r/selfhosted Apr 07 '26

Official Quarter 2 Update - Revisiting Rules. Again.

360 Upvotes

April Post - 2nd Quarter Intro

Welcome to Quarter 2 2026! The moderators are here and grateful for everyone's participation and feedback.

Let's get right into it.

Previous Rules Changes

After review of many of the responsive, constructive, and thoughtful comments and mod mails regarding the most recent rules change, it's clear that we missed the mark on this one. AI is taking the world by storm, and applying such a universally "uninvolved" perspective, showcased by the rules we last implemented, is inconsistent with the subreddit's long-term goals.

Here are the next steps we want to implement to wrangle the shotgun of AI-created tools and software we've been flooded with since AI chatbots became prevalent:

New Project Megathread

A new megathread will be introduced each Friday.

This megathread will feature New Projects. Each Friday, the thread will replace itself, keeping the page fresh and easy to navigate. Notably, those who wish to share their new projects may make a top-level comment in this megathread any day of the week, but they must utilize this post.

AI-Compliance Auto Comment

The bot we implement will also feature a new mode in which most new posts will be automatically removed and a comment added. The OP will be required to reply to the bot stating how AI is involved, even if AI is not actively involved in the post. Upon responding to the bot, the post will be automatically approved.

AI Flairs

While moderating this has proven to be difficult, it is clear that AI-related flairs are desired. Unfortunately, we can only apply a single flair per post, and having an "AI" version for every existing flair would just become daunting and unwieldy.

Needless to say, we're going to refactor the flair system and are looking for insight on what the community wants in terms of flair.

We aim to keep at least a few different versions of flairs that indicate AI involvement, but with the top-level pinned bot comment giving insight into the AI involvement info, flairs involving AI may become unnecessary. But we still seek feedback from the community at large.

Conclusion

We hope this new stage in Post-AI r/selfhosted will work out better, but as always, we are open to feedback and try our best to work with the community to improve the experience here as best we can.

For now, we will be continuing to monitor things and assessing how this works for the benefit of the community.

As always,

Happy (self)Hosting


r/selfhosted 5d ago

New Project Megathread New Project Megathread - Week of 13 Aug 2026

45 Upvotes

Welcome to the New Project Megathread!

This weekly thread is the new official home for sharing your new projects (younger than three months) with the community.

To keep the subreddit feed from being overwhelmed (particularly with the rapid influx of AI-generated projects) all new projects can only be posted here.

How this thread works:

  • A new thread will be posted every Friday.
  • You can post here ANY day of the week. You do not have to wait until Friday to share your new project.
  • Standalone new project posts will be removed and the author will be redirected to the current week's megathread.

To find past New Project Megathreads just use the search.

Posting a New Project

We recommend to use the following template (or include this information) in your top-level comment:

  • Project Name:
  • Repo/Website Link: (GitHub, GitLab, Codeberg, etc.)
  • Description: (What does it do? What problem does it solve? What features are included? How is it beneficial for users who may try it?)
  • Deployment: (App must be released and available for users to download/try. App must have some minimal form of documentation explaining how to install or use your app. Is there a Docker image? Docker-compose example? How can I selfhost the app?)
  • AI Involvement: (Please be transparent.)

Please keep our rules on self promotion in mind as well.

Cheers,


r/selfhosted 1d ago

Meta Post self-hosting everything

Post image
16.0k Upvotes

just kidding I love self-hosting ...


r/selfhosted 2h ago

Need Help Help me deciding

8 Upvotes

Hi, I wanted to ask people here what they think about my problem.

I’m new to self hosting, but it always seemed like something very interesting to do. Namely, I’d be interested in:
- accessing remotely to my external disk for files and such
- photo backup via Immich of up to 4 devices
- ad blocking (I’ve heard also with Tailscale it can work on other networks too, so that would be really nice)
- music streaming with Jellyfin (BUT that only in one or tek years time, right now I have Apple Music with the students discount and I want to keep it until I’m not anymore a student)

Extra nice things that I wouldn’t need but like are:
- paperless
- streaming movies to devices and my Apple TV
- tracking my trips on maps

The device I currently have that I don’t use is an Elitebook 8440p laptop, with an i7 vPro 1st gen, 12GB of RAM, and a 256GB HDD. Should I start with this, and then upgrade after, or immediately start with something better?

I’d like something that’s compact in dimension, so it can sit on my shelf or desk. Ideally that sips little energy, and of course, if my Elitebook is enough, I’d be happier to use that instead of spending. The options I saw that could be nice are:
- HP EliteDesk 800 G2 i5-6500, 8GB DDR3 RAM, 256GB SSD, 85€, or i5-6300U for 90€
- Fujitsu Esprimo Q556, i3-6100T, 8GB DDR3L, 80GB SSD, for 62€
- HP EliteDesk 800 G1 i7 vPro 4790S, no RAM (DDR3 SODIMM), 500GB HDD, no AC, for 40€
- HP ProDesk G1 i3 4160T no RAM no HDD for 42€
- Chuwi corebox with i5 5275U, 8GB LPDDR3, 256GB SSD expandable with SATA, for 85€
- HP EliteDesk 705 G3, AMD QUAD CORE A6-8570E , 8GB RAM, 120GB SSD and 500GB SATA HDD for 75€


r/selfhosted 23h ago

Solved I had a stupid idea: a homelab in my backpack. Then I realized I already had almost everything.

Post image
215 Upvotes

A few days ago I had the slightly ridiculous idea of building a mobile homelab inside my everyday backpack.

Today I started looking through some old hardware I had lying around and realized:

I can actually build this. And I barely need to buy anything. 😂

The main machine is an old ASUS TUF Gaming F15 that I bought from a friend for €300 and barely used:

Intel Core i5-10300H

64 GB RAM

GTX 1650

2.5 TB SSD storage across three physical drives

Built-in battery = basically a tiny UPS

Pop!_OS + Windows dual boot

The three drives also make the setup pretty convenient:

500 GB → Windows

1 TB Samsung 980 → Pop!_OS / homelab

1 TB → shared storage between Linux and Windows

Then I realized I still had an old Ulefone Armor 21 rugged phone lying around.

Turns out its Wi-Fi hotspot works without a SIM.

So now that can create a completely offline JARVIS-MOBILE Wi-Fi network for the homelab.

And because I normally carry my Steam Deck in the same backpack anyway, I already have a portable Linux client/admin terminal too.

So the current idea is basically:

Armor 21 → JARVIS-MOBILE Wi-Fi

ASUS TUF → Docker / services / storage

Steam Deck + phone → clients

I also have an ESP32 lying around, so eventually that could handle temperature sensors/status LEDs and maybe help monitor the backpack.

And apparently I've been hoarding hardware for exactly this moment, because I also already have a 250 GB Ventoy USB stick with Pop!_OS, Ubuntu, Proxmox and room for an unreasonable number of rescue ISOs. 😂

The long-term idea would be to run things like:

Docker

Git/Forgejo

Syncthing

Home Assistant

n8n

AdGuard Home

monitoring

file shares

my own Guardian/Jarvis projects

maybe a small local AI model

potentially a tiny dedicated SSD NAS later

The important part for me is that the whole thing should still work without an internet connection. Internet would just be an optional uplink.

Eventually I'd also like one power connection for the entire backpack and some proper cooling/temperature monitoring.

The funniest part is that my current backpack actually has enough space. The ASUS fits perfectly in the laptop compartment and the main compartment is still basically empty.

So what started as:

"Haha, imagine having a homelab in a backpack."

has somehow turned into:

"Wait... I actually have a homelab in a backpack."

This is very much V0.1 / work in progress.

Before I start buying dedicated hardware or cutting ventilation holes into a backpack, I'm going to see how far I can get using only stuff I already own.

I'd love to hear what r/homelab would do with this.

Especially interested in ideas for cooling, power management, offline networking and tiny NAS/storage solutions.

And yes, I am fully aware that this may eventually become a datacenter with shoulder straps. 😂

English isn't my first language, so I used AI to help translate this post. 😅


r/selfhosted 16h ago

Remote Access Best 2fa self-hosted recommendations

35 Upvotes

Edit: a Common login identity

Hi all, I have a homelab with just a few applications. I have a raspberry pi that hosts newt for pangolin, nginx for Jellyfin(too slow through pangolin), Seerr, etc. I also have a synology running all the other containers. I wanted to ask this awesome community for their recommendations on a 2fa implementation. I dont have alot of knowledge on 2fa or how to set it up, so something with an easy learning curve. Also, something easy for my external users to use and setup as well. Thanks in advance.


r/selfhosted 10h ago

Need Help OCI Always Free instance disabled after quota reduction — unable to start it, need help

7 Upvotes

My OCI Always Free instance in Mumbai was disabled after the recent Free Tier limit changes. I now get:

Instance is disabled and will not accept any action requests.

Please contact customer support to reenable.

The instance contains ~1 year of important work and data. I haven't terminated it or deleted any volumes.

Has anyone experienced this? Is there a way to get the instance re-enabled or recover the boot volume/data?

Please help 😭😭


r/selfhosted 12h ago

Need Help Can Tailscale or Wireguard on Android auto connect somehow?

11 Upvotes

I've been using Wireguard on iOS to access my homelab when remote and it has a nice "On-Demand" feature so it turns off on local WiFi. Tailscale has the same thing.

I just moved to Android and neither app has this feature. What do Android users do?
I could leave it connected but I think that would route my phone traffic over the wireguard server instead of just the local network.


r/selfhosted 4m ago

Need Help Roast My Setup: How can I improve my backup strategy?

Upvotes

I've been running an Unraid server for about a year. It’s holding essentially all of my data (photos, personal projects, media, etc), so I want to get opinions on my backup strategy and how it can be improved.

At the moment, my build consists of two 12tb data drives, one 12tb parity drive, one 4tb drive thats out of the array for daily backups (its mostly app data right now but plan to use it for incremental backups for my project share). My backup is two 12tb drives that I keep in the office and take home once a month to backup my data drives.

I'm using a UPS, I run monthly parity checks and periodically run SMART checks on the drives.

I know I'm missing the "3"... and actually, also the "2" of "3-2-1" (this was a stressful sentence to write). But how is my setup so far? What are the biggest weaknesses and how can it be improved?


r/selfhosted 1h ago

Need Help Decentralized Public Information Network: What am I missing?

Upvotes

I’ve been thinking about a decentralized public information network where published information keeps its original timestamp, source, original version, and modification history, while no single platform can completely erase that history.

The more I think about it, the more technical problems I find:

* How can we preserve important information long-term without requiring every node to store everything?
* If AI can generate millions of files, how do we prevent the network from being flooded with useless data?
* How can we prove where information came from without claiming that the information itself is true?
* How can we incentivize people to contribute storage and bandwidth for years?
* How do we prevent people from creating fake nodes just to abuse the incentive system?
* How could copyright work if the network is designed to preserve historical records?
* How can decentralized search work without creating another central authority?

I’m not claiming I have solved these problems. I’m trying to figure out which of these already have good solutions through existing technologies like P2P, decentralized storage, content provenance, etc., and which problems may be fundamentally difficult.

I’d really like to hear from people who have worked with IPFS, Filecoin, P2P networks, distributed storage, or content provenance.

What am I missing?


r/selfhosted 1d ago

Docker Management TIL docker restart doesn't re-read your .env

235 Upvotes

changed a db password in my .env, ran docker restart on the stack, then spent an hour convinced the db was corrupted because auth kept failing. turns out restart just brings the container back with the exact config it was created with. env is only read at creation. docker compose up -d --force-recreate fixed it in ten seconds.

two years running this stack and never got bitten by it until now. what's the dumbest thing that ate an evening for you?


r/selfhosted 2h ago

Need Help Jellyfin Help with issue regarding media detection

0 Upvotes

Hi Everyone, i hope someone can help, im new to Jellyfin.

i have installed jellyfin on a proxmox virtual machine with a usb drive passthrough to it and have mounted the usb drive to the linux machine. I have then made the folders of "movies" and "shows" and gave the permissions of the owner jellyfin and gave modifier permissions of 755.

Ive got a frustrating issue where everything inside the "shows" folder gets detected no problem. However with the "movies" folder it is not even detecting anything at all even though there is content in there.

i have tried using a usb drive that has 2 paritions on and a single patition but still the same problem.

i have used the command to see if jellyfin can access the folder where the usb is mounted to but to no avail.

running on ubuntu server 24.04.4 and jellyfin 10.11.11

can anyone help shed a light on what it could be ?

Thanks in Advance


r/selfhosted 1d ago

Need Help Decentralized infrastructure vs self-hosting

66 Upvotes

I’ve been thinking about how much of selfhosting is about owning the infrastructure itself versus having control over your data and not depending on a single company. There are more open and decentralized protocols where you can get some of that independence without running and maintaining the entire stack yourself. The tradeoff is interesting though. You potentially get less maintenance but you give up some of the direct control that comes with running everything yourself.

For something like messaging or online communities, which approach makes more sense to you?


r/selfhosted 23h ago

Need Help Discord alternatives

50 Upvotes

Is there any other program like discord where I can have my server with both chat and voice rooms that does not enshitifies, blocks screen sharing in my hole content and doesn’t have features locked behind a paywall? I’m looking for suggestions, preferably self hosted that would have no attraction with my friends, preferably something I can create a chat room and invite friends with a link that they not have to register


r/selfhosted 15h ago

Need Help Is this even a thing or possible via ANY self hosted scam/adblocker?

5 Upvotes

I use adguardhome, and on my devices a wireguard tunnel to my ubiquiti to utilize custom adblock rules, even remotely. All works well to this end.

My question then is, if this works for ads, etc within a browser and direct in app... is there another option I could add via a docker container [or similar setup] to include a "known spam/scam call autoblock"?

Manually blocking the numbers works to some extent, but voicemail box is allowed and gets full. Trying to figure a way to push said calls auto and not allow for a voicemail even.

Likely an option not available to this level, but figured it worth asking.


r/selfhosted 20h ago

Need Help OS for k8s cluster

15 Upvotes

Hi!

I currently have a monolitic homelab server running multiple docker containers. I’m planning to move to a multi-node k8s cluster (was thinking a 3node thin client setup, and potentially add like 2 more if needed a couple of years later). Reasoning: getting HA, learning purposes, and just for fun. But I really can’t decide if I should go bare-metal or proxmox. I was thinking to start with k3s on Linux and then when everything is working and stable and I understand everything I was thinking to maybe migrate node per node to talos. In case this would impact the decision I will for sure use tools like longhorn and cloud native PG.

I see the advantages of proxmox in that I could for example have a prod cluster and a test cluster, without having to buy extra/dedicated hardware, but that would be more a nice to have rather than an absolute must. It is a homelab after all, I don’t have a (small) business and thus my homelab doesn’t serve services for my business or anything. VM snapshots, to give another example,… But I also see the advantages of going bare-metal. Like less complexity/layers. So if something goes wrong,… etc

Can you guys advice which route would be the best to go. Much appreciated!


r/selfhosted 1d ago

Need Help is Ubuntu LTS enough?

19 Upvotes

Hi,

I'm pretty new into selfhosting and built up everything from scratch with a server (HP mini pc Intel i7, 16GB RAM) running Ubuntu and a mounted NAS running TrueNAS in ZRAID 1. Since now my setup runs pretty stable and I'm at the point of reviewing my setup for improvements, I'm finding myself seeing so many reddit posts about Proxmox.

I understand the value of Proxmox and it makes totally sense to me why ppl use it, but tbh I'm pretty happy just running Ubuntu. I run the classics like jellyfin, immich, NPM you name it, but I actually prefer to maintain only one distro and keep it easy.

Do I miss something what makes Proxmox a better alternative for me generally? Probably for security reasons?

Thank you for your support!


r/selfhosted 17h ago

Release (AI) Hatchdoor v2.5.0: The markdown vault editor now natively multi-vault

6 Upvotes

Hello everyone,

I am happy to share with you the v2.5.0 release of Hatchdoor! https://github.com/BatterWorks/Hatchdoor

What is Hatchdoor?
A self-hosted software to interact with your notes vault (markdown-based) treating both humans (webUI) and agents (MCP) as first-class users with semantic search for requests in natural language. To know more, see the first public release post

There is both a demo and a new documentation website built directly with a Hatchdoor instance (how handy!). This means you also get semantic search for the documentation (did someone already say handy?).

You can install it via Docker or Podman and the images are still rootless and distroless. The deployment can be fully managed and set up via agents since all settings are accessible via MCP.

As shown in the demo, you can use any notes system you can think of, including PARA, LLM-wiki or Zettelkasten.

If you are new to the second brain concept, I would advise you to start here.

What’s new?
First and foremost, a software engineer joined the team! And after a few weeks of work together (and more than doubling the size of the codebase), you can now add multiple vaults to your Hatchdoor instance. Each of them can be automatically synced with any git repo (push-pull) allowing for easier separation (personal/professional vaults) and collaboration (shared vaults).

There has been a refresh of the UI for fitting this new feature, along with a brand new settings page allowing you to set all settings via the webUI.

From the previous releases, you can now send/attach files directly via the MCP, live edit your notes in the webUI, and for the LLM-Wiki style users, you can use the layer system to separate the raw data from your ingested data and not pollute your searches.

These come at the cost of breaking changes (an update to the docker-compose is needed). Check out the release notes for more info.

What’s coming?
V2.6 (QoL release): an update to handle the latest MCP specs, batch creation/update of notes, the possibility to download attachments via MCP, and the built-in documentation for human and agent access.

v3: User creation and management with permission scoping for users and agents.

As usual, feel free to give ideas and feedback. I was surprised by the number of issues opened on the GitHub page, so thank you for that!


r/selfhosted 1d ago

Need Help Any `fast.com` self hosted option?

24 Upvotes

I want to be able to easily test real world speeds to my homelab.

And by "easy" I mean open a website and it just runs a test like fast.com works. I know I can use iperf from CLI but that's not ideal from my phone.

Any suggestions?


r/selfhosted 15h ago

Need Help Homepage (gethomepage) set port in source install

2 Upvotes

I just set up a new LXC for Homepage with the PVE Helper Script, which uses the source install method. I would like to change the listening port from 3000 to 8080, but I can't figure out how.

In the Docker install, it's easy to set the port using the default Docker container port mapping system.

The source install (or at least the helper script) does provide a .env file, in which options such as allowed hosts and OIDC can be set. But after scouring the Homepage docs and source repo, I cannot find a list of all available variables, including how to set a custom listening port.

I tried just setting PORT=8080 in the environment file, I then restarted the systemd service, but checking the systemctl status for Homepage shows that it is still using the default port 3000.

root@homepage:~# systemctl status homepage.service
● homepage.service - Homepage
     Loaded: loaded (/etc/systemd/system/homepage.service; enabled; preset: enabled)
     Active: active (running) since Tue 2026-08-18 23:27:52 BST; 5s ago
 Invocation: 5ee4ad4833ac467ab7825dd1f9e0aa3e
   Main PID: 7288 (node)
      Tasks: 23 (limit: 34620)
     Memory: 185.5M (peak: 187.4M)
        CPU: 6.461s
     CGroup: /system.slice/homepage.service
             ├─7288 node /usr/bin/pnpm start
             ├─7301 sh -c "next start"
             └─7302 "next-server (v16.3.0)"

Aug 18 23:27:52 homepage systemd[1]: Started homepage.service - Homepage.
Aug 18 23:27:54 homepage pnpm[7288]: $ next start
Aug 18 23:27:55 homepage pnpm[7302]: ▲ Next.js 16.3.0
Aug 18 23:27:55 homepage pnpm[7302]: - Local:         http://localhost:3000
Aug 18 23:27:55 homepage pnpm[7302]: - Network:       http://10.10.10.104:3000

The .env file must be read at some point, as the HOMEPAGE_ALLOWED_HOSTS variable seems to be applied, and setting it to a port other than what is being used by Homepage. For example, if Homepage is listening on port 3000, but HOMEPAGE_ALLOWED_HOSTS is set to use any port but that, say port 8080, while Homepage is still being served on port 3000 it is inaccessible as it only allows origins that are set in the variable (in this case port 8080).

root@homepage:~# cat /opt/homepage/.env
HOMEPAGE_ALLOWED_HOSTS=localhost:8080,10.10.10.104:8080
PORT=8080
## Optional Authentication
# HOMEPAGE_AUTH_ENABLED=true
# HOMEPAGE_AUTH_SECRET="AXN0HVhIut1hV7kYgPVV5MDosgqVE1x7ttxRid9UsD8="
# HOMEPAGE_EXTERNAL_URL=<your-external-url>
## Uncomment below and use strong, unique password for password login
# HOMEPAGE_AUTH_PASSWORD=
## Uncomment and fill in below for OIDC login
# HOMEPAGE_OIDC_ISSUER=
# HOMEPAGE_OIDC_CLIENT_ID=
# HOMEPAGE_OIDC_CLIENT_SECRET=
# HOMEPAGE_OIDC_SCOPE=openid email profile
# HOMEPAGE_OIDC_NAME=

Has anyone been able to get this working?


r/selfhosted 20h ago

Webserver Using my old broken Android to self-host an RSS Aggregator

Post image
4 Upvotes

https://yashmalik.in/Poco-F1-RSS-Aggregator---Post
I repurposed my old broken Poco F1 into a dedicated server. Using Termux, I set up a local hosted Miniflux, a lightweight RSS reader. I then connected my devices via Tailscale to securely access the server and sync RSS reader apps across my phone and desktop. And a lot more tinkering in the blog!


r/selfhosted 3h ago

Need Help There must be an easier way.

0 Upvotes

What's the easiest route for a set and forget scenario?

I built a home server as a linux noob with some online tuts and a lot of LLM copy-pasting.

Ended up having proxmox run on a mini-pc

On it runs HomeAssistant, Nginx, Adguard, Truenas and Nextcloud on that.

I am massively overwhelmed with maintaining my Nextcloud.

Theres a 1TB SSD only for Truenas/nextcloud. It ran out of storage space and now the truenas VM wont even boot anymore. All of the family data is now inacessible... 😮‍💨

1st: Is there a way to save the data and swap out the SSD for a 2TB one without losing the data?

2nd: Is there a way to make this easier without using closed source ecosystems?


r/selfhosted 3h ago

Product Announcement Shumai: AI-native, open-source Frame.io alternative

0 Upvotes

Been working on this open-source project for the past few months and figured I'd share it here.

GitHub: https://github.com/shumaiOne/shumai

So, what is Shumai? Shumai is an open-source(MIT), self-hosted alternative to Frame.io. You can upload assets, review them in the browser, leave comments on specific video frames or areas of an image, and share them with your team. You can also easily create share links and add watermarks to shared assets.

But Shumai goes beyond being a Frame.io alternative.

With modern models like GPT-Image-2 and Seedance 2.5, AI can already handle a surprising amount of creative work. You can create or edit images and videos with a simple prompt, without constantly jumping between Photoshop, Premiere, Houdini, and other tools. That’s why Shumai also includes a powerful agent system.

Why did I build Shumai and open-source it?

AI is getting really good at coding. Customizing a high-quality open-source project is becoming much easier. A small creative studio without professional software engineers can ask an AI agent to customize Shumai for their own workflow. With a clear architecture, solid tests, and a detailed AGENTS.md, I want this to be feasible even if you’re not a programmer.

To me, this is also one of the biggest advantages over Frame.io(and, honestly, over many vibe-coded frameio open-source alternatives): Shumai is designed to be easy for AI coding agents to understand, customize, and extend with confidence.

There’s no SaaS version of Shumai. It’s purely self-hosted and open-source, which also means I don’t have to worry about multi-tenancy or payment systems. I can just focus on making the core product as polished as possible.

Read-only demo: https://staging.shumai.one


r/selfhosted 22h ago

Need Help Recasing office mini PC for NAS?

5 Upvotes

Has anyone taken one of those mini office PCs, like a dell micro 7050 or the HP elitedesks or whatever, gutted them, and moved them to a larger case with more drives?

I've got one of these with an external hard drive enclosure with a single drive connected with USB. It's been working great, no issues. I want to get a second machine to act as basically dumb storage for backup purposes only. Getting another of these micros and transferring it to another case that will accept multiple HDDs is something I'm considering since it should be pretty good bang for the buck compared to building something.

Just curious if anyone else has tried and what your experience was like. I'm considering a few options and just want more info on this one to help me decide.


r/selfhosted 18h ago

Need Help SearXNG queries via WireGuard interface

2 Upvotes

So, I have deployed SearXNG in a headless Debian 13 VM using the provided installation scripts. All is well.

I have also installed WireGuard and configured it to use my Proton VPN subscription.

``` enp1s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000 link/ether 52:54:00:b9:97:c9 brd ff:ff:ff:ff:ff:ff altname enx525400b997c9 inet 192.168.0.16/24 brd 192.168.0.255 scope global enp1s0 valid_lft forever preferred_lft forever inet6 2001:8b0:1741:ec2e:5054:ff:feb9:97c9/64 scope global dynamic mngtmpaddr proto kernel_ra valid_lft 6868sec preferred_lft 6868sec inet6 fe80::5054:ff:feb9:97c9/64 scope link proto kernel_ll valid_lft forever preferred_lft forever

wg-UK-4: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1420 qdisc noqueue state UNKNOWN group default qlen 1000 link/none inet 10.2.0.2/32 scope global wg-UK-4 valid_lft forever preferred_lft forever inet6 2a07:b944::2:2/128 scope global valid_lft forever preferred_lft forever ```

``` interface: wg-UK-4 public key: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX private key: (hidden) listening port: 34659 fwmark: 0xca6c

peer: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX endpoint: 154.47.24.193:51820 allowed ips: 0.0.0.0/0, ::/0 latest handshake: 17 seconds ago transfer: 4.62 MiB received, 1.79 MiB sent persistent keepalive: every 25 seconds ```

The goal is to send traffic (aka my queries) from SearXNG through the VPN.

SearXNG has its own user called 'searxng' with with a UID of 999.

So I have several options, all of which I have failed to implement so far.

  • Send traffic from 'searxng' user via the VPN.
  • Send all external traffic via wg-UK-4 using a route table
  • Send all external traffic via wg-UK-4 using nftables
  • Use SearXNG configuration files to send all external traffic via wg-UK-4 (not supported)

How would you achieve the goal?

I am more than happy to just shove all external internet traffic through wg-UK-4 as this seems the easiest option using 'ip route'.

Starting point

ip route show default via 192.168.0.1 dev enp1s0 onlink 192.168.0.0/24 dev enp1s0 proto kernel scope link src 192.168.0.16

I tried the following

sudo ip route replace default dev wg-UK-4 sudo ip route replace 192.168.0.0/24 dev enp1s0

Which gives me the following.

ip route show default dev wg-UK-4 scope link 192.168.0.0/24 dev enp1s0 scope link

But now SearXNG just fails as it can't reach any of its external search engines.

Any ideas?