helped though. It was a good game too.
-
Has anyone been able to make #Termius work with #Tailscale #SSH ? I can shh into my #RaspberryPi from my Mac (both connected to Tailscale) but I can’t from my #iPad with Termius.
In alternative: can you please suggest me a good (even paid one but absolutely not subscription based!) SSH client for #iOS ?
Thanks 🙏
-
Has anyone been able to make #Termius work with #Tailscale #SSH ? I can shh into my #RaspberryPi from my Mac (both connected to Tailscale) but I can’t from my #iPad with Termius.
In alternative: can you please suggest me a good (even paid one but absolutely not subscription based!) SSH client for #iOS ?
Thanks 🙏
-
🇵🇱 Nowy wpis na blogu! / 🇬🇧 New blog post!
~200GB Free Cloud for Your files [ENG 🇬🇧]
#Cloudflare #Docker #DockerHub #dockerIo #FreeTier #FreeDNS42 #HTTPS #iptables #LetSEncrypt #Linux #MariaDB #MySQL #Nextcloud #NGINXProxyManager #OpenSource #Oracle #Portainer #PuTTY #SelfHosted #SSH #SSL #Termius #Ubuntu #ufw #VPS
Autor: @to3k
-
🇵🇱 Nowy wpis na blogu! / 🇬🇧 New blog post!
~200GB Free Cloud for Your files [ENG 🇬🇧]
#Cloudflare #Docker #DockerHub #dockerIo #FreeTier #FreeDNS42 #HTTPS #iptables #LetSEncrypt #Linux #MariaDB #MySQL #Nextcloud #NGINXProxyManager #OpenSource #Oracle #Portainer #PuTTY #SelfHosted #SSH #SSL #Termius #Ubuntu #ufw #VPS
Autor: @to3k
-
🇵🇱 Nowy wpis na blogu! / 🇬🇧 New blog post!
~200GB Free Cloud for Your files [ENG 🇬🇧]
#Cloudflare #Docker #DockerHub #dockerIo #FreeTier #FreeDNS42 #HTTPS #iptables #LetSEncrypt #Linux #MariaDB #MySQL #Nextcloud #NGINXProxyManager #OpenSource #Oracle #Portainer #PuTTY #SelfHosted #SSH #SSL #Termius #Ubuntu #ufw #VPS
Autor: @to3k
https://blog.tomaszdunia.pl/200gb-free-cloud-for-your-files-eng-%f0%9f%87%ac%f0%9f%87%a7/
-
🇵🇱 Nowy wpis na blogu! / 🇬🇧 New blog post!
~200GB Free Cloud for Your files [ENG 🇬🇧]
#Cloudflare #Docker #DockerHub #dockerIo #FreeTier #FreeDNS42 #HTTPS #iptables #LetSEncrypt #Linux #MariaDB #MySQL #Nextcloud #NGINXProxyManager #OpenSource #Oracle #Portainer #PuTTY #SelfHosted #SSH #SSL #Termius #Ubuntu #ufw #VPS
Autor: @to3k
https://blog.tomaszdunia.pl/200gb-free-cloud-for-your-files-eng-%f0%9f%87%ac%f0%9f%87%a7/
-
🇵🇱 Nowy wpis na blogu! / 🇬🇧 New blog post!
Darmowa chmura ~200GB na Twoje pliki
#Cloudflare #Docker #DockerHub #dockerIo #FreeTier #FreeDNS42 #HTTPS #iptables #LetSEncrypt #Linux #MariaDB #MySQL #Nextcloud #NGINXProxyManager #OpenSource #Oracle #Portainer #PuTTY #SelfHosted #SSH #SSL #Termius #Ubuntu #ufw #VPS
Autor: @to3k
-
🇵🇱 Nowy wpis na blogu! / 🇬🇧 New blog post!
Darmowa chmura ~200GB na Twoje pliki
#Cloudflare #Docker #DockerHub #dockerIo #FreeTier #FreeDNS42 #HTTPS #iptables #LetSEncrypt #Linux #MariaDB #MySQL #Nextcloud #NGINXProxyManager #OpenSource #Oracle #Portainer #PuTTY #SelfHosted #SSH #SSL #Termius #Ubuntu #ufw #VPS
Autor: @to3k
-
A few days ago I found out that #Termius #SSH app that so many #Linux users and business customers use is actually made by russians. It's listed as a US company and doesn't even have russian translation, but have a look at their CEO's LinkedIn page: https://www.linkedin.com/in/roman-kudiyarov-0980346
Deleted my account. No way I'am giving any of my data or money to the terrorists.
#russianinvasion #devops #development #admin #security #russiaisaterroriststate
And would you trust russians your server credentials?
-
A few days ago I found out that #Termius #SSH app that so many #Linux users and business customers use is actually made by russians. It's listed as a US company and doesn't even have russian translation, but have a look at their CEO's LinkedIn page: https://www.linkedin.com/in/roman-kudiyarov-0980346
Deleted my account. No way I'am giving any of my data or money to the terrorists.
#russianinvasion #devops #development #admin #security #russiaisaterroriststate
And would you trust russians your server credentials?
-
#termius app turned on a trial subscription for me though I never asked for it. Even worse - it turned on my keys and credentials sync with their servers - never asked for that too.
Never turned a pro subscription trial on and was never asked for it.
Why are my passkeys and credentials for my servers are being sent to some shady cloud when I was never even asked if I’d want that?
#privacy #surveillance #cybersecurity #infosec #passkeys #password #cybercrime #linux #terminal #ssh
-
@codemonkeymike that's exactly why I use a plug in to mask my User Agent in any browser that I use 🤗...well, not exactly why, I don't want anything knowing exactly what system I'm running unless I trust the source and/or need to.
Still comes in handy for that kind of situation though lol. Also definitely check out Bottles for your Windows program emulation! It's how I first started running #termius SSH on my other #nixos laptop! 🙌 :windows:
-
@codemonkeymike that's exactly why I use a plug in to mask my User Agent in any browser that I use 🤗...well, not exactly why, I don't want anything knowing exactly what system I'm running unless I trust the source and/or need to.
Still comes in handy for that kind of situation though lol. Also definitely check out Bottles for your Windows program emulation! It's how I first started running #termius SSH on my other #nixos laptop! 🙌 :windows:
-
I loved #Termius for years. But almost €10/month for a terminal client was a bit too much. I switched to #WebSSH and it does all the same way. I'm pretty happy with it. €10 for lifetime is much a difference.
https://apps.apple.com/us/app/webssh-sysadmin-tools/id497714887
-
I loved #Termius for years. But almost €10/month for a terminal client was a bit too much. I switched to #WebSSH and it does all the same way. I'm pretty happy with it. €10 for lifetime is much a difference.
https://apps.apple.com/us/app/webssh-sysadmin-tools/id497714887
-
-
YunoHost – self-hosting in a friendly form [ENG 🇬🇧]
🇵🇱 Przejdź do polskiej wersji tego wpisu / Go to polish version of this post
In my previous post, I described how to get free access to a pretty good VPS – Oracle Cloud Free Tier. Today, I’ll present one of my proposals for what can be done with it, specifically showing how to turn such a server into a center for running self-hosted solutions in a simple way. We will install on it a tool, or rather a system, called YunoHost, which is used to run services and stands out for its very user-friendly graphical interface that allows even non-technical people to dive into the world of self-hosting. YunoHost is open-source software that, under a clear visual layout, has very well-written code that takes care of the proper technical configuration and security of the services that will be run on it.
EDIT: One of the readers rightly pointed out that not everyone wants to install YunoHost in the Oracle cloud and are here to learn how to do it, for example, on a machine that already has the Debian operating system installed. I recommend these people skip straight to the YunoHost Installation section.
Preparation
As I mentioned in the introduction, in the further part of this post, we will need a server in Oracle Cloud, which I wrote about in the post Free VPS with 4 OCPU, 24GB RAM and 200GB disk. Writing this tutorial, I assume that you, dear Reader, have already created an account on Oracle Cloud, launched an instance on it as I described, opened ports 80 and 443, enabled IPv6 support, and know how to connect via SSH. As always, I recommend using the convenient and free (for what we need) tool Termius.
Meeting the above conditions, we can get to work!
Installing Debian on the Oracle instance
If your created instance is 100% as I described, it means that you have installed the Ubuntu system on it. YunoHost only works on Debian, which is not on the list of available systems from Oracle. It’s not a big problem, just an additional step to convert our Ubuntu to Debian. We will use a ready-made script available on GitHub at this link.
UPDATE 2023-11-05: I have determined that it is important to add in this place that the above script will not work on every VPS! It works correctly on Oracle, but there has been a case where a remote server (not on Oracle) was completely killed using this script (the server did not recover after a restart, and it had to be rebuilt from scratch). Please keep this in mind.
Let’s connect to our VPS via SSH. Then let’s download the aforementioned script:
curl -fLO https://raw.githubusercontent.com/bohanyang/debi/master/debi.shLet’s give it permissions to execute:
chmod a+rx debi.shNow we need to perform an important step that is necessary for the proper execution of later actions. We need to share our SSH public key, which we use to log in to this server, and which will be able to be downloaded and used by the installer. We need to provide the installer with the key that will be placed on the newly installed Debian system. Without this, after completing the installation and conversion from Ubuntu to Debian, we would lose access to our server! There are many ways to do this, but I will present one that requires only an account on GitHub.
Instructions on how to add an SSH public key to your server on GitHub:
- If you don’t have an account on GitHub yet, you need to create one.
- After logging in, click on your avatar in the upper right corner and select Settings from the dropdown menu.
- In the Access section on the left, select SSH and GPG keys, and then on the right, click the green New SSH key button.
- In the window that appears, enter any name you want to identify this key in the Title field, leave Authentication Key as the Key type, and in the Key text field, enter your public SSH key.
- Important: Make sure to upload your public, NOT private key! The public key can be openly shared with anyone on the internet and poses no security risk to your server. However, the private key should be kept confidential and never shared anywhere, as it is the key that provides access to your server.
- Confirm by clicking the green Add SSH key button.
For clarity, I am presenting below the format of a sample public key:
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAAgQCvYkO7T45XKg95Jhj69xvzO+E74hdzO+KTeNLOsA2RwzAEeKkZCLGT1l3tWNZ57BuK0Umt5qbHOye/gTOAsY+kekIsyN27bzTlKx4O7GfmYIYNsByX0nj76JBCfcxazUwLCxIu6TC8Q+/1KGpwqfBV8rwLD0MEbFVm5ruSaEFDWw== blogtomaszduniaThe SSH key that has been shared will be available at:
https://github.com/<Your_GitHub_login>.keys
Now that we have shared our public SSH key, we can proceed with the installation of Debian on our server. We run the script:
sudo ./debi.sh --version 11 --authorized-keys-url https://github.com/<Your_GitHub_login>.keysNote that you need to modify the content of this command by changing the phrase <Your_GitHub_login> to the appropriate value corresponding to your GitHub account name.
Now that everything is ready, we can start the installation by restarting the machine with the following command:
sudo shutdown -r nowWe will of course be disconnected from the server. The process may take a few minutes, so be patient if you can’t connect to it immediately. In the meantime, we will also need to change the login details for SSH, as we will now be logging in to a completely different system. The username we will log in with will change. The old user was named ubuntu, and the new one is debian.
PS: If you feel the need to do so, after completing the installation, you can remove your public SSH key from GitHub.
YunoHost Installation
Once the configuration of Debian is completed, we can connect to the server. From this moment on, the instructions are universal for any device with Debian installed. First of all, update the system and its packages:
sudo apt updatesudo apt upgrade -yThen, install the necessary components:
sudo apt install htop curl unzip tmux -yNext, we will use the tmux (Terminal Multiplexer) tool, which in short allows for creating and managing multiple virtual terminals. Start a tmux session:
tmux new -s yunoWe switch to the root account:
sudo -iWe download the YunoHost installation script and start the installation:
curl https://install.yunohost.org | bashThe installation process is simple and there is practically nothing to do during it, so I won’t describe it in detail. After it is finished, we will receive a message that further configuration will take place through the browser by going to the following address:
https://<server_ip>/
This is how we do it, meaning we open the browser, enter the appropriate address, and confirm. We should see a warning that the connection may not be secure. This is a familiar behavior of the browser, which is dictated by the fact that we do not have an SSL certificate installed for this domain. At this stage, it is not important. We click through this warning, looking for a button that says I accept the risk and want to continue or something similar, the exact wording depends on the browser you are using.
We will see the YunoHost welcome screen, which congratulates us on a successful installation and encourages us to further configure it. So we click the Start button [1]. In the main domain settings, we define the alias under which this administrative panel (and user panel) will be available, so we set up the alias that will allow us to avoid using the server’s IP address as a link to our YunoHost. There are two options: you can attach your external domain (or subdomain) here or use subdomains provided by YunoHost. They may end with:
- nohost.me
- noho.st
- ynh.fr
To avoid complications, we will use the second option, so we select the I don’t own a domain… option [2], type in the chosen character string in the Domain name text field [3], and confirm with the Next button [4]. On the next page, we create an administrator account. We fill in the fields: username [5], Full name [6], and enter the password twice [7]. We confirm with the Next button [8]. I probably don’t need to remind anyone here that the password should be strong enough as it is the only protection for our administrative panel against unauthorized access, and this whole infrastructure is available on the open Internet. Finally, we will be asked to confirm with the OK button [9]. After all this, we just have to wait for the process to finish, and we will be taken to the main control panel.
It is important that from now on, you should connect to the server using the credentials provided during the administrator account creation. Therefore, do not log in as the user debian but as the newly created user and use the new password instead of the SSH key. After the first login, it is good to return to logging in using SSH keys. I described how to do it here. It is also important to disable password authentication through the YunoHost web interface by going to (Main control panel) -> Tools -> YunoHost settings -> SSH section -> Password authentication -> change it to No, not by editing the sshd_config file as described in this post. Of course, both methods will work the same, but by editing the file from the terminal, YunoHost will later report it as an error that it has detected its modification, which can cause configuration conflicts.
Basic configuration – preparing to work
After entering the main control panel of YunoHost, I recommend that you first go to System update. The system will be immediately scanned for packages that can be updated. After scanning is completed, confirm by clicking the green Update all packages button at the bottom. After starting the first services, it will also be possible to update them from this menu. After seeing two messages – All system packages are up to date! and All programs are up to date! – return to the main panel.
Next, the place we should check is Diagnostics. It is a smart YunoHost tool whose task is to scan our configuration and check if everything is set correctly. After the scan is complete, we will see four types of markers:
- Blue – informational, presenting important information but not requiring action,
- Green – confirming that a certain parameter is set correctly,
- Yellow – indicating that something is not set correctly, but it is not a critical function,
- Red – critical, indicating that something important is set incorrectly and thus something may not work properly.
It is reasonable to address the issues marked in red first. In my case, the diagnostic tool reported a problem that I have correctly opened ports 22, 80, and 443, but opening ports 25, 587, 993, 5222, and 5269 is also required for proper operation. The other red markers were in the Email section, but we will not worry about them now because they are caused by the fact that port 25 is currently closed.
We were pointed out which ports to open, so let’s do it. I have described how to do it in Oracle Cloud quite extensively here (using the example of ports 80 and 443). The only difference is that we need to make the changes only from the Oracle interface (add appropriate Ingress Rules), because YunoHost will take care of everything from the server side. Remember to also open ports in the IPv6 addressing range. After making the changes, we run the diagnostic process again.
In my case, there were still two red markers related to mail handling. Both indicate a problem with sending mail, because despite opening port 25, it seems closed, and there is also a problem with reverse DNS. This is probably due to the fact that some cloud service providers block the ability to send mail from their offered servers, and it seems that Oracle belongs to this group. It can be bypassed by using an appropriate relay, but we will not deal with it today.
Since we have the biggest problems under control, let’s move down a level and pay attention to the yellow markers. In my case, the first problem reported in yellow was the issue of enabling the backports repositories in the package manager. Backports repositories are special repositories that contain newer software versions originally developed for newer versions of Linux distributions. They are used to provide users of older Linux distributions with access to newer software without the need to update the entire operating system to a newer version. Installing software from the backports repository can lead to instability or conflicts, so YunoHost suggests that we do not use them, and we will follow this advice and disable them from the package manager list.
First of all, let’s determine which repositories we are dealing with:
sudo grep -nr backport /etc/apt/sources.list*In response to this command, I received the following result:
/etc/apt/sources.list:10:# see https://www.debian.org/doc/manuals/debian-reference/ch02.en.html#_updates_and_backports/etc/apt/sources.list:14:# bullseye-backports, previously on backports.debian.org/etc/apt/sources.list:15:deb http://deb.debian.org/debian bullseye-backports main/etc/apt/sources.list:16:deb-src http://deb.debian.org/debian bullseye-backports mainAs we can see, the keyword backport, which we are looking for, appears four times in the file /etc/apt/sources.list in lines 10, 14, 15, and 16, of which the first two are commented out, so to speak, disabled, but without removing them from the list. We need to do the same with lines 15 and 16 of this file. So let’s go to the package manager repository list file and add the # symbol where needed:
sudo nano /etc/apt/sources.listSave the file and exit it.
For security purposes, let’s scan the system again using a diagnostic tool. In my case, it looks like no more issues were found, so the system seems ready for further actions.
Base Backup
Basic configuration completed. At this stage, it’s a good practice to make a backup of a clean system, which can be easily restored if needed. I always make such a backup, and in addition to periodic backups, I also make extra copies before launching each new service (application).
Backups are performed in the (Main control panel) -> Backup -> Local archives (local) -> green button on the right +New backup. The backup can be downloaded from the graphical web interface or from the terminal, e.g., through some automation. The backups are stored on the server under the path – /home/yunohost.backup/archives/<backup_creation_date>.tar.
What’s next?
I will talk about what can be done next using YunoHost on another occasion. The purpose of this post was only to show how to install YunoHost and I think it is a good basis for future posts, in which I will describe in more detail how to run various services in such a configured environment. The list of applications (services) that can be run using YunoHost is available here and it must be admitted that it is extensive. Some of the more interesting options include:
- code-server – self-hosted version of Visual Studio Code editor,
- Discourse – discussion forum,
- Domoticz – smart home system,
- FreshRSS – RSS aggregator,
- Gitea – source code management,
- Grafana – analytical tool,
- Home Assistant – smart home system,
- n8n – automation tool,
- Mastodon – social network,
- Nextcloud – file sharing and collaboration platform,
- Nitter – alternative front-end for Twitter,
- PeerTube – self-hosted version of YouTube,
- phpMyAdmin – MySQL database management,
- Pi-hole – DNS server,
- Pixelfed – self-hosted version of Instagram,
- Roundcube – email client,
- Transmission – torrent (P2P) client,
- Vaultwarden – self-hosted version of Bitwarden password manager,
- Wallabag – read-it-later content aggregator,
- WireGuard – VPN server,
- WordPress – blogging platform,
- WriteFreely – blogging platform like WordPress but in the Fediverse.
And these are just a few quick selections because there is a lot more and I probably missed a few truly interesting and/or unknown (to me) services. There are also a lot of interesting positions on the waitlist for implementation.
If you liked this post then you can support me! 🙂
#backports #Backup #Cloud #Debian #Firewall #FreeTier #GitHub #GUI #Linux #OpenSource #Oracle #Port22 #Port25 #Port443 #Port5222 #Port5269 #Port587 #Port80 #Port993 #SelfHosted #SSH #SSHKeys #Termius #tmux #Ubuntu #VPS #YunoHost
-
YunoHost – self-hosting in a friendly form [ENG 🇬🇧]
🇵🇱 Przejdź do polskiej wersji tego wpisu / Go to polish version of this post
In my previous post, I described how to get free access to a pretty good VPS – Oracle Cloud Free Tier. Today, I’ll present one of my proposals for what can be done with it, specifically showing how to turn such a server into a center for running self-hosted solutions in a simple way. We will install on it a tool, or rather a system, called YunoHost, which is used to run services and stands out for its very user-friendly graphical interface that allows even non-technical people to dive into the world of self-hosting. YunoHost is open-source software that, under a clear visual layout, has very well-written code that takes care of the proper technical configuration and security of the services that will be run on it.
EDIT: One of the readers rightly pointed out that not everyone wants to install YunoHost in the Oracle cloud and are here to learn how to do it, for example, on a machine that already has the Debian operating system installed. I recommend these people skip straight to the YunoHost Installation section.
Preparation
As I mentioned in the introduction, in the further part of this post, we will need a server in Oracle Cloud, which I wrote about in the post Free VPS with 4 OCPU, 24GB RAM and 200GB disk. Writing this tutorial, I assume that you, dear Reader, have already created an account on Oracle Cloud, launched an instance on it as I described, opened ports 80 and 443, enabled IPv6 support, and know how to connect via SSH. As always, I recommend using the convenient and free (for what we need) tool Termius.
Meeting the above conditions, we can get to work!
Installing Debian on the Oracle instance
If your created instance is 100% as I described, it means that you have installed the Ubuntu system on it. YunoHost only works on Debian, which is not on the list of available systems from Oracle. It’s not a big problem, just an additional step to convert our Ubuntu to Debian. We will use a ready-made script available on GitHub at this link.
UPDATE 2023-11-05: I have determined that it is important to add in this place that the above script will not work on every VPS! It works correctly on Oracle, but there has been a case where a remote server (not on Oracle) was completely killed using this script (the server did not recover after a restart, and it had to be rebuilt from scratch). Please keep this in mind.
Let’s connect to our VPS via SSH. Then let’s download the aforementioned script:
curl -fLO https://raw.githubusercontent.com/bohanyang/debi/master/debi.shLet’s give it permissions to execute:
chmod a+rx debi.shNow we need to perform an important step that is necessary for the proper execution of later actions. We need to share our SSH public key, which we use to log in to this server, and which will be able to be downloaded and used by the installer. We need to provide the installer with the key that will be placed on the newly installed Debian system. Without this, after completing the installation and conversion from Ubuntu to Debian, we would lose access to our server! There are many ways to do this, but I will present one that requires only an account on GitHub.
Instructions on how to add an SSH public key to your server on GitHub:
- If you don’t have an account on GitHub yet, you need to create one.
- After logging in, click on your avatar in the upper right corner and select Settings from the dropdown menu.
- In the Access section on the left, select SSH and GPG keys, and then on the right, click the green New SSH key button.
- In the window that appears, enter any name you want to identify this key in the Title field, leave Authentication Key as the Key type, and in the Key text field, enter your public SSH key.
- Important: Make sure to upload your public, NOT private key! The public key can be openly shared with anyone on the internet and poses no security risk to your server. However, the private key should be kept confidential and never shared anywhere, as it is the key that provides access to your server.
- Confirm by clicking the green Add SSH key button.
For clarity, I am presenting below the format of a sample public key:
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAAgQCvYkO7T45XKg95Jhj69xvzO+E74hdzO+KTeNLOsA2RwzAEeKkZCLGT1l3tWNZ57BuK0Umt5qbHOye/gTOAsY+kekIsyN27bzTlKx4O7GfmYIYNsByX0nj76JBCfcxazUwLCxIu6TC8Q+/1KGpwqfBV8rwLD0MEbFVm5ruSaEFDWw== blogtomaszduniaThe SSH key that has been shared will be available at:
https://github.com/<Your_GitHub_login>.keys
Now that we have shared our public SSH key, we can proceed with the installation of Debian on our server. We run the script:
sudo ./debi.sh --version 11 --authorized-keys-url https://github.com/<Your_GitHub_login>.keysNote that you need to modify the content of this command by changing the phrase <Your_GitHub_login> to the appropriate value corresponding to your GitHub account name.
Now that everything is ready, we can start the installation by restarting the machine with the following command:
sudo shutdown -r nowWe will of course be disconnected from the server. The process may take a few minutes, so be patient if you can’t connect to it immediately. In the meantime, we will also need to change the login details for SSH, as we will now be logging in to a completely different system. The username we will log in with will change. The old user was named ubuntu, and the new one is debian.
PS: If you feel the need to do so, after completing the installation, you can remove your public SSH key from GitHub.
YunoHost Installation
Once the configuration of Debian is completed, we can connect to the server. From this moment on, the instructions are universal for any device with Debian installed. First of all, update the system and its packages:
sudo apt updatesudo apt upgrade -yThen, install the necessary components:
sudo apt install htop curl unzip tmux -yNext, we will use the tmux (Terminal Multiplexer) tool, which in short allows for creating and managing multiple virtual terminals. Start a tmux session:
tmux new -s yunoWe switch to the root account:
sudo -iWe download the YunoHost installation script and start the installation:
curl https://install.yunohost.org | bashThe installation process is simple and there is practically nothing to do during it, so I won’t describe it in detail. After it is finished, we will receive a message that further configuration will take place through the browser by going to the following address:
https://<server_ip>/
This is how we do it, meaning we open the browser, enter the appropriate address, and confirm. We should see a warning that the connection may not be secure. This is a familiar behavior of the browser, which is dictated by the fact that we do not have an SSL certificate installed for this domain. At this stage, it is not important. We click through this warning, looking for a button that says I accept the risk and want to continue or something similar, the exact wording depends on the browser you are using.
We will see the YunoHost welcome screen, which congratulates us on a successful installation and encourages us to further configure it. So we click the Start button [1]. In the main domain settings, we define the alias under which this administrative panel (and user panel) will be available, so we set up the alias that will allow us to avoid using the server’s IP address as a link to our YunoHost. There are two options: you can attach your external domain (or subdomain) here or use subdomains provided by YunoHost. They may end with:
- nohost.me
- noho.st
- ynh.fr
To avoid complications, we will use the second option, so we select the I don’t own a domain… option [2], type in the chosen character string in the Domain name text field [3], and confirm with the Next button [4]. On the next page, we create an administrator account. We fill in the fields: username [5], Full name [6], and enter the password twice [7]. We confirm with the Next button [8]. I probably don’t need to remind anyone here that the password should be strong enough as it is the only protection for our administrative panel against unauthorized access, and this whole infrastructure is available on the open Internet. Finally, we will be asked to confirm with the OK button [9]. After all this, we just have to wait for the process to finish, and we will be taken to the main control panel.
It is important that from now on, you should connect to the server using the credentials provided during the administrator account creation. Therefore, do not log in as the user debian but as the newly created user and use the new password instead of the SSH key. After the first login, it is good to return to logging in using SSH keys. I described how to do it here. It is also important to disable password authentication through the YunoHost web interface by going to (Main control panel) -> Tools -> YunoHost settings -> SSH section -> Password authentication -> change it to No, not by editing the sshd_config file as described in this post. Of course, both methods will work the same, but by editing the file from the terminal, YunoHost will later report it as an error that it has detected its modification, which can cause configuration conflicts.
Basic configuration – preparing to work
After entering the main control panel of YunoHost, I recommend that you first go to System update. The system will be immediately scanned for packages that can be updated. After scanning is completed, confirm by clicking the green Update all packages button at the bottom. After starting the first services, it will also be possible to update them from this menu. After seeing two messages – All system packages are up to date! and All programs are up to date! – return to the main panel.
Next, the place we should check is Diagnostics. It is a smart YunoHost tool whose task is to scan our configuration and check if everything is set correctly. After the scan is complete, we will see four types of markers:
- Blue – informational, presenting important information but not requiring action,
- Green – confirming that a certain parameter is set correctly,
- Yellow – indicating that something is not set correctly, but it is not a critical function,
- Red – critical, indicating that something important is set incorrectly and thus something may not work properly.
It is reasonable to address the issues marked in red first. In my case, the diagnostic tool reported a problem that I have correctly opened ports 22, 80, and 443, but opening ports 25, 587, 993, 5222, and 5269 is also required for proper operation. The other red markers were in the Email section, but we will not worry about them now because they are caused by the fact that port 25 is currently closed.
We were pointed out which ports to open, so let’s do it. I have described how to do it in Oracle Cloud quite extensively here (using the example of ports 80 and 443). The only difference is that we need to make the changes only from the Oracle interface (add appropriate Ingress Rules), because YunoHost will take care of everything from the server side. Remember to also open ports in the IPv6 addressing range. After making the changes, we run the diagnostic process again.
In my case, there were still two red markers related to mail handling. Both indicate a problem with sending mail, because despite opening port 25, it seems closed, and there is also a problem with reverse DNS. This is probably due to the fact that some cloud service providers block the ability to send mail from their offered servers, and it seems that Oracle belongs to this group. It can be bypassed by using an appropriate relay, but we will not deal with it today.
Since we have the biggest problems under control, let’s move down a level and pay attention to the yellow markers. In my case, the first problem reported in yellow was the issue of enabling the backports repositories in the package manager. Backports repositories are special repositories that contain newer software versions originally developed for newer versions of Linux distributions. They are used to provide users of older Linux distributions with access to newer software without the need to update the entire operating system to a newer version. Installing software from the backports repository can lead to instability or conflicts, so YunoHost suggests that we do not use them, and we will follow this advice and disable them from the package manager list.
First of all, let’s determine which repositories we are dealing with:
sudo grep -nr backport /etc/apt/sources.list*In response to this command, I received the following result:
/etc/apt/sources.list:10:# see https://www.debian.org/doc/manuals/debian-reference/ch02.en.html#_updates_and_backports/etc/apt/sources.list:14:# bullseye-backports, previously on backports.debian.org/etc/apt/sources.list:15:deb http://deb.debian.org/debian bullseye-backports main/etc/apt/sources.list:16:deb-src http://deb.debian.org/debian bullseye-backports mainAs we can see, the keyword backport, which we are looking for, appears four times in the file /etc/apt/sources.list in lines 10, 14, 15, and 16, of which the first two are commented out, so to speak, disabled, but without removing them from the list. We need to do the same with lines 15 and 16 of this file. So let’s go to the package manager repository list file and add the # symbol where needed:
sudo nano /etc/apt/sources.listSave the file and exit it.
For security purposes, let’s scan the system again using a diagnostic tool. In my case, it looks like no more issues were found, so the system seems ready for further actions.
Base Backup
Basic configuration completed. At this stage, it’s a good practice to make a backup of a clean system, which can be easily restored if needed. I always make such a backup, and in addition to periodic backups, I also make extra copies before launching each new service (application).
Backups are performed in the (Main control panel) -> Backup -> Local archives (local) -> green button on the right +New backup. The backup can be downloaded from the graphical web interface or from the terminal, e.g., through some automation. The backups are stored on the server under the path – /home/yunohost.backup/archives/<backup_creation_date>.tar.
What’s next?
I will talk about what can be done next using YunoHost on another occasion. The purpose of this post was only to show how to install YunoHost and I think it is a good basis for future posts, in which I will describe in more detail how to run various services in such a configured environment. The list of applications (services) that can be run using YunoHost is available here and it must be admitted that it is extensive. Some of the more interesting options include:
- code-server – self-hosted version of Visual Studio Code editor,
- Discourse – discussion forum,
- Domoticz – smart home system,
- FreshRSS – RSS aggregator,
- Gitea – source code management,
- Grafana – analytical tool,
- Home Assistant – smart home system,
- n8n – automation tool,
- Mastodon – social network,
- Nextcloud – file sharing and collaboration platform,
- Nitter – alternative front-end for Twitter,
- PeerTube – self-hosted version of YouTube,
- phpMyAdmin – MySQL database management,
- Pi-hole – DNS server,
- Pixelfed – self-hosted version of Instagram,
- Roundcube – email client,
- Transmission – torrent (P2P) client,
- Vaultwarden – self-hosted version of Bitwarden password manager,
- Wallabag – read-it-later content aggregator,
- WireGuard – VPN server,
- WordPress – blogging platform,
- WriteFreely – blogging platform like WordPress but in the Fediverse.
And these are just a few quick selections because there is a lot more and I probably missed a few truly interesting and/or unknown (to me) services. There are also a lot of interesting positions on the waitlist for implementation.
If you liked this post then you can support me! 🙂
#backports #Backup #Cloud #Debian #Firewall #FreeTier #GitHub #GUI #Linux #OpenSource #Oracle #Port22 #Port25 #Port443 #Port5222 #Port5269 #Port587 #Port80 #Port993 #SelfHosted #SSH #SSHKeys #Termius #tmux #Ubuntu #VPS #YunoHost
-
🇵🇱 Nowy wpis na blogu! / 🇬🇧 New blog post!
Docker – one server, many services [ENG 🇬🇧]
#Backup #container #Docker #DockerHub #dockerCompose #dockerIo #OpenSource #piHole #Portainer #RaspberryPi #SelfHosted #tar #TCP #Termius #UDP #VirtualMachine #VM #YAML
Autor: @[email protected]
-
🇵🇱 Nowy wpis na blogu! / 🇬🇧 New blog post!
Docker – one server, many services [ENG 🇬🇧]
#backup #container #docker #dockerhub #dockercompose #dockerio #opensource #pihole #portainer #raspberrypi #selfhosted #tar #tcp #termius #udp #virtualmachine #vm #yaml
Autor: @[email protected]
-
🇵🇱 Nowy wpis na blogu! / 🇬🇧 New blog post!
Home server – basic configuration [ENG 🇬🇧]
#bash #debian #firewall #ipadonly #linux #nano #odroid #passwd #raspberrypi #script #skrypt #ssh #sshkeys #termius #ubuntu #ufw #update #upgrade
Autor: @[email protected]
https://blog.tomaszdunia.pl/serwer-domowy-podstawowa-konfiguracja-eng/
-
🇵🇱 Nowy wpis na blogu! / 🇬🇧 New blog post!
Home server – basic configuration [ENG 🇬🇧]
#bash #debian #firewall #ipadonly #linux #nano #odroid #passwd #raspberrypi #script #skrypt #ssh #sshkeys #termius #ubuntu #ufw #update #upgrade
Autor: @[email protected]
https://blog.tomaszdunia.pl/serwer-domowy-podstawowa-konfiguracja-eng/