Elektrine lite

← Feed

@unitedwithme@lemmy.today

2026-09-06 05:01 UTC

I’m going to go out in a limb and die on it, that: why overcomplicate things with Docker containers?? I didn’t read through your post; The title, to me, doesn’t require it based on what you’re doing. I then read you’re Problem box and confirmed you don’t need NVR on Docker. Seems overkill or really, pointless. A. Do you absolutely NEED the VLAN for your NVR? Why not just isolate the devices on the network with a bogus DNS record or FW rule blocking via MAC or IP? B. Why run NVR through Docker? I hate devs who only containerize and don’t allow for options. Deal killer, personally. But it it has a native option, why not run that? It’s just extra steps for traffic to pass through which feels like a complicated bottleneck. Idk, you do you. I’m SURE I’ll get hate for this comment, but sometimes you need to take a steep back and think about what’s necessary vs what’s for fun for learning. I’d you can, hey great! If you can’t, or it breaks, how much time do you now want to spend learning how to troubleshoot?

Replies (2)

  • @GreenKnight23@lemmy.world 2026-09-06 05:58

    @> A. Do you absolutely NEED the VLAN for your NVR? Why not just isolate the devices on the network with a bogus DNS record or FW rule blocking via MAC or IP? DNS doesn’t stop direct IP comms. I have seen a few devices that talked direct IP to bypass DNS blocks. as you said, a firewall rule is a far better solution. However, I don’t trust my Chinese cameras enough to not rootkit their way across my network, so it has to be quarantined. a VLAN is one way to successfully do that. personally I dislike the high maintenance costs of VLANs. That’s why I opted to run a completely different network for all my IOT devices including cameras. the DVR is on that network and proxied through a dual homed server that straddles the two networks. firewall rules in place that only allow specific ports through on specific devices to specific devices.

    Open ##4681186

  • @lemmyvore@feddit.nl 2026-09-06 10:02

    Tagged VLANs would be needed regardless, because I have only one server with one physical connection and I wanted to have processes on it on 2 different networks. Docker is neither here nor there, you’re right it’s not needed for the solution. I was using it anyway, I know lots of selfhosters do, and it does make it easy to create an ipvlan and put an app on it. Docker is not the only way to achieve containerization but I do appreciate and use containerization (and virtualization). It lets the host OS stay simpler and cleaner and prevents the various apps from messing with it. It makes it easy to control each app’s environment. You can do app containers, system containers or VMs as needed. It makes it easy to back up, restore and reproduce an app and its state, independently of the host OS or any other app. Abstractions help… they empower you to do more. You invest some time into learning, sure, but it pays off later in time saved managing and the ability to do more complex stuff faster. Troubleshooting is what it is. Nothing’s perfect, you’re going to end up troubleshooting something sometime not matter what you use.

    Open ##4684665