

In general, you take the model size in billions of parameters (eg: 397B), divide it by 2 and add a bit for overhead, and that’s how much RAM/VRAM it takes to run it at a “normal” quantization level. For Qwen3.5-397B, that’s about 220 GB. Ideally that would be all VRAM for speed, but you can offload some or all of that to normal RAM on the CPU, you’ll just take a speed hit.
So for something like Qwen3.5-397B, it takes a pretty serious system, especially if you’re trying to do it all in VRAM.


Who cares if it’s exposed to the internet?
Encrypting your local traffic is still valuable to protect your systems from any bad actors on your local network (neighbor kid cracks your wifi password, some device on your network decides to start snooping on your local traffic, etc)
Many services require HTTPS with a valid cert to function correctly, eg: Bitwarden. Having a real cert for a real domain is much simpler and easier to maintain than setting up your own CA


Why are you having to update your DNS records when you add a new service? Just set up a wildcard A record to send *.myserver.com to the reverse proxy and you never have to touch it again. If your DNS doesn’t let you set wildcard A records, then switch to a better DNS.


I didn’t use to, but I do now. Debian on everything (except the Proxmox servers, but Proxmox is basically Debian too)


I’m not a computer expert or planning to be.
Then don’t use Arch. Seriously, where are you guys even finding out about Arch, much less wanting to try it? Whoever told you Arch would be a good fit, don’t listen to them on anything Linux-related again. Arch is not for beginners, and it’s not for people who don’t want to learn the ins and outs of their computer because they’re having to dig into the guts to fix it whenever an update breaks something. Arch is a fine distro for people who WANT those things, need bleeding edge hardware support, and don’t mind having to fix it whenever it breaks. It doesn’t sound like that’s at all what you’re looking for though.


I guess it depends on the containers that are being run. I have 175 containers on my systems, and between them I get somewhere around 20 updates a day. It’s simply not possible for me to read through all of those release notes and fully understand the implications of every update before implementing them.
So instead I’ve streamlined my update process to the point that any container with an available update gets a button on an OliveTin page, and clicking that button pulls the update and restarts the container. With that in place I don’t need fully autonomous updates, I can still kick them off manually without much effort, which lets me avoid updating certain “problematic” containers until after I’ve read the release notes while still blindly updating the rest of them. Versions all get logged as well, so if something does go wrong with an update (which does happen from time to time, though it’s fairly rare) I can easily roll back to the previous image and then wait for a fix before updating again.


Unfortunately that approach is simply not feasible unless you have very few containers or you make it your full time job.


self-signed won’t get rid of any warnings, it will just replace “warning this site is insecure” with “warning this site uses a certificate that can’t be validated”, no real improvement. What you need is a cert signed by an actual certificate authority. Two routes for that:
Create your own CA. This is free, but a PITA since it means you have to add this CA to every single device you want to be able to access your services. Phones, laptops, desktops, etc.
Buy a real domain, and then use it to generate real certs. You have to pay for this option ($10-20/year, so not a lot), but it gets you proper certs that will work on any device. Then you need to set up a reverse proxy (nginx proxy manager was mentioned in another post, that will work), configure it to generate a wildcard cert for your domain using DNS-01 challenge, and then apply that cert to all of your subdomains. Here’s a pretty decent video that walks you through the process: https://m.youtube.com/watch?v=TBGOJA27m_0


Just use client-side encryption, then it doesn’t matter where it goes


the network appliance is now discontinued and self-hosting the network appliance can no longer happen software-only, you have to use their “server os”, which can’t be run in a container.
Of course it can, they just don’t provide a pre-containerized version but other people do. The server software just a regular program that you can install on any Linux OS. I use the linuxserver Docker version, it’s regularly updated and works without issue. It uses about 1.2 GB of RAM, so a little heavy, but nothing crazy.
https://docs.linuxserver.io/images/docker-unifi-network-application/


You can back up ~/.ssh though, and restore it on any system.


I’m sorry to hear that. Our company recently got acquired, and every 4-6 months the new IT team tries to say, “but do you guys really need Linux? What for?”. We answer them, in depth, every time, but then it just comes back up a few months later.
I’m scared one of these days they’re just going to force the change on us, all productivity will grind to an absolute halt, deliverables will be missed, and eventually they’ll backtrack but only after it’s too late to recover the programs that got hosed in the process.
BentoPDF is for editing PDFs, Paperless is for organizing PDFs. Think GIMP vs Immich.


Do not split a RAID array across drives in separate USB enclosures.
Doing RAID on USB drives is alright, as long as they’re all in the same enclosure and use a single USB interface. If you split an array between drives with separate USB interfaces, you will face corruption and rebuild issues when one of the controllers has a hiccup or comes up slower/faster than the other, which WILL happen. If you need to run a RAID array on USB-connected drives, use a 2-bay USB-connected DAS. I’ve used the QNAP TR-002 in the past, it works fine, just set it to individual mode.
The better option since we’re just talking about a mirror, is to run on one drive primarily, and occasionally sync your data to the other for a backup.


4-bay DAS with a handful of big HDDs in RAIDZ1. Load it up, then store it in your office at work or at a friend or family member’s house. Retrieve, update, and scrub somewhere between once every few weeks to once every few months, depending on how often your critical data is changing.


From what I’ve read about the issue middle mouse click to paste overwrites normal expected behaviour in some applications
Applications can override the behavior. I have several applications I use on a daily basis that use the middle mouse for panning and they work fine. If other applications don’t, that’s their own fault. Forcing users to disable a useful feature system-wide so a couple lazy applications can get away with buggy code is not a reasonable solution.


I only use a few applications where middle click panning makes sense, and it works fine, middle click paste has no effect. If some applications don’t handle panning properly, that’s a bug in those applications. Why on earth should we disable a useful feature system-wide so a couple buggy applications can get away with shoddy code?


No, middle click paste has nothing to do with middle mouse scroll, or middle click open-in-new-window. They’re independent functions, and all 3 can work together just fine. Disabling middle click paste has absolutely no upside that I can think of. Unless they’re going to replace middle click paste with something more useful, I don’t understand this push.
Yes, you can buy and download CD quality or HD quality (up to 24-bit, 192 kHz) FLAC from their store. From their homepage, there should be a link to the download store in the header bar: https://www.qobuz.com/us-en/shop