<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Yay!]]></title><description><![CDATA[<p>Yay! PocketID [1] is up and running in my homelab. Runs as a quadlet service container under podman behind a nginx reverse proxy, with its own SSL cert, generated by my own CA. Passkeys in the <a href="https://social.wildeboer.net/tags/Homelab" rel="tag">#<span>Homelab</span></a>!</p><p>[1] <a href="https://pocket-id.org" rel="nofollow noopener"><span>https://</span><span>pocket-id.org</span><span></span></a> "The most user-friendly OpenID Connect Certified<img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/2122.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--tm" style="height:23px;width:auto;vertical-align:middle" title="™" alt="™" /> and OAuth 2.0 provider that lets users sign in to your applications with passkeys."</p><p><a href="https://social.wildeboer.net/tags/Selfhost" rel="tag">#<span>Selfhost</span></a> <a href="https://social.wildeboer.net/tags/SysAdminLife" rel="tag">#<span>SysAdminLife</span></a> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span></p>]]></description><link>https://forum.fedi.dk/topic/af818bda-cc32-4692-bd7f-15a004c308b8/yay</link><generator>RSS for Node</generator><lastBuildDate>Fri, 11 Sep 2026 21:16:21 GMT</lastBuildDate><atom:link href="https://forum.fedi.dk/topic/af818bda-cc32-4692-bd7f-15a004c308b8.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 04 Sep 2026 14:37:25 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Yay! on Wed, 09 Sep 2026 15:34:45 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net" rel="nofollow noopener">@<span>jwildeboer</span></a></span> <span><a href="/user/homelab%40fedigroups.social" rel="nofollow noopener">@<span>homelab</span></a></span> I also have <a href="https://fedifreu.de/tags/PocketID" rel="tag">#<span>PocketID</span></a> running in my homelab also with my own CA (#stepca) but using a <a href="https://fedifreu.de/tags/caddy" rel="tag">#<span>caddy</span></a> reverse proxy.</p><p>If you also need/want SSH key provisioning (amongst other things) I can recommend <a href="https://fedifreu.de/tags/kanidm" rel="tag">#<span>kanidm</span></a></p><p>It doesn't offer a fancy admin web interface like PocketID, though. There is a minimal one for users - for admins there is a powerful CLI. </p><p><a href="https://kanidm.github.io/" rel="nofollow noopener"><span>https://</span><span>kanidm.github.io/</span><span></span></a></p>]]></description><link>https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117241812439557675</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117241812439557675</guid><dc:creator><![CDATA[abulling@fedifreu.de]]></dc:creator><pubDate>Wed, 09 Sep 2026 15:34:45 GMT</pubDate></item><item><title><![CDATA[Reply to Yay! on Tue, 08 Sep 2026 19:24:44 GMT]]></title><description><![CDATA[<p dir="auto">@{jwildeboer@social.wildeboer.net} if we all used openid and rss/atom readers, we may have not needed protocols like diaspora or activity pub.</p>
<p dir="auto">subscribe/read by rss/atom, comment with openid.</p>
]]></description><link>https://forum.fedi.dk/post/https://xn--y9azesw6bu.xn--y9a3aq/content/a3c51187-6401-48b6-99e0-42489359e6d5/</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://xn--y9azesw6bu.xn--y9a3aq/content/a3c51187-6401-48b6-99e0-42489359e6d5/</guid><dc:creator><![CDATA[inky@xn--y9azesw6bu.xn--y9a3aq]]></dc:creator><pubDate>Tue, 08 Sep 2026 19:24:44 GMT</pubDate></item><item><title><![CDATA[Reply to Yay! on Mon, 07 Sep 2026 17:07:52 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> <br />I'm not sure im reading that right, but since I just spent a bit of time redoing DNS at home: having two DNS servers and DHCP in the mix I found out that hostnames do not resolve if I ask "the wrong one". Might just be the same thing or not at all, worth the toot. <img class="not-responsive emoji" src="https://media.hachyderm.io/custom_emojis/images/000/096/572/original/d5ea6fcd9cb88672.png" title=":mastodon_oops:" /> </p><p>So in the end I completely gave up on using hostnames, and instead im doing split horizon DNS and assigning one A/AAAA record e.g. &lt;name&gt;.host.my.tld for every metal or virtual machine. A bit more annoying to type but hey. Once I got my zones and authorative servers right all my problems went away.</p><p><span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://hachyderm.io/users/bmarinov/statuses/117230853993529208</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://hachyderm.io/users/bmarinov/statuses/117230853993529208</guid><dc:creator><![CDATA[bmarinov@hachyderm.io]]></dc:creator><pubDate>Mon, 07 Sep 2026 17:07:52 GMT</pubDate></item><item><title><![CDATA[Reply to Yay! on Sat, 05 Sep 2026 17:39:00 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> I struggled for quite a while to get it up and running on my TrueNAS, but when I finally understood the concepts and got everything right it was a great addition.</p>]]></description><link>https://forum.fedi.dk/post/https://thoresson.social/users/anders/statuses/117219651766079064</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://thoresson.social/users/anders/statuses/117219651766079064</guid><dc:creator><![CDATA[anders@thoresson.social]]></dc:creator><pubDate>Sat, 05 Sep 2026 17:39:00 GMT</pubDate></item><item><title><![CDATA[Reply to Yay! on Sat, 05 Sep 2026 15:55:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span> super ! It will have more reach</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/ramonfincken/statuses/117219245729758385</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/ramonfincken/statuses/117219245729758385</guid><dc:creator><![CDATA[ramonfincken@mastodon.social]]></dc:creator><pubDate>Sat, 05 Sep 2026 15:55:44 GMT</pubDate></item><item><title><![CDATA[Reply to Yay! on Sat, 05 Sep 2026 15:44:05 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@ramonfincken">@<span>ramonfincken</span></a></span> See the post I made immediately before: <a href="https://social.wildeboer.net/@jwildeboer/117217341135131860" rel="nofollow noopener"><span>https://</span><span>social.wildeboer.net/@jwildebo</span><span>er/117217341135131860</span></a> Now that it works and I understand why, I can start working on that blog post. I am just a slow human being and it's the weekend, so please allow me a few hours to get it all done <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://social.wildeboer.net/users/jwildeboer/statuses/117219199909129564</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://social.wildeboer.net/users/jwildeboer/statuses/117219199909129564</guid><dc:creator><![CDATA[jwildeboer@social.wildeboer.net]]></dc:creator><pubDate>Sat, 05 Sep 2026 15:44:05 GMT</pubDate></item><item><title><![CDATA[Reply to Yay! on Sat, 05 Sep 2026 15:41:47 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span> TLS by the way, but why not also blog this?</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/ramonfincken/statuses/117219190850423196</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/ramonfincken/statuses/117219190850423196</guid><dc:creator><![CDATA[ramonfincken@mastodon.social]]></dc:creator><pubDate>Sat, 05 Sep 2026 15:41:47 GMT</pubDate></item><item><title><![CDATA[Reply to Yay! on Sat, 05 Sep 2026 15:35:22 GMT]]></title><description><![CDATA[<p>And solved! After adding the correct mapping and environment variable to the immich-server quadlet file, I can now login to immich using a passkey via PocketID!</p><p><a href="https://social.wildeboer.net/tags/SSO" rel="tag">#<span>SSO</span></a> <a href="https://social.wildeboer.net/tags/SelfHost" rel="tag">#<span>SelfHost</span></a> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://social.wildeboer.net/users/jwildeboer/statuses/117219165629401783</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://social.wildeboer.net/users/jwildeboer/statuses/117219165629401783</guid><dc:creator><![CDATA[jwildeboer@social.wildeboer.net]]></dc:creator><pubDate>Sat, 05 Sep 2026 15:35:22 GMT</pubDate></item><item><title><![CDATA[Reply to Yay! on Sat, 05 Sep 2026 13:34:53 GMT]]></title><description><![CDATA[<p><span><a href="/user/bmarinov%40hachyderm.io">@<span>bmarinov</span></a></span> What still seems to fail is name resolution. My immich-server container seems unable to get to my PocketID  container using its hostname sos.homelab.jhw <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://social.wildeboer.net/users/jwildeboer/statuses/117218691848325058</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://social.wildeboer.net/users/jwildeboer/statuses/117218691848325058</guid><dc:creator><![CDATA[jwildeboer@social.wildeboer.net]]></dc:creator><pubDate>Sat, 05 Sep 2026 13:34:53 GMT</pubDate></item><item><title><![CDATA[Reply to Yay! on Sat, 05 Sep 2026 13:15:15 GMT]]></title><description><![CDATA[<p><span><a href="/user/bmarinov%40hachyderm.io">@<span>bmarinov</span></a></span> Yes, I tried that. And also making sure with "setsebool -P container_read_certs 1"  that SELinux stays happy. I also note that there seems to be a "--import-native-ca" flag in podman but I am not sure how to add that to a quadlet file. <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://social.wildeboer.net/users/jwildeboer/statuses/117218614679565012</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://social.wildeboer.net/users/jwildeboer/statuses/117218614679565012</guid><dc:creator><![CDATA[jwildeboer@social.wildeboer.net]]></dc:creator><pubDate>Sat, 05 Sep 2026 13:15:15 GMT</pubDate></item><item><title><![CDATA[Reply to Yay! on Sat, 05 Sep 2026 12:56:29 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span><br />Can you mount the host certs and shadow whatever is in the containers? Should work and reduce CA distribution to the hosts only. <br />I am just (very slowly) rolling out Lego(CLI) + a push job to move LE certs around. Once this is done I'll be dealing with vault and the same problem. </p><p>CA is kind of easy to fix on the incus system containers via terraform. Container apps I manage through lazy ansible and my plan was to do it by mounting the lab CA. On k8s we just roll out configmaps and mount them in the pods. Slightly tempted to redeploy kubernetes at home just for things like that ..<br /><span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://hachyderm.io/users/bmarinov/statuses/117218540864023266</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://hachyderm.io/users/bmarinov/statuses/117218540864023266</guid><dc:creator><![CDATA[bmarinov@hachyderm.io]]></dc:creator><pubDate>Sat, 05 Sep 2026 12:56:29 GMT</pubDate></item><item><title><![CDATA[Reply to Yay! on Sat, 05 Sep 2026 12:15:58 GMT]]></title><description><![CDATA[<p><span><a href="/user/lennybacon%40infosec.exchange">@<span>lennybacon</span></a></span> As I use my own CA, I have added my CA root to /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem on all my servers. Now I want to be sure my containers use that one, so TLS verification works. <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://social.wildeboer.net/users/jwildeboer/statuses/117218381582524697</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://social.wildeboer.net/users/jwildeboer/statuses/117218381582524697</guid><dc:creator><![CDATA[jwildeboer@social.wildeboer.net]]></dc:creator><pubDate>Sat, 05 Sep 2026 12:15:58 GMT</pubDate></item><item><title><![CDATA[Reply to Yay! on Sat, 05 Sep 2026 11:32:40 GMT]]></title><description><![CDATA[<p><span><a href="/user/jwildeboer%40social.wildeboer.net">@<span>jwildeboer</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span> What exactly do you mean by „map the host CA certificates into containers“? I don’t want to answer a question you did not ask <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":-)" alt="🙂" /></p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/lennybacon/statuses/117218211283577763</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/lennybacon/statuses/117218211283577763</guid><dc:creator><![CDATA[lennybacon@infosec.exchange]]></dc:creator><pubDate>Sat, 05 Sep 2026 11:32:40 GMT</pubDate></item><item><title><![CDATA[Reply to Yay! on Sat, 05 Sep 2026 07:51:22 GMT]]></title><description><![CDATA[<p>I know some of you are waiting for a blog post or gist on how I do it, but I first need to solve a few problems, mainly on how to get PocketID on a separate virtual network so that name resolution and connections work between the various containers on the same machine. Also: how to map the host CA certificates into the containers. If you know, how to do this with <a href="https://social.wildeboer.net/tags/podman" rel="tag">#<span>podman</span></a> please share, so that I can learn! Stay tuned <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p><p><a href="https://social.wildeboer.net/tags/PocketID" rel="tag">#<span>PocketID</span></a> <a href="https://social.wildeboer.net/tags/SSO" rel="tag">#<span>SSO</span></a> <a href="https://social.wildeboer.net/tags/SelfHost" rel="tag">#<span>SelfHost</span></a> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://social.wildeboer.net/users/jwildeboer/statuses/117217341135131860</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://social.wildeboer.net/users/jwildeboer/statuses/117217341135131860</guid><dc:creator><![CDATA[jwildeboer@social.wildeboer.net]]></dc:creator><pubDate>Sat, 05 Sep 2026 07:51:22 GMT</pubDate></item><item><title><![CDATA[Reply to Yay! on Fri, 04 Sep 2026 15:59:34 GMT]]></title><description><![CDATA[<div><span><a href="/user/jwildeboer%40social.wildeboer.net"><span>@jwildeboer</span></a></span><span> Oh wow, this looks extremely neat. Got to try this out!</span></div>]]></description><link>https://forum.fedi.dk/post/https://shrimp.vijf.life/notes/aqqpeltfx1f1ekk7</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://shrimp.vijf.life/notes/aqqpeltfx1f1ekk7</guid><dc:creator><![CDATA[sijmen@shrimp.vijf.life]]></dc:creator><pubDate>Fri, 04 Sep 2026 15:59:34 GMT</pubDate></item></channel></rss>