I just went through my setup to verify dnssec settings in unbound to troubleshoot strange latency when removing random names while browsing. Did you verify the unbound certificate file was created and had the proper permissions? There are also a couple other configuration items in unbound related to dnssec that can be tweaked to improve the implementation.
- 0 Posts
- 80 Comments
I do exactly the same thing for all three of these services! My implementation is on podman rather than docker, but basically the same deal.
Zanathos@lemmy.worldto Games@sh.itjust.works•Switch 2’s non-Nintendo games are flopping for so many reasonsEnglish5·2 days agoWatch the switch 2 announcement direct. It’s full of third party developers “happy to finally bring their games to switch” that have been released over the past 7 years on every other platform. Most of them playable on steam deck or other competing handhelds. I felt really bad for Nintendo during the direct and was a big decision point for me to not be a day 1 buyer even as an avid Nintendo fan. I will buy when the next major Zelda releases, and I will look for second hand devices before buying new.
Apologies, you mentioned specifically your network drive. Interesting article but they give several work arounds for containers that may require host mode, and it appears the non Plex pass image is one of them to resolve this specific issue.
I would go around them and go directly to the source of categorization. It looks like this is the Symantec categorization website in case it’s different from what you’re workplace provides - https://sitereview.bluecoat.com/#/
You’ve likely given it full control to whatever storage you’ve mounted in the container anyway, unless you’ve given it the :ro flag, which in that case would operate the same regardless of networking mode. If someone gains access to your internal host, you have bigger problems. Some things just play better under host mode and all bridged mode is doing is creating a virtual switch on your host and passing allowed traffic through it at a base level. The best way to protect is by running a load balancer in a DMZ and proxying all of the traffic through it which is how I have my instance running. I funnel everything external --> TCP\UDP 443 in DMZ vlan load balancer --> internal LAN IP:docker port. I run a mix of host network or bridged mode depending on the container.
Are you running in docker? Change from bridged mode to host mode on your container which should resolve this.
From a time when the jerk motion was used en mass. https://www.dailymotion.com/video/x2jvcd5
As someone else mentioned, this is only available to PlexPass users. Sorry for the confusion! I bought my lifetime sub over a decade ago at this point and forget about these inconsistencies that used to just be part of the product.
It all starts to make sense then. I need to set Jellyfin up soon. It’s only a matter of time before they come after the “Lifetime” purchasers like myself. I bought it over a decade ago at this point.
Strange that plex.tv isn’t blocked while a “personal” categorized website is. Have you looked to see what category your domain is shuffled under? You could try submitting a recategorization request to Cisco Umbrella or Fortinet databases. Requests for recategorization are free to do.
Thank you Internet stranger for reminding me of this sketch.
Under Settings > Network there is a configuration item exactly for this. I’m running host network, but you can add the docker networks here as well.
Easily ‘The Rock’. Nick Cage AND the final (non canon) 007 story all in one? YES PLEASE!
Zanathos@lemmy.worldto RetroGaming@lemmy.world•Pick-ups from the Vancouver Retro Gaming ExpoEnglish1·6 days agoLol same thought here. Was amazing for the time, but I should probably let nastalgia live on in my head and not try to pick it up again for the same reason.
Zanathos@lemmy.worldto RetroGaming@lemmy.world•Pick-ups from the Vancouver Retro Gaming ExpoEnglish4·7 days agoI have been thinking a lot of Dark Cloud lately. Was one of the first PS2 games I played after release and have great nostalgia of it. I remember the final 100 floor dungeon but only traversing maybe 40-50 floors before getting burned out and moving onto more games from the PS2 era. I think NFSU was up next in my list.
It’s sad that this statement is true to the core, but I’ve seen statements and videos of Israelites literally claiming that Palestinians are not considered human. They are considered beneath, or less than human due to their belief, and that is how they are justifying their ethnic cleansing of the area.
Awesome, thanks for explaining that. For some reason my despecialized is only 720p, so I may hunt down those 4K upscaled just to see a quality comparison on my end. I know there’s only so much that can be done, but with checking out on my part at least.
Zanathos@lemmy.worldto World News@lemmy.world•Nine women accuse Jared Leto of sexual impropriety in new reportEnglish3·13 days agoDid you even read my comment? You realize 30 Seconds to Mars is over 20 years old, right? It’s been a gradual deterioration of his character over the years.
Instead of port 53, I need to run unbound on 5335 (or another obscure port).I believe I also had to make some host level changed for DNS to operate correctly for incoming requests.
Here’s my podman run commands. These might have changed a bit with Pihole v6, but should still be ok AFAIK.
#PiHole1 Deployment/Upgrade Script podman run -d --name pihole -p 53:53/tcp -p 53:53/udp -p 8080:80/tcp --hostname pihole --cap-add=CAP_AUDIT_WRITE -e FTLCONF_REPLY_ADDR4=192.168.0.201 -e PIHOLE_DNS_=“192.168.0.201#5335;192.168.0.202#5335” -e TZ=“America/New York” -e WEBPASSWORD=" MyPassword" -v /var/pihole/pihole1:/etc/pihole -v /var/pihole/pihole1/piholedns/:/etc/dnsmasq.d --restart=unless-stopped --label=“io.containers.autoupdate=registry” docker.io/pihole/pihole:latest
#UnBound1 Deployment/Upgrade Script podman run -d --name unbound -v /var/pihole/pihole1/unbound:/opt/unbound/etc/unbound/ -v /var/pihole/pihole1/unbound/unbound.log:/var/log/unbound/unbound.log -v /var/pihole/pihole1/unbound/root.hints:/opt/unbound/etc/unbound/root.hints -v /var/pihole/pihole1/unbound/a-records.conf:/opt/unbound/etc/unbound/a-records.conf -p 5335:5335/tcp -p 5335:5335/udp --restart=unless-stopped --label=“io.containers.autoupdate=registry” docker.io/mvance/unbound:latest