— GPG Proofs —

This is an OpenPGP proof that connects my OpenPGP key to this Lemmy account. For details check out https://keyoxide.org/guides/openpgp-proofs

[ Verifying my OpenPGP key: openpgp4fpr:27265882624f80fe7deb8b2bca75b6ec61a21f8f ]

  • 0 Posts
  • 10 Comments
Joined 2 years ago
cake
Cake day: July 10th, 2023

help-circle
  • Sorry, I wasn’t clear - I use PowerDNS so that I can more easily deploy services that can be resolved by my internal networks (deployed via Kubernetes or Terraform). In my case, the secondary PowerDNS server does regular zone transfers from the primary in order to ensure it has a copy of all A, PTR, CNAME, etc records.

    But PowerDNS (and all DNS servers really), can either be authoritative resolvers or recursors. In my case, the PDNS servers are authoritative for my homelab zone/domain and they perform recursive lookups (with caching) for non-authoritative domains like google.com, infosec.pub, etc. By pointing my PDNS servers to PiHole for recursive lookups, I ensure that I have ad blocking while still allowing for my automation to handle the homelab records.


  • This is overkill.

    I have a dedicated raspberry pi for pihole, then two VMs running PowerDNS in Master/Slave mode. The PDNS servers use the Pihole as their primary recursive lookup, followed by some other Internet privacy DNS server that I can’t recall right now.

    If I need to do maintenance on the pihole, power DNS can fall back to the internet DNS server. If I need to do updates on the PowerDNS cluster, I can do it one at a time to reduce the outage window.

    EDIT: I should have phrased the first sentence: “My setup is overkill” rather than “This is overkill” - the Op is asking a very valid question and the passive phrasing of my post’s first sentence could be taken multiple ways.





  • Hosting on the public web isn’t too crazy - start with port forwarding on standard ports (443 for sale/web) and add in a dynamic DNS address.

    More than likely your residential ISP doesn’t change your IP that often, but Dynamic DNS solves that problem before it hits. I use Cloudflare, but mostly because I’m lazy and haven’t moved off of them after their most recent sketch behavior.


  • I had no idea our 40lb Boston Terrier/Beagle mix walking around was so loud for our downstairs neighbors. After they told us, we invested in some rugs to try and dampen the sound.

    Of course, they would get into screaming matches at 3am with each other until the cops were called - then the cops would ring our buzzer because they refused to answer.

    I do not miss apartment living.



  • First off, having been through IVF (unsuccessfully unfortunately) I wish you and your wife the best. I’ve found people who haven’t gone through it tend to minimize the process and it can feel isolating and frustrating. If you want someone to chat about it - dm me on Mastodon (@pezhore@infosec.exchange).

    Secondly, I wouldn’t look as much at the bodily autonomy but more at the “life begins at inception” / fetal personhood stuff. That’s the stuff that significantly impacts IVF and how non-viable eggs/zygotes are handled. Of course bodily autonomy is important for if the process works but complications occur after implantation.