<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Self_hosting on Side Of Burritos</title>
  <link rel="alternate" href="https://staging.sideofburritos.com/tags/self_hosting/" />
  <link rel="self" href="https://staging.sideofburritos.com/tags/self_hosting/index.xml" />
  <subtitle>Recent content in Self_hosting on Side Of Burritos</subtitle>
  <id>https://staging.sideofburritos.com/tags/self_hosting/</id>
  <generator uri="http://gohugo.io" version="0.165.0">Hugo</generator>
  <language>en-us</language>
  <updated>2026-08-30T13:45:00Z</updated>
  <author>
    <name>Josh</name>
    
  </author>
  
      <entry>
        <title>Why I left Proton Mail and Tuta for Stalwart</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/why-i-left-proton-mail-and-tuta-for-stalwart/" />
        <id>https://staging.sideofburritos.com/blog/why-i-left-proton-mail-and-tuta-for-stalwart/</id>
        <published>2026-08-30T13:45:00Z</published>
        <updated>2026-08-30T13:45:00Z</updated>
        <summary type="html">I&amp;#39;ve been paying for Proton Mail for nearly a decade. Recently, I switched to Tuta to test that out as well. But I always wanted to get back to self-hosting my own email server. Around 6 months ago, I came across Stalwart, and I knew I wanted to eventually switch to it.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode125s0hbhb">🎥 


<a href="https://youtu.be/UGQVQaR6HhA" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://proton.me/" target="_blank" rel="noopener" class="text-break">https://proton.me/</a></li>
<li>


<a href="https://tuta.com/" target="_blank" rel="noopener" class="text-break">https://tuta.com/</a></li>
<li>


<a href="https://stalw.art/" target="_blank" rel="noopener" class="text-break">https://stalw.art/</a></li>
<li>


<a href="https://stalw.art/docs/email/management/masked-email/" target="_blank" rel="noopener" class="text-break">https://stalw.art/docs/email/management/masked-email/</a></li>
<li>


<a href="https://stalw.art/docs/install/upgrade/" target="_blank" rel="noopener" class="text-break">https://stalw.art/docs/install/upgrade/</a></li>
<li>


<a href="https://stalw.art/pricing/" target="_blank" rel="noopener" class="text-break">https://stalw.art/pricing/</a></li>
<li>


<a href="https://www.smtp2go.com/" target="_blank" rel="noopener" class="text-break">https://www.smtp2go.com/</a></li>
<li>


<a href="https://docs.hetzner.com/cloud/servers/faq/" target="_blank" rel="noopener" class="text-break">https://docs.hetzner.com/cloud/servers/faq/</a></li>
<li>


<a href="https://www.tb.pro/" target="_blank" rel="noopener" class="text-break">https://www.tb.pro/</a></li>
<li>


<a href="https://blog.thunderbird.net/2025/07/state-of-the-thunder-answering-community-questions/" target="_blank" rel="noopener" class="text-break">https://blog.thunderbird.net/2025/07/state-of-the-thunder-answering-community-questions/</a></li>
</ul>
<hr>


<p><details >
  <summary markdown="span">Transcript</summary>
  <h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<hr>
<p>I wanted to make a video on my updated email setup. For years I was using Proton and Tuda, but at this point I have migrated all my domains to a self-hosted instance of Stalwart.</p>
<p>I want to start off by giving some background on this decision and then some of the pros and cons of it. So while I have my complaints about both Proton and Tuda, in general I think they both provide a great service. It&rsquo;s also worth understanding my outlook on email is that it&rsquo;s not private at all. You&rsquo;re using one unique identifier to contact another unique identifier.</p>
<p>Yes, you can use PGP to encrypt the body of the message and sometimes the subject. You can also use things like aliases or simple login, which can improve your privacy a bit, but that also comes with its own complications. Like now you are stuck paying for a service since you don&rsquo;t have control over those aliases, which I got to give props to Proton on purchasing simple login. It makes it much more difficult to leave their service if you use that alias feature. So if you&hellip;</p>
<p>Even with my view on the privacy of email communication, there still is a massive benefit to using an end-to-end encrypted provider like Tuda or Proton. If you use one of the big centralized providers like Gmail or Yahoo, all your emails are stored in the clear on their servers. They can scrape those emails for information and at this point use them to train their AI models. So while that does help protect your emails that are stored in your inbox, it doesn&rsquo;t help for the emails you send to anyone using Gmail or one of those other providers, but that&rsquo;s a whole separate topic.</p>
<p>Typically when you self-host, it&rsquo;s for a privacy benefit, but with something like Stalwart, if I&rsquo;m being honest, I think it&rsquo;s actually less private to self-host my mail server. If you look at my sideofburritos.com domain right now, you&rsquo;ll see the MX record points to mail.sideofburritos.com. And if you look at that, you&rsquo;ll see it&rsquo;s tied to a Hetzner IP address, so you know the IP of the VPS that I&rsquo;m using.</p>
<p>I&rsquo;m the only one using this mail server, so all the activities&hellip; originates to me. If I&rsquo;m using something like Proton or Tuda, my activity can blend into the masses, but that&rsquo;s not happening in this case. But for me, it&rsquo;s more about control and having visibility into my email versus that small, in my opinion, privacy benefit.</p>
<p>One example of this that kind of pushed me over the edge to finally set this up. I was having some issues on Tuda receiving emails. Randomly, I had an email that was getting rejected that was previously working. I checked the rejected tab in the Tuda app, and I didn&rsquo;t see anything listed there.</p>
<p>I asked their support about it, and they said, not all rejections are visible there as it depends on some criteria. It can make a difference, for example, whether the email was rejected due to an issue with the email itself that caused the rejection, or if the sending server is blacklisted. We can always reach out to the service if there is a general issue with email communications with our server.</p>
<p>So the email that was getting dropped was an email from my membership site. I have mailgun configured as the smtp sending relay on there, so I checked the logs on there. Everything looked like it should have been delivered. Malgun showed no issues with the sending of the email, so tuta was just dropping it for some reason.</p>
<p>I never really got an answer on why those were getting silently dropped, but like I mentioned earlier, that for me that was kind of the breaking point for wanting more visibility into my email instead of this sort of black box set up. And I&rsquo;m not specifically blaming them. I can only imagine the amount of phishing and spam emails they need to filter out, especially offering free accounts. Who knows what kind of traffic they&rsquo;re getting?</p>
<p>But what I really wanted was more visibility, so if something was happening I could dig into it and figure out why. So with stalwart I finished migrating all my domains about two months ago, which I think is a decent amount of time to test it out, and in that time I haven&rsquo;t had any issues with it sending or receiving emails. I&rsquo;ve updated it a few times and all the updates have gone successfully. No issues. Let me put this in dark mode quick.</p>
<p>So some of the pros with Stalwart, since you are self-hosting it yourself, you can host as many domains as you want on there. With Proton, I think the plan I had, I was limited to three, so I needed to use aliases for some domains and shared domains for emails. I couldn&rsquo;t give every domain its own email, so that was kind of an inconvenience.</p>
<p>Stalwart also supports server-side encryption using OpenPGP. So the cool thing about this, Proton actually uses PGP for their encryption, some rendition of it. But if you use a client like Thunderbird, which is what I use because it&rsquo;s the only one I found so far that supports using PGP for opening your emails on desktop and mobile, you can actually discover the published Proton PGP keys for the emails. They publish those by default when you sign up.</p>
<p>So if I&rsquo;m emailing someone at Proton.me, I click discover in Thunderbird, it finds their published public PGP key, and now those emails are intent-encrypted. So I don&rsquo;t actually need a Proton account to email someone using Proton encrypted. So that&rsquo;s pretty great.</p>
<p>And on the topic of security, Stalwart reminds me of Graphene OS in the sense that out of the box, the default setup is pretty secure. You don&rsquo;t have to worry about being an open relay just because you set it up.</p>
<p>In the past, when I used to self-host my own email server, this was about a decade ago at this point, most of those services available at the time were configured to be open by default. So you had to make sure you locked them down, didn&rsquo;t miss anything. Otherwise, you could be an open relay and now you&rsquo;re sending spam mail because someone found your server when they were scanning the internet.</p>
<p>With Stalwart, it handles MTA-STS, TLS provisioning, DKIM key generation, rotation, and DNS publication. All of that is handled automatically if you use their DNS integration. I&rsquo;m currently using it with Cloudflare and Bunny.net. Both have been working flawlessly.</p>
<p>It also has&hellip; automatic IP banning, rate limiting, ACLs. So if someone&rsquo;s scanning your server and they trigger that rate limit, that IP is automatically blocked.</p>
<p>So this next part is going to get a bit into the weeds on how email works. But if you&rsquo;re at all curious about this, it&rsquo;s going to be worth watching. Otherwise, you can just skip ahead to the cons section of this video.</p>
<p>So I currently host my stalwart server on Hetzner. And by default, they block ports 25 and 465. This is common on VPS providers. Spammers will sign up quick and start spamming from their IP addresses using a VPS, which can cause a bunch of IPs to get block listed. So by default, they block that.</p>
<p>If you&rsquo;ve been paying for a month or a few months with a VPS using Hetzner, you can request those ports to be unblocked. I did it and it was unblocked within seconds. I think it was automated.</p>
<p>But as far as sending goes, I actually use a SMTP relay. In this case, SMTP to go. The reason for that is is while I do plan to have that Hetzner VPS long term, I don&rsquo;t want to be responsible for the IP reputation of that. If an IP gets marked as spam or block listed, now people will stop receiving your emails because of the IP reputation. It&rsquo;s not something I want to worry about.</p>
<p>If I had my own AS and my own IP range assigned to me, which would be way more long term that setup than I would send from my IP range. But in this case, I don&rsquo;t. But that would be a fun future project.</p>
<p>SMTP2Go, their free plan offers 1000 emails per month. That doesn&rsquo;t count against receiving emails. That&rsquo;s just sending. I can&rsquo;t imagine more people, at least an individual, send more than 1000 emails per month. So the free plan should work for you. That&rsquo;s what I use. So far, it&rsquo;s been great. I haven&rsquo;t encountered any sending reliability issues.</p>
<p>There&rsquo;s also a bunch of other free relays out there you can use. I think Postmark has 100 emails per month. Mail gun has a thousand they allow, so there&rsquo;s definitely options, but that&rsquo;s what I use for sending. Again, I don&rsquo;t want to worry about the IP reputation of my vps, so I use a third party for the sending.</p>
<p>But getting back to some of the other things that stalwart offers, they do have a masked email option. You&rsquo;ll notice this is marked as an enterprise feature, which I&rsquo;ll talk about in a few minutes. So I believe this is similar to something like simple login. Each mask is bound to one account and can be disabled or destroyed independently, so end users can hand out different addresses to every external service and cut them off without affecting the others.</p>
<p>I really do like simple login as a service. It&rsquo;s easy to use, provides a nice privacy benefit, but it&rsquo;s kind of like the mafia. It&rsquo;s really easy to get into it, but good luck migrating away from it. So I&rsquo;m hoping to move to something like this using a separate domain specifically for aliases, but we&rsquo;ll see how that goes.</p>
<p>One other pro regarding stalwart is mozilla who offers thunderbird. They&rsquo;re going to be offering thunder mail in the future, which is a paid hosted version for email. You can join their waitlist if you want, but they have a blog post where they mention that the only project we&rsquo;re using to help build thunderbird pro is stalwart, but we absolutely want to make sure the project gets its financial support from us to support its sustainability and well-being.</p>
<p>To me, that&rsquo;s a huge benefit to using stalwart. There&rsquo;s going to be a large company behind it supporting it financially, and I think that speaks a lot to the longevity of the project.</p>
<p>Now getting to some of the cons of stalwart. As we saw on the masked email wiki page, it&rsquo;s marked as an enterprise feature. So if we go to stalwart pricing, the minimum you can pay for is 25 mailboxes, which comes out to 60 usd per year. I actually think that&rsquo;s cheaper than my proton plan currently that I have. I pay for it. To me, that&rsquo;s more than worth it to support the open source project and get some of the other features that are behind that payment.</p>
<p>And then regarding the privacy and pgp keys, so proton and tuta, well actually I don&rsquo;t know what tuta uses exactly, but with proton they automate that entire pgp key setup. With stalwart you&rsquo;ll have to generate those keys yourself, configure them. It&rsquo;s not difficult, but it does take some time to set up.</p>
<p>And like I mentioned earlier, the only clients I found so far that support that encrypted mailbox are thunderbird. I couldn&rsquo;t find any web clients that supported it, which is unfortunate. I think I saw something that stalwart might offer a first party webmail client and hopefully it&rsquo;s supported in there. I would like to have webmail accessible. So you are limited on the clients you can use. You&rsquo;ll have to use the app thunderbird desktop and mobile if you want that.</p>
<p>Stalwart does have built-in spam spam filtering, but it&rsquo;s overly aggressive. You&hellip; there is a feature where you can submit the mail and say this is not spam to kind of teach the filter. I don&rsquo;t know if I just don&rsquo;t receive enough mail or I haven&rsquo;t done that enough, but it hasn&rsquo;t really seemed to help.</p>
<p>But I do guess it&rsquo;s better that it&rsquo;s overly aggressive versus not being good enough, so I just make it a habit to check the spam folder every so often. I have also configured a few sieve rules to allow list domains and senders to make sure those don&rsquo;t get marked as spam. So again, kind of goes back to that self-hosting setup. There might be some things you need to tune yourself.</p>
<p>It&rsquo;s also worth mentioning that stalwart is currently pre-version one. They expect the version one released in the first half of 2026. It&rsquo;s currently the second half, so I&rsquo;m assuming it&rsquo;ll be next year in 2027 because at this point there&rsquo;s not, there is no stable or finalized database schema and configuration system. So when you are doing upgrades, there might be some breaking changes you&rsquo;ll have to handle yourself since you are self-hosting.</p>
<p>If that doesn&rsquo;t sound like something you want to do, then you might want to put this off till version one. Like I said, though, I started doing this about three months ago or two months ago. All the upgrades so far, there&rsquo;s a new version every week, have been straightforward and simple. Docker pull and Docker up, and the new version was deployed.</p>
<p>So those are the cons that I found so far regarding stalwart directly. These next cons are more self-hosting in general related.</p>
<p>If something happens with your email setup, there&rsquo;s no status page to check. There&rsquo;s no email support to contact. It&rsquo;s on you to resolve. If you&rsquo;re not receiving emails, you&rsquo;re wondering what&rsquo;s going on. Again, that&rsquo;s on you. You need to check the logs, see what&rsquo;s going on. Did you hit your limit in your SMTP relay? Did your ports somehow get blocked? Did Docker stop running? Did the process crash?</p>
<p>In my experience self-hosting, these things aren&rsquo;t common, but when they do happen, they can take some time to figure out. I really do think that self-hosting is easy, especially with docker. A couple commands, you can have a service running setup and you can start using it.</p>
<p>The part that&rsquo;s not easy, which I think a lot of people don&rsquo;t think about when they&rsquo;re paying for a cloud service, is consistent reliable backups. It&rsquo;s easy to set a service up, but if that hard drive dies, you know, even if you&rsquo;re using a shared hosting provider, they do have hardware issues. If that server dies and they just give you a new one with a fresh installation of your operating system, can you restore your backups? Do your backups run reliably every day? Do you monitor those backups? Do you check them for freshness? Do you document your restore procedure?</p>
<p>Different things like that that people don&rsquo;t talk about enough because they&rsquo;re not that interesting to share because you only need them in a worst case scenario. But if you are self-hosting, you really need to think about those and take that into consideration before you decide to dive in head first.</p>
<p>So is the juice worth the squeeze? I don&rsquo;t know. That&rsquo;s up to you. To me it is. I also just enjoy doing this kind of stuff.</p>
<p>If you&rsquo;re going to be annoyed when you get an alert on the weekend in the middle of the day when you&rsquo;re hanging out with some friends and you&rsquo;re now no longer receiving email, then doing something like this probably isn&rsquo;t for you. Stick to a managed provider.</p>
<p>But if you&rsquo;re at all interested in self-hosting email, I definitely recommend checking out stalwart. I&rsquo;m also thinking about doing a full setup video with another domain that I have that I don&rsquo;t currently have set up to receive email. If you think that&rsquo;d be useful, let me know down in the comments or in the comments on my blog, and if there&rsquo;s enough of those I&rsquo;ll try to make that video happen.</p>
<p>But that&rsquo;s all I got for this video. I hope you have a great rest of your day and I&rsquo;ll see you next time.</p>

</details></p>

]]></content>
      </entry>
      <entry>
        <title>How to Install Home Assistant on Raspberry Pi (Connect ZBT-2 Tutorial)</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/how-to-install-home-assistant-on-raspberry-pi/" />
        <id>https://staging.sideofburritos.com/blog/how-to-install-home-assistant-on-raspberry-pi/</id>
        <published>2026-01-09T15:00:00Z</published>
        <updated>2026-01-09T15:00:00Z</updated>
        <summary type="html">I’ve avoided anything “smart home” related for a while. But eventually, my research led me to Home Assistant, so here we are.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode84s0hbhb">🎥 


<a href="https://youtu.be/N8n3VwpyFbk" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://www.home-assistant.io/" target="_blank" rel="noopener" class="text-break">https://www.home-assistant.io/</a> - Home Assistant Website</li>
<li>


<a href="https://www.home-assistant.io/connect/zwa-2/" target="_blank" rel="noopener" class="text-break">https://www.home-assistant.io/connect/zwa-2/</a> - Home Assistant Connect ZWA-2</li>
<li>


<a href="https://www.home-assistant.io/green/" target="_blank" rel="noopener" class="text-break">https://www.home-assistant.io/green/</a> - Home Assistant Green</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So, last month I bought a lamp. It has a switch on it. Turns on and off. I did put a dimmable bulb in it, but the switch does not support dimming. So, unfortunately, it&rsquo;s either off or full brightness. I did start looking into some options on how to make it dimmable without actually changing the switch on the lamp. I found some plugs that you can manually adjust that essentially limit the current going to the actual bulb or to the outlet, which then makes the lamp dimmer. If you turn it up, it makes it brighter. But fiddling around with something like that and then having it statically set did not seem ideal.</p>
<p>Up until this point, I don&rsquo;t have any home automation. I don&rsquo;t have any smart bulbs. I don&rsquo;t have any smart thermostats. But after I started looking into my options with this lamp, it started leading me towards home automation options. Given all the other content on my channel, I obviously don&rsquo;t want to use something that&rsquo;s cloud-controlled by someone else. I wanted something I could self-host, control on my own, yet could still have full automation.</p>
<p>And then the more I looked into it, the more I thought it&rsquo;d be nice to have something where the lights could start turning on at dusk. They could then ramp up in brightness as the night went on. Once it started getting towards the time I wanted to go to sleep, the lights would start to dim down until they turned off. I also thought it&rsquo;d be nice to have something where it could turn on and off on a schedule when I am not home or on vacation. Whether or not this actually would deter a potential robber into thinking someone&rsquo;s home, I don&rsquo;t know, but it seemed like a nice feature to have.</p>
<p>And so what I settled on was using Home Assistant with Z-Wave. Z-Wave is a wireless protocol that lets you control different smart devices if they support Z-Wave. There&rsquo;s alternatives like Zigbee, which I also looked into. But what I found is that Z-Wave has been around for a while, and they seem to have better security, which was extremely important to me. Regardless of the security, though, I&rsquo;ll be placing it on a separate VLAN on my switch. This will let me keep an eye just on the Home Assistant traffic and the Z-Wave traffic, along with keeping it separate from my actual LAN traffic.</p>
<p>But what this boils down to is I purchased a lamp, and that gave me an excuse to now look at some more self-hosting home automation that I can explore. And this is where we&rsquo;re at. But before we get into it, I do want to mention that I truly believe that, given enough time, anyone can pretty much figure out anything. But if you are someone that prefers to spend money in order to save time, I do offer paid consultations. You can head on over to sideburritos.com and then click on the Schedule Consultation button. Whether that&rsquo;s GrapheneOS, or you&rsquo;re looking to get into self-hosting, or maybe you&rsquo;re a business looking to improve your overall security and privacy, I&rsquo;m happy to help. So again, sideburritos.com, and then click on the Schedule Consultation button.</p>
<p>So, I don&rsquo;t have an actual top-down camera setup, but I did find out I could clip a tripod to my monitor stand, and it looks pretty good. So, let&rsquo;s see how this goes.</p>
<p>So, here&rsquo;s the hardware I mentioned. It&rsquo;s the Home Assistant Connect ZWA-2. Thank you, Jeff Geerling, for posting a video on this. It kind of led me down that path instead of going with a third-party option.</p>
<p>So, inside the box, it&rsquo;s pretty straightforward. We have the base. On the back, there&rsquo;s a single USB-C port along with a reset button. We then have the rather large antenna, a small instruction booklet, and then lastly, a USB-A to USB-C cable, which is cloth braided. Pretty nice, and that&rsquo;s convenient since Raspberry Pis all have USB-A on them, and that&rsquo;s what I&rsquo;ll be using.</p>
<p>And then, speaking of Raspberry Pis, I have this one here. This is just a standard, I think it&rsquo;s a 4B. It has a janky heatsink on the bottom, along with a PoE hat on it. If you&rsquo;ve never heard of the PoE hat before for the Raspberry Pi, basically what this allows is you install this on the top of the board, and now that turns this Ethernet port into a port that accepts PoE. So that means you no longer need to use a wall adapter to power the Raspberry Pi. As long as you have a PoE switch, you plug in the Ethernet cable that provides network connectivity along with power, and you can save yourself a cable.</p>
<p>For the actual operating system, I have a microSD card here. I&rsquo;d prefer to use one of the hard drives I have lying around, but I don&rsquo;t have an external hard drive enclosure. So, SD card it is.</p>
<p>As far as the smart home devices that I&rsquo;ll be using with this, I have two smart plugs I purchased. This is a Zooz smart plug, and this is a Minoston smart plug. The reason I got two different ones is the Zooz comes highly recommended. Thanks again, Jeff Geerling, for that one. But this only supports on-and-off functionality, which is not what I&rsquo;m looking for with my lamp. But this one, the Minoston, does support dimming, so I&rsquo;ll be using this for my lamp. This one I&rsquo;ll be using with my Christmas tree for testing. But long-term, I do have a device that I want to be able to turn on and off remotely, and that&rsquo;s what I&rsquo;ll be using this for.</p>
<p>On a side note, in case you&rsquo;re wondering where the Qubes OS video is, that&rsquo;ll be coming shortly. I had to purchase an adapter so I could record the Qubes OS screen from my current laptop. I tried to film it with a camera. It looked terrible. I wouldn&rsquo;t want to watch a video like that, so I&rsquo;m not going to make you watch one like that either. But that one will be out shortly.</p>
<p>So, with the SD card installed, let&rsquo;s go back to Home Assistant&rsquo;s website. Get started. Home Assistant does have official hardware, which is pretty cool. I did not purchase one of these. I&rsquo;m going to be using the Raspberry Pi, but if you don&rsquo;t feel comfortable using a Raspberry Pi, they do have some plug-and-play options.</p>
<p>Let&rsquo;s get started with the Raspberry Pi. This is a Pi 4, so it should work. MicroSD card. You do need an Ethernet cable required for installation. After that, it can work with Wi-Fi. I will be keeping this on Ethernet, though, plugged into my PoE switch.</p>
<p>First step: download and install Raspberry Pi Imager. Just had to update Raspberry Pi Imager. Quick, let&rsquo;s go back to the guide. So, I have a Raspberry Pi 4. Next. What OS do I want to use? Looks like other specific-purpose OS. Looks like they actually have Home Assistant in here according to the guide. Home automation. There&rsquo;s Home Assistant. We&rsquo;re going with Home Assistant OS. This one. This is the actual kit that you can buy from Home Assistant, but we&rsquo;re using the Raspberry Pi, so it&rsquo;s going to be this one.</p>
<p>Storage. That&rsquo;s the one I plugged into my computer. Next. Writing. Right. You&rsquo;re about to erase. I understand.</p>
<p>While that finishes up, let&rsquo;s check on the next step. Eject the SD card and then start up your Raspberry Pi. I think this is almost done verifying. Currently testing out OBS to record these videos, so it seems a little bit easier to see the windows. Looks good. Finish.</p>
<p>So now, for this setup, since my switch is not over here, I&rsquo;ll show you what I&rsquo;ll be doing. I&rsquo;m going to insert the SD card into the Raspberry Pi. That&rsquo;s good.</p>
<p>Next, we have the antenna. Get the base out of here. Grab the actual antenna. Get the USB cable.</p>
<p>So what I&rsquo;ll be doing is plugging an Ethernet cable into here. This USB cable goes into one of the ports. The base gets the antenna screwed into it like so. Pretty straightforward. And then the USB-C cable gets plugged into the back of the antenna. So that&rsquo;s it. I&rsquo;m going to plug this into my switch now, and I&rsquo;ll be back.</p>
<p>So, I just plugged that into my switch. Let&rsquo;s hope it&rsquo;s booting up and getting an IP address from DHCP. I&rsquo;ll log into my switch to see what IP address it got. So, it&rsquo;s been a couple of minutes, and it looks like the Raspberry Pi did get an IP address. So, I guess it&rsquo;s started up correctly.</p>
<p>Next is to go to the IP address, port 8123, in your browser. So let&rsquo;s go there. Continue to site. Cool. Preparing Home Assistant. This may take 20 minutes or more. Interesting. So I&rsquo;m going to make you watch every minute of this. Just kidding. I&rsquo;ll see you shortly.</p>
<p>So, we are back. That took about five minutes, I&rsquo;d say. Are you ready to awaken your home, reclaim your privacy, and join a worldwide community of tinkerers? Absolutely, I am.</p>
<p>Looks like you can upload a backup or restore from their cloud. I&rsquo;m guessing they offer that as a service. So, I&rsquo;ll create my smart home. Time to create a user. I&rsquo;m going to blur out this screen because you don&rsquo;t need to see me doing this.</p>
<p>Looks like you can select your home location. I&rsquo;m going to skip this one for now. The country you&rsquo;re in. Share anonymized information from your installation. No, no, no, no. It&rsquo;s nice that it&rsquo;s opt-in, not opt-out, so I&rsquo;ll give them credit on that one.</p>
<p>Found compatible devices on your local network. Z-Wave. Cool. Bluetooth. I&rsquo;m assuming Z-Wave uses that to pair with.</p>
<p>Finish.</p>
<p>My user, Josh. Let&rsquo;s see. Settings. Devices and Services. Home Assistant. Connect ZWA-2. That&rsquo;s it. Looks like it&rsquo;s discovered. I do want to add it. In a few steps, we&rsquo;re going to set up your home adapter. Home Assistant can automatically install and configure the recommended Z-Wave setup. Let&rsquo;s customize it, because why not.</p>
<p>Is your network new, or does it already exist? It is new. Created configuration for Z-Wave JS. Finish.</p>
<p>Failed setup. Failed to connect. Cannot connect to blah blah blah. Okay. Don&rsquo;t know why that is.</p>
<p>I just reloaded it, and it did find it. So I guess it did work. Or maybe it took a little bit too long to start up, so it couldn&rsquo;t see it.</p>
<p>LED. If I toggle it, it does turn off. Okay. I will say the device does look pretty cool. I&rsquo;ll try and include a picture here in the video. It kind of looks like a small airplane tower.</p>
<p>Firmware update available. Okay, let&rsquo;s just update it because we&rsquo;re here. I&rsquo;m always a big fan of a changelog, so it&rsquo;s nice they include that.</p>
<p>So, I didn&rsquo;t see the actual antenna flash at all, but I just noticed that the installed version and latest version now match. So I&rsquo;m assuming it&rsquo;s good now. Refresh the page. Up to date. Z-Wave info. Okay.</p>
<p>I&rsquo;m going to look more into this after. I&rsquo;m not going to do it right now, but I do want to try and connect one of the outlets that I purchased.</p>
<p>So, overview map. Not in Amsterdam, but that&rsquo;s the default location. Energy. Okay. Has to-do list overview. Media. Guessing what it can save from devices, or if you have cameras hooked up, which I might try and pair some home security cameras I have to this.</p>
<p>Okay, so just looking so far, I will say it&rsquo;s a little confusing at first. Okay, here&rsquo;s the plus button. Want to add a device. Add a Z-Wave device.</p>
<p>Only use your camera to scan QR codes when using a secure connection with the app or over HTTPS. Okay. Well, I&rsquo;m not going to scan with my camera, so I guess I&rsquo;ll use the QR code manually.</p>
<p>Let&rsquo;s get back to the top-down view quick. Every smart device does have a QR code on it. Let me not show these on camera since that would be a security issue. Actually, this one, yeah, on the side here, we do have a QR code, which I&rsquo;m not going to show you.</p>
<p>But here&rsquo;s the plug. I think this is a physical power switch. So it&rsquo;s nice that even though it&rsquo;s a smart device, you can still use it as a dumb device, which is nice in case my home hosting setup goes down and I can still turn a lamp on and off.</p>
<p>Okay, looks like I need to scan it with my phone so I can get the QR code, since the QR code does not list it. Okay, so I scanned it with my phone. I think this is about 100 characters. I&rsquo;m just going to send it to myself on Signal quick so I can copy and paste it, because I&rsquo;m not typing that in.</p>
<p>So I guess long-term, it would be good to put an HTTPS proxy in front of this or use the app so that you don&rsquo;t need to do this manually every time you want to add a new device. Either way, it&rsquo;s always a good idea to use HTTPS. So I will be adding that later. I run Nginx Proxy Manager on my home hosting or self-hosting setup, so I&rsquo;ll just add it to that.</p>
<p>So here&rsquo;s the code. It&rsquo;s going to be blurred out on the screen, but it is massive. Next. Indoor smart plug. I guess it detects that from the code. Let me plug this in, though, so it can be on.</p>
<p>So I just plugged in the smart plug. I heard a relay click inside of it. This is a long-range device area. I don&rsquo;t have any yet. I guess there&rsquo;s some default ones. Just put living room. Add device.</p>
<p>If your device is already turned on, you might need to turn it off and on again. Okay, it&rsquo;s searching for the device. I guess I&rsquo;ll try turning it on and off.</p>
<p>Just turned it on and off. It should be scanning for it. Looks like it did find it. This device is currently being interviewed. It may not be fully operational. Okay, definitely got some stuff to learn about Z-Wave and Home Assistant. This is cool.</p>
<p>The plug looks like it gives some sensor details about it. Let me plug in my phone to this. So, I wish I had something better to visibly show that the outlet is on or off based on the dashboard here, but here&rsquo;s a phone. I have a power brick plugged into the outlet and then plugged into a USB-C cable. So let&rsquo;s plug it into the phone. Looks correct. It should be off.</p>
<p>And I&rsquo;m guessing controls. If I toggle this, then the phone should turn on.</p>
<p>Heard the relay click, and the phone is now booting up. So that did work. We can see some stats here. Electrical consumption: 0.4 amps, 2 watts. The phone is currently charging at 9 watts. Okay, looks like it is working.</p>
<p>And if I turn this off—let me just—okay, there it is. Heard the relay click again in the outlet, and it&rsquo;s no longer charging.</p>
<p>So one thing I was worried about is the latency from when I toggle something to when the actual device reacts to that action. It seems almost instant. If I click it, I feel like I&rsquo;m hearing, in real time, the outlet going on and off. So it does seem near instant that this is working.</p>
<p>I&rsquo;ve seen some complaints—maybe it&rsquo;s some other protocols or other devices—where there is some latency, which can be kind of annoying because you&rsquo;re wondering, did the actual action work? Is your setup not working? Is the device not working? But with this being instant, you can tell pretty quickly.</p>
<p>So overall, I think that setup was pretty straightforward. It&rsquo;s always pretty iffy when you&rsquo;re dealing with hardware and software how things are going to work, but it seems like the Home Assistant antenna worked very well with Home Assistant, as I would hope.</p>
<p>So I&rsquo;m going to go and play with this some more, work on some configurations, and I&rsquo;ll come back in the future with another video on what I have set up and some good things and maybe bad things I find out about it.</p>
<p>So if you do want to set this up yourself, I do think it was pretty straightforward. Again, Home Assistant does have some first-party hardware that you can use. So if you&rsquo;re looking for something that might be a little bit better than a Raspberry Pi or a little more straightforward, then that is an option.</p>
<p>So if you have any questions or comments, or any tips on using Home Assistant or some cool things that you set up, feel free to leave those down below, and I&rsquo;ll see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>Some thoughts on switching to KeePass</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/i-switched-to-keepass/" />
        <id>https://staging.sideofburritos.com/blog/i-switched-to-keepass/</id>
        <published>2025-05-31T10:00:00Z</published>
        <updated>2025-06-01T10:00:00Z</updated>
        <summary type="html">I switched to KeePass</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode93s0hbhb">🎥 


<a href="https://youtu.be/sRi66okPdFM" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://community.bitwarden.com/t/allow-attachments-to-be-exported-when-using-export-data/835/1" target="_blank" rel="noopener" class="text-break">https://community.bitwarden.com/t/allow-attachments-to-be-exported-when-using-export-data/835/1</a> - Allow Attachments to be exported when using Export Data Feature Request</li>
<li>


<a href="https://bitwarden.com/blog/upload-store-and-now-export-attached-files-in-your-secure-bitwarden-vault/" target="_blank" rel="noopener" class="text-break">https://bitwarden.com/blog/upload-store-and-now-export-attached-files-in-your-secure-bitwarden-vault/</a> - Bitwarden blog post announcing attachments export</li>
<li>


<a href="https://grapheneos.social/@GrapheneOS/114549099206535021" target="_blank" rel="noopener" class="text-break">https://grapheneos.social/@GrapheneOS/114549099206535021</a> - GrapheneOS post mentioned in intro</li>
<li>


<a href="https://keepassxc.org/" target="_blank" rel="noopener" class="text-break">https://keepassxc.org/</a> - KeePassXC (Desktop)</li>
<li>


<a href="https://www.keepassdx.com/" target="_blank" rel="noopener" class="text-break">https://www.keepassdx.com/</a> - KeePassDC (Android)</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>Just a few quick updates before we get into it.</p>
<p>I send out a monthly email newsletter — if you want to sign up for that, you can go to sidecideros.com, throw your email in the box, and hit subscribe. While you&rsquo;re there, you can also check out my podcast, which is called In the Shell. You can find out where to listen at intheshellpodcast.com.</p>
<p>Back on sidecideros.com, I added a small phone icon at the top. If you click on it, it takes you to a page with an up-to-date list of all the apps I use on my Google Pixel running GrapheneOS. So if you&rsquo;re just getting started or you&rsquo;re curious about what I use, you can check that out and use it as a reference.</p>
<p>About five months ago, I published a video called The Big Problem with Bitwarden Backups. TL;DR — I was migrating my self-hosted Bitwarden instance to a new server. I set it up, imported my backup (exported using the web interface), and everything seemed fine. But shortly after, I needed an attachment from my vault — I think it was a PDF — and realized that none of the attachments had been imported.</p>
<p>After digging into it and finding a forum post, I learned that Bitwarden backups didn’t export attachments at the time. Fast forward to now, and it looks like they’ve fixed that — they even published a blog post about it. Attachments are now included in backups, which is great!</p>
<p>That said, I still don’t use Bitwarden. As Bush once said (sort of):</p>
<p>“Fool me once… shame on — shame on you. Fool me… we can&rsquo;t get fooled again.”</p>
<p>(Yes, that was a joke.)</p>
<p>Even so, I still recommend Bitwarden for 99% of people. I think it’s the best option if you need a cloud-hosted, centralized vault — especially if you’re managing passwords for multiple people in your family and don’t want to be solely responsible for your data.</p>
<p>As for me, I’ve reached a point in my self-hosting journey where I’m trying to simplify my setup. Bitwarden running in Docker containers is fairly straightforward, but there were some backend elements I wasn’t entirely comfortable with. A few times during updates, the service wouldn&rsquo;t come back up right away. I had to troubleshoot, figure out what changed, make updates, and get it running again.</p>
<p>For something like a password manager, that kind of downtime can be stressful. That’s why I moved to KeePass.</p>
<p>One of the benefits of KeePass is that your vault is just a single file. That means you can back it up by literally copying it to a flash drive. If you ever need to restore it, you just open the file with KeePass — no need to set up a new instance, import a backup, and go through the login process. You can access your vault from any computer or phone with the app installed. That simple file structure is a big plus in my book.</p>
<p>Quick note before I continue: If you haven’t self-hosted anything before, your password manager shouldn’t be the first thing you self-host. Start with something less critical, get your backup plan in place, and then maybe consider self-hosting your password manager.</p>
<p>So back to KeePass — it’s simple. I use KeePassXC on desktop and KeePassDX on Android. One thing to keep in mind is that unlike Bitwarden (which provides a complete ecosystem from the same company), KeePass is more fragmented. But once everything is set up, you don’t really have to think about it.</p>
<p>The interface is straightforward. I really like the password generator — you can choose between passwords and passphrases, and it includes a default word list (you can add more if you want). I do wish it had a username generator, though — that’s one feature it lacks.</p>
<p>Creating new entries is simple. You can attach files, and since everything is stored in that one file, you don’t have to worry about exporting attachments separately.</p>
<p>KeePass also supports MFA. I use YubiKeys for this — specifically the 5C model. Every time you make a change, KeePass prompts you to touch the YubiKey for confirmation. I also have a Nano YubiKey that I leave plugged into my computer, which makes it more convenient. This adds a layer of protection against automated attacks since physical touch is required for authentication.</p>
<p>There’s a browser plugin for KeePass, but I found it a bit clunky and stopped using it. Instead, KeePass has a feature called Auto-Type. You select an entry, click Perform Auto-Type, and it types your credentials into the active window. I don’t personally use it — I just copy and paste.</p>
<p>On my phone, I also avoid keyboard integration — I just copy and paste there as well, and it works fine for me.</p>
<p>You might be wondering how I sync across devices now that I’m not using a centralized setup. I do 95% of my work on my laptop, so I only make changes there. Then every few days, I manually transfer the updated password database to my phone and tablet using LocalSend.</p>
<p>You could sync your KeePass database to a cloud service and install the client on each device — I actually have mine synced to Seafile, which I also self-host — but I still prefer the manual method. It keeps things simple, and I haven’t had any issues with it.</p>
<p>So while I still think Bitwarden is a fantastic choice for most people, if you&rsquo;re into self-hosting, KeePass is absolutely worth checking out.</p>
<p>If you have any questions or comments, feel free to leave them down below — and I’ll see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>The Big Problem with Bitwarden Backups</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/problems-with-bitwarden-backups/" />
        <id>https://staging.sideofburritos.com/blog/problems-with-bitwarden-backups/</id>
        <published>2025-01-11T10:00:00Z</published>
        <updated>2025-01-11T10:00:00Z</updated>
        <summary type="html">Bitwarden is a great password manager, but there’s a critical issue with backups that could catch you off guard.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode109s0hbhb">🎥 


<a href="https://youtu.be/OI_mElYmQ7w" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://bitwarden.com/help/export-your-data/" target="_blank" rel="noopener" class="text-break">https://bitwarden.com/help/export-your-data/</a> - Bitwarden Export Vault Data Help Page</li>
<li>


<a href="https://community.bitwarden.com/t/allow-attachments-to-be-exported-when-using-export-data/835/1" target="_blank" rel="noopener" class="text-break">https://community.bitwarden.com/t/allow-attachments-to-be-exported-when-using-export-data/835/1</a> - Allow Attachments to be exported when using Export Data Feature Request</li>
<li>


<a href="https://news.ycombinator.com/item?id=31702594" target="_blank" rel="noopener" class="text-break">https://news.ycombinator.com/item?id=31702594</a> - Hacker News post about Bitwarden backups</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>Today, I want to talk about Bitwarden. Let me start by saying that I think it&rsquo;s a great password manager and a solid option for many people. I&rsquo;ve been self-hosting it for the past two years, but there&rsquo;s one major feature missing that could potentially cause problems for users, just as it did for me.</p>
<p>For the past two years, I&rsquo;ve been hosting Bitwarden on a Raspberry Pi, along with a few other containers. Recently, I wanted to simplify and consolidate my setup, so I moved Bitwarden, along with the other containers, to an existing Mini PC I had. I got the containers up and running on the new host, and the next step was to restore the backups I had taken. Everything went smoothly—backups for the other containers restored perfectly. When I restored Bitwarden’s backup, everything seemed fine. I signed in on my other devices, ensured syncing was working, and verified all my passwords were intact. Perfect.</p>
<p>About a month later, everything still looked good. Confident in my setup, I decided to format the drive the Raspberry Pi was using and deleted the backups I had for it. Then, of course, Murphy’s Law struck. I logged into my new Bitwarden instance to check on some documents I had uploaded, and to my surprise, they were gone.</p>
<p>This leads to the major feature Bitwarden is missing: the ability to export attachments when you back up your vault.</p>
<p>Let me walk you through what happened. In my self-hosted instance, I had to use a cloud-hosted Bitwarden Vault to get a license for the self-hosted subscription. So, I decided to test this feature in the cloud-hosted vault. Here’s what I found:</p>
<p>When you try to export your vault, you have a few options—JSON, CSV, or encrypted JSON. I selected JSON, confirmed the format, typed in my master password, and exported the vault. When I looked at the exported file, it was clear something was off. The file size was only 636 bytes, even though the test entry I uploaded included a 40 MB attachment.</p>
<p>I’ll take some responsibility here—there were red flags I should have noticed. The file was too small, and JSON is unlikely to contain encoded attachments due to size limitations. There were no additional folders or files for attachments, just a single, tiny JSON file. I should have realized this, but I was working casually and didn’t double-check.</p>
<p>To make matters worse, there’s no warning in the Bitwarden interface about attachments not being included in exports. The only mention of this that I could find was in the &ldquo;Export Vault&rdquo; help document, which states: “Vault exports will not include file attachments, items in the trash, or sends.” While they do technically warn you, I think this information should be far more prominent.</p>
<p>Bitwarden has no problem including warnings in other parts of the app. For instance, the &ldquo;Security&rdquo; tab highlights warnings about changing your master password or enabling two-step login with yellow-highlighted alerts. A similar approach for export warnings could save users from losing critical data.</p>
<p>Needless to say, I lost backups of SSH keys, important documents, and even photos of identification that I had stored securely in Bitwarden. It’s a harsh lesson in the importance of keeping local backups, which is a topic I’ll cover in a future discussion.</p>
<p>After realizing this, I started searching to see if others had faced the same issue. I found a Hacker News thread discussing the exact problem: Bitwarden does not export attachments in backups. The thread linked to a community feature request for this functionality dating back to May 2018. That’s nearly six years, and the feature still hasn’t been implemented.</p>
<p>Some commenters suggested contributing to the open-source project by submitting a pull request to implement the feature. While that’s a fair point, it’s also worth noting that file attachments are a paid feature. If you’re paying for the product, you might reasonably expect such a basic feature to be included without needing to develop it yourself.</p>
<p>All this is to say: if you’re using attachments in Bitwarden or considering it, I’d recommend either avoiding them or ensuring you save local copies of any files you upload. Personally, I might use this as an opportunity to explore other options like KeePass and see if they better meet my needs.</p>
<p>I hope sharing this experience helps someone avoid losing their attachments in Bitwarden. If you have any questions or comments, feel free to leave them below, and I’ll see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>My Top 3 Favorite Linux Commands (and How I Use Them)</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/my-three-favorite-linux-commands/" />
        <id>https://staging.sideofburritos.com/blog/my-three-favorite-linux-commands/</id>
        <published>2024-12-23T10:00:00Z</published>
        <updated>2024-12-23T10:00:00Z</updated>
        <summary type="html">I share my three favorite Linux commands that I use daily: dig, whois, and ping. I demonstrate how I use dig for DNS lookups and troubleshooting, including resolving hostnames, finding MX records, and using &#43;trace for in-depth DNS debugging. Then, I explore the whois command for gathering domain and IP address information, including registration details and server locations. Finally, I explain how ping helps diagnose network connectivity and DNS issues quickly and efficiently. These commands are simple yet powerful tools for any Linux user.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode102s0hbhb">🎥 


<a href="https://youtu.be/SusygCxeF78" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>So, as I&rsquo;m recording this video, it&rsquo;s currently 5 days before Christmas. When you&rsquo;re watching this, it will be 2 days before Christmas. 5 - 2 is 3. Therefore, I want to talk about my three favorite Linux commands. These might not be my favorite Linux commands, but they are my most used ones.</p>
<p>The first one is dig, and what that&rsquo;s useful for is resolving hostnames to IP addresses or looking up specific DNS records. So, in the basic sense, we&rsquo;ll just do a dig on sideofburritos.comom.</p>
<p>We can see here in the answer section, we have the two IP addresses that correspond to the two A records I have assigned for my domain. If you want a cleaner output to only show the answer section, you can add +short on the end. Now, we only get the two IP addresses instead of everything else.</p>
<p>Another use of this, which I was reminded of yesterday when someone asked me what email provider I use for my site sideofburritos.com domain, is if we do another query and add MX on the end of it—which is short for mail exchange—it will do a query for the mail exchange records associated with my domain. So, if we run that again, here&rsquo;s the response. We can see it&rsquo;s mail.protonmail.ch and mx.secprotonmail.ch. Those are the mail servers that ProtonMail uses for custom domains.</p>
<p>Another example: if we do the same query for yellowball.fm, which is the podcast hosting platform I run (if you&rsquo;re looking for hosting), we can see here mail.tutao.de. Tutanota changed their name to &ldquo;Tuta&rdquo; so it&rsquo;s easier to say, but they haven&rsquo;t changed their records. Anyways, I use Tutanota for that. But that&rsquo;s a quick way to see what email provider someone might be using to send emails. You can use this to do some sleuthing and get other information about a domain, but those are the main two ways I use it for queries.</p>
<p>The last way that I use it commonly, and this is mostly for troubleshooting, is adding +trace. If we scroll up to see the output: fun fact—domains actually have a dot or period on the end of them. Let&rsquo;s just change that to make it a bit more clear. You don&rsquo;t need to type the dot; it&rsquo;s just assumed, but in all reality, it is there. Domain names are read from right to left, so that&rsquo;s why we can see here the first query is for . (dot), which specifies the root. That&rsquo;s why we get the root name servers back in our response.</p>
<p>Next, we have .com, which is why we see the com. nameservers. That&rsquo;s the next one that we need to query to get the response for who has cab.bos.com. So once those are queried for cab.bos.com, they reply with the authoritative nameservers for the domain, which we can see here: cab.bos.com.. We have the NS record nameservers, and we have the two authoritative nameservers that I have configured for my domain.</p>
<p>Then lastly, those are queried, and what those reply with are the associated A records for our initial query that was sent. So, before, when we were running a simple dig sideofburritos.comom, all this was happening in the background, but you weren&rsquo;t seeing it because we didn&rsquo;t include the +trace. So, you might be wondering why this is useful. Well, first off, I think it&rsquo;s just cool to see this—I like DNS a lot; I think it&rsquo;s a very cool protocol.</p>
<p>But it&rsquo;s also useful for troubleshooting. Let&rsquo;s say you&rsquo;re trying to figure out why your domain&rsquo;s not resolving. If you run +trace and you get to here but get nothing else after that, it means something&rsquo;s going on with your records that are configured there. That would indicate, &ldquo;Hey, go look at your nameservers. Do you have the A records configured correctly? Have they propagated?&rdquo; Different things like that. So, again, you might not use this often, but when you do, it&rsquo;s invaluable for troubleshooting.</p>
]]></content>
      </entry>
      <entry>
        <title>How to guide - Raspberry Pi USB Boot</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/raspberry-pi-usb-boot/" />
        <id>https://staging.sideofburritos.com/blog/raspberry-pi-usb-boot/</id>
        <published>2023-03-06T10:00:00Z</published>
        <updated>2023-03-06T10:00:00Z</updated>
        <summary type="html">Step-by-step guide to configure your Raspberry Pi to boot from USB first.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode113s0hbhb">🎥 


<a href="https://youtu.be/_5Drx8hNIr0" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-infor-video">Links referenced in/for video</h2>
<ul>
<li>


<a href="https://youtu.be/CnRYn-9EGvE" target="_blank" rel="noopener" class="text-break">https://youtu.be/CnRYn-9EGvE</a> - What is Raspberry Pi Imager?</li>
<li>


<a href="https://www.raspberrypi.com/software/" target="_blank" rel="noopener" class="text-break">https://www.raspberrypi.com/software/</a> - Download Rapsberry Pi Imager</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong> ✔️</p>
<p>The default boot order on the Raspberry Pi is to first boot from the micro SD card, which is less than ideal if you would like to boot from a USB drive first. So, in today&rsquo;s video, I&rsquo;m going to cover how you can change the boot order on your Raspberry Pi.</p>
<p>To begin, you will need Raspberry Pi Imager. For this, if you&rsquo;ve never used it before, check out my video linked on the screen now and down below where I go over the basics and how to install it.</p>
<p>Once you open Raspberry Pi Imager, select &ldquo;Choose OS&rdquo;, scroll down, and select &ldquo;Miscellaneous utility images&rdquo;, and select &ldquo;Bootloader&rdquo;. Then, select the option for USB boot which boot from USB if available, otherwise boot from SD card, which is exactly what we want.</p>
<p>So, once you select that, the next step is to choose a storage device. For this example, I&rsquo;ll be using a Micro SD card, but make sure whatever medium you decide to use, you don&rsquo;t have any data stored on it that you need to keep because this process will completely erase it.</p>
<p>So, at this point, connect the SD card to your computer.
Once that&rsquo;s connected, select &ldquo;Choose storage&rdquo;, select your storage device, and then before we click &ldquo;Write&rdquo;, just double-check that you have USB boot as the operating system, the correct storage device is selected, and then go ahead and click &ldquo;Write&rdquo; again. Just a warning that all existing data will be erased. Are you sure you want to continue? Yes.</p>
<p>The USB boot image is very small, so this should take less than 30 seconds. Once it does finish, you can select &ldquo;Continue&rdquo;, and we can now remove our storage device from our computer.</p>
<p>So, at this point, we now have our Raspberry Pi. I&rsquo;m going to go ahead and insert the micro SD card into it, and now the next step will be to power it up. I&rsquo;m just going to switch my camera to my computer screen so you can see what it looks like. If you don&rsquo;t have a monitor to connect your Raspberry Pi to, that&rsquo;s perfectly fine. Just power up your Raspberry Pi, let it sit for 30 seconds, and you should be all set.</p>
<p>As you&rsquo;ll see in a moment on my screen, the Raspberry Pi will power up from an image we just flashed to our micro SD card, and the bootloader will be reconfigured to boot from the USB drive first and the micro SD card second.</p>
<p>So, at this point, I have my Raspberry Pi connected to my monitor, and I have the micro SD card inserted in the Raspberry Pi. I&rsquo;m now going to power up the Raspberry Pi.</p>
<p>Once the green screen shows up, that means that the boot order has been successfully reconfigured, and now our Raspberry Pi will boot from USB first and micro SD card second. If you enjoyed this video, I think you&rsquo;ll like the top one listed here, and the bottom one has been automatically selected for you.</p>
]]></content>
      </entry>
      <entry>
        <title>What is Raspberry Pi Imager?</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/what-is-raspberry-pi-imager/" />
        <id>https://staging.sideofburritos.com/blog/what-is-raspberry-pi-imager/</id>
        <published>2023-02-20T10:00:00Z</published>
        <updated>2023-02-20T10:00:00Z</updated>
        <summary type="html">Raspberry Pi Imager is a free software tool that allows you to easily download and install operating systems on your Raspberry Pi computer.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode124s0hbhb">🎥 


<a href="https://youtu.be/CnRYn-9EGvE" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://www.raspberrypi.com/software/" target="_blank" rel="noopener" class="text-break">https://www.raspberrypi.com/software/</a> - Raspberry Pi Imager Download</li>
<li>


<a href="https://github.com/raspberrypi/rpi-imager" target="_blank" rel="noopener" class="text-break">https://github.com/raspberrypi/rpi-imager</a> - Telemetry collection details</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong> ✔️</p>
<p>Raspberry Pi Imager makes it easy to install a variety of operating systems onto your micro SD card, external SSD, or whatever other medium you choose to install your operating system on for your Raspberry Pi. They make it super easy to install. You can head on over to raspberry pi.com. Once you get there, select &ldquo;Software&rdquo; and then, depending on which operating system you are running, select that download. In my case, download for Windows.</p>
<p>Once the download finishes, open it. Do you want to allow this app? Yes, follow the prompts. Once that finishes, select &ldquo;Finish.&rdquo; There is one setting I like to change before I use it. The setting I like to change is located in the advanced settings. To access that on Windows, you need to hit Ctrl, Shift, and X on your keyboard, and you should see this screen pop up. Once this shows up, I change this to &ldquo;Always use,&rdquo; and then I scroll down to the bottom, and the setting labeled &ldquo;Enabled Telemetry,&rdquo; I uncheck that and then select &ldquo;Save.&rdquo;</p>
<p>The detail on the GitHub page, which I will link down below, explains what Telemetry is collected, the URL, operating system name, and category if present, of a selected image are sent along with the running version of Raspberry Pi Imager, your operating system, CPU architecture, local, and Raspberry Pi revision if applicable to this URL. And then they go over the web service that it&rsquo;s sent to, where it&rsquo;s hosted and why they do it, which is to allow them to query the number of downloads over time and nothing else. I personally don&rsquo;t think there&rsquo;s anything malicious about the Telemetry they want to collect, but since the option is easily accessible, I like to disable it.</p>
<p>So, at this point, you can now browse the OS&rsquo;s that are available to install through the tool. They have the default Raspberry Pi OS, a popular section I like to use, as well as other general-purpose OS. In here, they have Ubuntu, which is what I&rsquo;ll be using in my demonstrations in future videos. They have some useful options under &ldquo;Miscellaneous Utility Images&rdquo; and under &ldquo;Bootloader.&rdquo; From here, you can change the boot order of your device. So, if you want to boot from USB before SD card, you can configure that from here.</p>
<p>I just wanted to give a quick overview of what this software offers. In a future video, I&rsquo;ll walk through the install and booting up of our freshly installed OS on our Raspberry Pi. If you enjoyed this video, I think you&rsquo;ll like the top one here, and the machines think you&rsquo;ll like the bottom one.</p>
]]></content>
      </entry>
      <entry>
        <title>Raspberry Pi 4 Explained | Hardware layout</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/raspberry-pi-4-explained/" />
        <id>https://staging.sideofburritos.com/blog/raspberry-pi-4-explained/</id>
        <published>2023-01-30T10:00:00Z</published>
        <updated>2023-01-30T10:00:00Z</updated>
        <summary type="html">The Raspberry Pi 4 is a compact and powerful computer that can be used for a variety of applications.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode112s0hbhb">🎥 


<a href="https://youtu.be/oWxeoU9v3K8" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://www.amazon.com/dp/B09HKGGPLR" target="_blank" rel="noopener" class="text-break">https://www.amazon.com/dp/B09HKGGPLR</a> - Western Digital 250GB WD Blue SN570 NVMe</li>
<li>


<a href="https://www.amazon.com/dp/B08G14NBCS" target="_blank" rel="noopener" class="text-break">https://www.amazon.com/dp/B08G14NBCS</a> - ORICO M.2 NVMe SSD Enclosure</li>
<li>


<a href="https://www.hackster.io/news/meet-the-new-raspberry-pi-4-model-b-9b4698c284" target="_blank" rel="noopener" class="text-break">https://www.hackster.io/news/meet-the-new-raspberry-pi-4-model-b-9b4698c284</a></li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong> ✔️</p>
<p>In today&rsquo;s video, I wanted to cover the hardware components on the Raspberry Pi. Understanding what you are working with is helpful and I find it impressive what they have managed to cram on this circuit board. Towards the end of the video, I will suggest an upgrade if you plan to use it for full-time hosting. On the top right, we have a gigabit Ethernet port, which supports true gigabit Ethernet speeds. The Ethernet transceiver chip on the Raspberry Pi allows you to achieve full gigabit speeds of 1000 megabits per second, compared to the Raspberry Pi 3, which was limited to 300 megabits per second. Below the Ethernet port, we have two USB 3.0 ports and two USB 2.0 ports. On the side view, we can see the Ethernet port in the center and two USB 3.0 ports (which have blue inside) and two USB 2.0 ports (black) on the left. Below the Ethernet controller, we have the USB controller chip. On the previous Raspberry Pi 3, the Ethernet and USB controller were on the same chip, causing the limitation of 300 megabits per second on the gigabit Ethernet interface.</p>
<p>Now, that&rsquo;s broken up into two separate chips, which allows for USB 3.0 and the true gigabit Ethernet port. So now, if we continue on our way around the board, here we have a four-pole stereo output jack, which is handy if you want to connect headphones or some other external speaker. To the left of that, we have a CSI camera port. This is something I&rsquo;ve never actually used, but if you wanted to connect an external web camera, if you use this as a desktop replacement, that&rsquo;s what that port could be used for. To the left of that, we have two micro HDMI ports, which means that this board does support dual displays, which again is impressive for something so small. If you only use a single monitor, then this board can support 4K at 60 frames per second. If you use the dual display option, it can support two monitors at 4K 30 frames per second. Now, to the left of the micro HDMI ports, we have a USBC port, and this is used to provide power to the Raspberry Pi. Now, returning to the top of the board, here we have a DSi display port, this is something I&rsquo;ve never used. And, continuing up to the top left, we have a radio frequency shielded module that provides Dual Band Wi-Fi 2.4 and 5 gigahertz. It provides 802.11 BGN and AC along with Bluetooth 5.0 and Bluetooth LE. So, if you don&rsquo;t have a nearby Ethernet port, you can still use the wireless adapter and have internet access. It&rsquo;s also helpful if you use this as a desktop computer replacement; you can connect a Bluetooth keyboard and mouse to it. Above that, we have this black bar with 40 pins in it; this is a 40-pin GPIO header, you likely won&rsquo;t be using this. And next to that, we have a grouping of four pins, and this is used for PoE. There&rsquo;s an extra module you can purchase, which is a PoE hat, and what that allows you to do is use PoE with the Raspberry Pi. PoE stands for power over Ethernet, so what that does is, once you plug in the PoE hat to the Raspberry Pi, you can now plug in an Ethernet cable, and if your switch supports PoE, then that singular cable can provide both network connectivity and power to the Raspberry Pi, and you don&rsquo;t need to use the USBC port to power it.</p>
<p>So, in the center, we have the &ldquo;star of the show.&rdquo; This is a 64-bit quad-core Arm Cortex A72 processor clocked at 1.5 gigahertz. This processor has been more than enough for small projects. To the right of the CPU, we have DDR4 SD RAM. This will vary in size depending on the Raspberry Pi purchased. This one has 4GB of RAM, but it can range from 2GB to 8GB. This concludes the top of the board.</p>
<p>Moving to the bottom, there&rsquo;s one component to highlight: the Micro SD card slot. This is commonly used to store the OS and related files. To upgrade, the author suggests using an NVMe SSD instead of the Micro SD card. You&rsquo;ll need an NVMe SSD and an enclosure to plug the SSD in, then connect it to the Raspberry Pi via USB. This author uses it for a Mastodon server on a Raspberry Pi. You&rsquo;ll still need a Micro SD card for initial setup, but once that&rsquo;s done, the OS and data will be stored on the NVMe SSD. The reason for this upgrade is that Micro SD cards can be unreliable with large amounts of reading and writing. If a modern SD card fails, it goes into read-only mode to protect data.</p>
<p>I actually experienced this twice when I was setting up my Mastodon server. I tried to use only a Micro SD card, but when I installed the ruby gems, which required a high number of reads and writes, the SD cards went into read-only mode and I could no longer use them. Since I upgraded to the M.2 SSD, I haven&rsquo;t had any issues and it&rsquo;s been running reliably. I&rsquo;ll link both the enclosure and the NVMe SSD below if you&rsquo;re interested in purchasing them. I bought both from Amazon, the bookstore run by Bezos. The enclosure cost me around $19 and the specific NVMe drive that I bought was $35. There are cheaper drives available, but I like Western Digital, so you can probably pick one up for $15 on the low end. Again, this isn&rsquo;t a required upgrade, you can still just use the Micro SD card if you prefer, but for reliability&rsquo;s sake, I would suggest making the upgrade. There were some comments on my last video that said you can get a used old laptop for cheaper. This is likely true, but I like the small form factor and low power consumption of the Raspberry Pi, so I stick with it. The self-hosting guides that I&rsquo;ll have in the near future can be adapted to whatever hardware you have lying around, but I&rsquo;ll be demonstrating and performing the installs on a Raspberry Pi. If you made it this far and are not tired of hearing me talk yet, the top video is one I think you&rsquo;ll enjoy if you liked this one, and the bottom one was chosen for you by the YouTube algorithm.</p>
]]></content>
      </entry>
      <entry>
        <title>Should you use self hosted applications?</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/self-hosted-raspberry-pi/" />
        <id>https://staging.sideofburritos.com/blog/self-hosted-raspberry-pi/</id>
        <published>2023-01-16T10:00:00Z</published>
        <updated>2023-01-16T10:00:00Z</updated>
        <summary type="html">Self-hosting can be the best option for privacy. When you decide to self-host you will have some added work in terms of security, uptime, and east of use.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode117s0hbhb">🎥 


<a href="https://youtu.be/NqWho5Qgq5A" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="supplies-needed">Supplies needed</h2>
<ul>
<li>Raspberry Pi - I purchased the Raspberry Pi Model B (4GB). If you can afford it, try to get 2 (1 for a backup).</li>
<li>Micro SD Card - I went with a 64GB High Endurance SanDisk card (linked below). I would suggest buying 1 extra.</li>
<li>External monitor - this isn&rsquo;t required, but it would make things easier to see the display out from your Raspberry Pi. You can use it without a monitor, as long as you know how to find out the IP address for SSH.</li>
<li>If you want to use a monitor, you&rsquo;ll need a Micro HDMI to HDMI cable</li>
<li>Keyboard &amp; mouse (wireless or wired). Again, this isn&rsquo;t required. You can SSH into the Raspberry Pi from another computer.</li>
<li>A desktop/laptop you can SSH to the Raspberry Pi from. The other option would be to configured it using a monitor you plug into it with a keyboard/mouse, and you wouldn&rsquo;t need access to another computer.</li>
<li>Ethernet cable if you&rsquo;d like to use the Ethernet port. It also supports Wi-Fi.</li>
</ul>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://rpilocator.com/" target="_blank" rel="noopener" class="text-break">https://rpilocator.com/</a> - Helpful tool to monitor multiple sites for Raspberry Pi availability. This will be your best bet at finding one.</li>
<li>


<a href="https://store.rakwireless.com/" target="_blank" rel="noopener" class="text-break">https://store.rakwireless.com/</a> - I&rsquo;ve purchased two from here. They ship directly from China and have a heat sink attached. I don&rsquo;t know if these are knockoffs, but everything looks legitimate.</li>
<li>


<a href="https://www.amazon.com/dp/B07P3D6Y5B" target="_blank" rel="noopener" class="text-break">https://www.amazon.com/dp/B07P3D6Y5B</a> - SanDisk 64GB High Endurance Video MicroSDXC</li>
<li>


<a href="https://www.amazon.com/dp/B08ZY3RR9X" target="_blank" rel="noopener" class="text-break">https://www.amazon.com/dp/B08ZY3RR9X</a> - Micro HDMI to HDMI cable</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>They say the best option for privacy is to self host your own data and services. While I do agree the privacy benefits are hard to beat, there are some downsides that I don&rsquo;t think are discussed enough. Before we get into it, I will be doing a self hosting series in the very near future using a Raspberry Pi, I settled on the Raspberry Pi Because it&rsquo;s an affordable option for many people compared to purchasing a full fledged server. It&rsquo;s low power nearly silent, since it&rsquo;s fanless. And you can get one for between 35 and 100. US dollars, depending on where you buy them from. One of the main benefits of self hosting, especially as someone who talks a lot about privacy is that you own your data and have physical control over it. It&rsquo;s not uploaded to the cloud encrypted on a server that a company may have access to, you are going to be responsible for it yourself on your own hardware, wherever you decide to plug it in and powered up. I think having that level of control can be liberating, while at the same time terrifying, your data will be stored on a little card like this. That means if you lose it, the card malfunctions, or there&rsquo;s a natural disaster and it&rsquo;s destroyed, and you didn&rsquo;t take a backup or replicate it somewhere your data is gone. And that&rsquo;s on you. There&rsquo;s no large corporation ensuring its integrity, and that it&rsquo;s stored in multiple geographic locations in case of catastrophic failure. Now, while that might sound a bit scary, there&rsquo;s also something satisfying about knowing that if you want to destroy your data you can and it&rsquo;s not stored somewhere that you were not aware of.</p>
<p>So as far as privacy goes, self hosting is a big win. Security. That&rsquo;s a different story. For all intents and purposes, you will be a systems administrator, patches, updates, upgrades configurations, the security we all take for granted when we upload our data to a billion or trillion dollar company is now your responsibility. This goes back to where I mentioned that at least some part of you has to be okay with tinkering and troubleshooting. This won&rsquo;t be a set it and forget it sort of thing, you&rsquo;ll have to maintain it and take care of it. It also sounds like I&rsquo;m talking about a pet. Modern day expectations are that services are available 24/7 365 As someone who has worked for a hosting company, I don&rsquo;t think most people realize the level of effort and resources it takes to get five nines of uptime. When you self host you&rsquo;re at the mercy of your internet service provider and Power Company. Maybe the power goes out for 10 seconds, which normally wouldn&rsquo;t be a big deal. But now your server was powered off and you need to turn it on and login again. Maybe you had a battery backup so you&rsquo;re good for short outages. But what if you live somewhere like Florida and the power&rsquo;s out for weeks. I also heard that some ISPs have rules about hosting services out of your home, even if they are for personal use. I&rsquo;ve never had any issues in the United States. But I don&rsquo;t know how that works in other countries. An easy way to avoid some of the hardware power and internet failures I just mentioned would be to rent a VPS from a cloud provider. There are some pretty affordable ones out there. But for now on this channel, I&rsquo;m going to focus on hosting out of your home.</p>
<p>With the doom and gloom out of the way. I&rsquo;ll be doing various demonstrations in the coming months on configurations and services. If you have the money, I would suggest getting at least two Raspberry Pi&rsquo;s with extra SD cards so that you can have one to mess around with and one to host your data. It&rsquo;s also useful to have one as a backup in case your main one has a hardware issue. The goal of this was not to demotivate you. That&rsquo;s the last thing I want, especially since I&rsquo;ll be making videos on it in the near future. I just want to make sure that you&rsquo;re aware of the added responsibility you&rsquo;ll have before embarking on this.</p>
]]></content>
      </entry>

</feed>
