I think you overestimate the technical capabilities of my family or their eagerness to install software. When I ran Plex, and nobody ever installed the Plex app like I recommended to them, even though it's one click away in all the app stores.
I mean, if they aren't even willing to download the one app that actually gets them the content they want to see, then *no* software will ever be something that this type of user will be interested in. Not everyone has to use an app, so why try and cater to an audience who clearly has zero interest? You're not gonna magically make it somehow even easier than "go to app store, download app" to the point that they'll use any piece of software.
No, the browser version of Plex is much simpler because you can just send a link. The receiver only needs to go through a simple "type your email and password" sign-up process, and that's it. Nothing to install, works everywhere.
Tailscale is exponentially worse, though. Not only would I have ask them to go to Jellyfin and sign up and log in, I would have to explain that they can't do that until they've installed the Tailscale app (which I have to explain because most non-techies do not know what a VPN is). Tailscale requires its own account, so they have to first sign up to that, and I have to add them as an external user first.
You do need a DNS service with API access for automatically creating/renewing the certificates for things that are only served over tailscale though, since they aren't publicly accessible for the letsencrypt servers to talk to.
Caddy is great, but doesn't solve the problem I was talking about on its own.
Caddy will get SSL certs automatically if it is exposed to the internet and DNS for that domain points to it, but if you are routing over tailscale exclusively Caddy can't automatically validate the domain names over ACME. There is a Caddy extension for doing DNS based validation, but that puts you back to needing a DNS provider with an API.
> There is a Caddy extension for doing DNS based validation, but that puts you back to needing a DNS provider with an API.
Yea, for clarity this is what i was describing. I use Porkbun's API and the Caddy instance isn't reachable from the internet, only local and over tailscale
Same, it's fantastic. As long as you don't need to support as many requests per second on your hardware as something like NGINX could, Caddy is the way to go.
Has cloudfare become any more strict with passing large amounts of video data through them? I heard they were kind of against it, but haven't enforced anything.
in interviews, they said if you give them examples of "xyz" is prohibited by applicable law, they would remove it. They would not help you spy on them probably, by backdooring their infra or sth.
That's exactly the point though: if you are choosing to platform some and not others, and some (many? most?) of the groups you are choosing to platform are violent groups, you very quickly run out of plausible deniability.
reply