this post was submitted on 01 Feb 2026
51 points (100.0% liked)

Selfhosted

55365 readers
851 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

  7. No low-effort posts. This is subjective and will largely be determined by the community member reports.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

It's been a while, let's go! Any major fuckups lately or smooth sailing?

I had to change the local DNS setup yesterday. I finally installed my wife Linux Mint and wanted to set her up for Vaultwarden real quick which became an hour long debug session since apparently CNAME entries for hostnames don't work as I thought. Never came up the recent year as all my machines took it, but resolved refused to and so I eventually deleted the entries in the Pihole and created them as A records pointing to the VM with the reverse proxy, hoping I won't need to change the IP anytime soon. It's always DNS!

In other news I think I moved all my local dockered services to forgejo+komodo now and applying updates by merging renovate MRs still feels super smooth. I just updated my calibre web automated with a single click. Only exception is home assistant where I have yet to find a good split in what to throw in a docker volume and what to check in git and bindmount.

you are viewing a single comment's thread
view the rest of the comments
[–] shifting9810@lemmy.mrpostman.ch 3 points 8 hours ago (1 children)

Wait I don't understand how changing your CNAME to A records resolved your problem. Did your wife's computer simply not resolve the CNAME records?

[–] tofu@lemmy.nocturnal.garden 2 points 8 hours ago (1 children)

So I have my vms behind an opnsense with DHCP, the opnsense also creates local DNS records like vm1.opnsense. The pihole has conditional forwarding for .opnsense to the firewall, so I can resolve the domain everywhere in LAN.

I had CNAME records in the pihole for my actual domain (e.g. lemmy.nocturnal.garden) pointing to vm1.opnsense so I take a shortcut from inside the LAN, avoiding going "outside" via the public IP.

Mint/resolved resolves the .opnsense domains when I directly look them up, but for a reason I didn't fully understand, it does not work with a CNAME entry pointing to that. So I have up on the CNAME approach and created A records for each service, directly pointing to the VM's IP.

[–] zo0@programming.dev 3 points 7 hours ago (1 children)

I'm curious as why you decided to setup pihole when you already have opnsense. More so that your records are in pihole and not opnsense

[–] tofu@lemmy.nocturnal.garden 1 points 7 hours ago (1 children)

I've had pihole years before the opnsense, but also opnsense is not the main router but just sits in front of my homelab. The wifi etc is a FritzBox, which also acts as WAN for opnsense.

That way, everything still in the house still works if my homelab/opnsense is down. Pihole is on a pi in the FritzBox LAN.

[–] zo0@programming.dev 2 points 6 hours ago (1 children)

That sounds overly complicated, why not have it all on opnsense instead of 3 different devices?

Is your opnsense unstable? Otherwise regarding network availability you are just introducing unnecessary failure points the network.

[–] tofu@lemmy.nocturnal.garden 3 points 6 hours ago (1 children)

The point of the opnsense is that I can tinker with it without risking our home wifi. It needs to stay up for my wife, for our mqtt devices/home assistant etc.

I don't introduce points of failure to our home network which is the critical part. If something in the opnsense misbehaves, it only impacts my lab stuff. The FritzBox + Pihole combination has proven pretty stable over years, even though I'm considering getting a second Pihole device for high availability.

[–] zo0@programming.dev 2 points 6 hours ago (1 children)

Ah right, I thought you were doing it like this

Internet -> Fritzbox + Pihole -> Opnsense -> Home Network

It makes sense now :D

[–] tofu@lemmy.nocturnal.garden 2 points 5 hours ago

Yeah that would be a bit convoluted :D