[{"content":" ██╗ ██╗ ███████╗██████╗ █████╗ ██████╗ ███╗ ███╗███████╗███╗ ██╗ ████████╗ ██╔════╝██╔══██╗██╔══██╗██╔══██╗████╗ ████║██╔════╝████╗ ██║ ╚██╔═██╔╝ ███████╗██████╔╝███████║██████╔╝██╔████╔██║█████╗ ██╔██╗ ██║ ████████╗ ╚════██║██╔══██╗██╔══██║██╔══██╗██║╚██╔╝██║██╔══╝ ██║╚██╗██║ ╚██╔═██╔╝ ███████║██████╔╝██║ ██║██║ ██║██║ ╚═╝ ██║███████╗██║ ╚████║ ╚═╝ ╚═╝ ╚══════╝╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝╚═╝ ╚═══╝ stian@hugo ~ $ whoami stian - photos, travel, and the occasional bit of tech stian@hugo ~ $ uptime sbarmen.no, up since 2013 Notes and photos from wherever I\u0026rsquo;ve been, plus the occasional writeup of something I built or broke.\n","date":"27 September 2026","externalUrl":null,"permalink":"/","section":"","summary":" ██╗ ██╗ ███████╗██████╗ █████╗ ██████╗ ███╗ ███╗███████╗███╗ ██╗ ████████╗ ██╔════╝██╔══██╗██╔══██╗██╔══██╗████╗ ████║██╔════╝████╗ ██║ ╚██╔═██╔╝ ███████╗██████╔╝███████║██████╔╝██╔████╔██║█████╗ ██╔██╗ ██║ ████████╗ ╚════██║██╔══██╗██╔══██║██╔══██╗██║╚██╔╝██║██╔══╝ ██║╚██╗██║ ╚██╔═██╔╝ ███████║██████╔╝██║ ██║██║ ██║██║ ╚═╝ ██║███████╗██║ ╚████║ ╚═╝ ╚═╝ ╚══════╝╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝╚═╝ ╚═══╝ stian@hugo ~ $ whoami stian - photos, travel, and the occasional bit of tech stian@hugo ~ $ uptime sbarmen.no, up since 2013 Notes and photos from wherever I’ve been, plus the occasional writeup of something I built or broke.\n","title":"","type":"page"},{"content":"","date":"27 September 2026","externalUrl":null,"permalink":"/categories/","section":"Categories","summary":"","title":"Categories","type":"categories"},{"content":"","date":"27 September 2026","externalUrl":null,"permalink":"/categories/homelab/","section":"Categories","summary":"","title":"Homelab","type":"categories"},{"content":"In part one I built a Proxmox VE node on a free Oracle Cloud Ampere instance, with LXC containers on an internal bridge that can reach the internet but cannot be reached from it. Safe, and a good setup for internal services. But not useful for external exposure.\nThis post is the other half: giving a container its own public IPv4 address, filtering it properly and as a bonus optionally doing IPv6 without any NAT at all.\nSame values as before. The addresses are examples.\n1. A container with its own public IP # The example: private 10.20.0.12 on the VNIC, mapped 1:1 to container 10.20.1.12. Same last octet on both sides, which keeps the NAT rules readable.\nI N T E R N E T │ 203.0.113.41 ────────┼──────── primary public IP (reserved, 1:1) │ (shared egress, part one) │ subnet 10.20.0.0/24, gw .1 │ ╔═════════════════════════════════╧══════════════════════════════════╗ ║ px0-oc — one public IP mapped straight through to a container ║ ║ ║ ║ enp0s6 10.20.0.10/24 ← primary public IP ║ ║ + 10.20.0.12/32 ← 203.0.113.41 ║ ║ │ ║ ║ │ DNAT in 10.20.0.12 → 10.20.1.12 ║ ║ │ SNAT out 10.20.1.12 → 10.20.0.12 (1) ║ ║ │ SNAT out 10.20.1.0/24 → 10.20.0.10 (2) ║ ║ │ ║ ║ vmbr0 10.20.1.1/24 internal only, never seen by OCI ║ ║ ═════════╤═══════════════════════════════╤════ ║ ║ ┌───────┴───────┐ ┌───────┴───────┐ ║ ║ │ CT 102 │ │ CT 101 │ ║ ║ │ 10.20.1.12 │ │ 10.20.1.20 │ ║ ║ │ 203.0.113.41 │ │ outbound only │ ║ ║ └───────────────┘ └───────────────┘ ║ ╚════════════════════════════════════════════════════════════════════╝ In: the public IP lands on the VNIC and is DNAT\u0026rsquo;d straight through to the container. Out: rule (1) sends that one container back out the same address, and it has to sit above (2), the catch-all from part one that every other container egresses on.\n1.1 In the OCI console # Instance → Networking → the VNIC → IP Administration Assign private IP address Subnet 10.20.0.0/24 Manually assign, enter 10.20.0.12, CIDR 32 Optional: a hostname Public IP: Reserved public IP → Create new reserved IP address Give it a name, for example the external hostname you will use. It is only a label in OCI and does not set reverse DNS: mine has no PTR record at all. If you need reverse DNS, for mail in particular, ask Oracle for it through a support request. Assign. Note the public IP you get back. In the examples below it is 203.0.113.41. Also, when I do this and click Assign the window just stalls and does not close. It still works, just go back and refresh to find the IP.\n1.2 On the Proxmox host # Set HOST, PRIV and CT, then run the block as-is.\nHOST=10.20.0.10 # this node\u0026#39;s primary address on enp0s6, from part one PRIV=10.20.0.12 CT=10.20.1.12 ip addr add ${PRIV}/32 dev enp0s6 iptables -t nat -A PREROUTING -i enp0s6 -d ${PRIV} -j DNAT --to-destination ${CT} iptables -t nat -I POSTROUTING 1 -o enp0s6 -s ${CT} -j SNAT --to-source ${PRIV} sed -i \u0026#34;/^:POSTROUTING/a -A PREROUTING -d ${PRIV}/32 -i enp0s6 -j DNAT --to-destination ${CT}\\\\n-A POSTROUTING -s ${CT}/32 -o enp0s6 -j SNAT --to-source ${PRIV}\u0026#34; /etc/iptables/rules.v4 sed -i \u0026#34;\\\\|^\\\\s*address ${HOST}/|a\\\\ up ip addr add ${PRIV}/32 dev enp0s6\u0026#34; /etc/network/interfaces iptables-restore --test \u0026lt; /etc/iptables/rules.v4 \u0026amp;\u0026amp; echo \u0026#34;rules.v4 OK\u0026#34; In order:\nip addr add gives the host the private address the public IP maps to. A /32, since it is one service address and not a subnet. DNAT is inbound: traffic arriving for 10.20.0.12 is handed to the container. No port or protocol match, so all of it. SNAT is outbound: the container leaves as 10.20.0.12 instead of the host\u0026rsquo;s primary address. The two sed lines make both survive a reboot, by writing the rules into /etc/iptables/rules.v4 and the address into the enp0s6 stanza in /etc/network/interfaces, anchored on HOST, the node\u0026rsquo;s own address. Get HOST wrong and the second sed matches nothing, silently. ip -4 -o addr show enp0s6 prints it: it is the one that is not a /32. iptables-restore --test parses the file without loading it. If it is silent and you get rules.v4 OK, the host will come up with these rules. Do not skip it. The first sed inserts both rules directly after the :POSTROUTING line, which puts the SNAT rule above the 10.20.1.0/24 catch-all from part one. That order matters: the specific rule has to be evaluated first, or the container egresses on the wrong public IP and you get to spend an evening wondering why your reverse DNS never matches. -I POSTROUTING 1 does the same thing to the live ruleset, where -A would append below the catch-all.\nOnly the live ip addr add matters today, the file edit is for the next boot. Proxmox also reflows this file whenever you touch networking in the GUI, so check it by eye now rather than finding out later:\nsed -n \u0026#39;/iface enp0s6 inet static/,/^$/p\u0026#39; /etc/network/interfaces Every up ip addr add line should be indented, inside the stanza, above the blank line.\n1.2.1 What it should look like # The /24 and the new /32 side by side:\nip -4 addr show enp0s6 | grep inet inet 10.20.0.10/24 scope global enp0s6 inet 10.20.0.12/32 scope global enp0s6 The SNAT rules in the right order, specific above catch-all:\niptables -t nat -S POSTROUTING -P POSTROUTING ACCEPT -A POSTROUTING -s 10.20.1.12/32 -o enp0s6 -j SNAT --to-source 10.20.0.12 -A POSTROUTING -s 10.20.1.0/24 -o enp0s6 -j SNAT --to-source 10.20.0.10 If the /24 line sits above the /32 line, fix it before going further. iptables -t nat -S PREROUTING should show one DNAT rule per exposed container, and sed -n '/iface enp0s6 inet static/,/^$/p' /etc/network/interfaces the new up ip addr add line.\nIf iptables -t nat -S shows only the four -P policy lines, the rules never loaded. Check systemctl status netfilter-persistent before anything else.\n1.3 The container # Create it exactly as in part one, but with IP 10.20.1.12/24 and gateway 10.20.1.1. If you change the address or the Firewall checkbox later, Proxmox applies it to the running container straight away, no restart needed.\nThe DNAT rule is both protocol- and port-agnostic, so this is true 1:1 NAT: all traffic to that public IP reaches the container, and the host exposes nothing on it.\nOne quirk to remember: the host cannot reach a container via its public-mapped private IP. The DNAT rule matches -i enp0s6 in PREROUTING, which does not apply to locally generated traffic. From the node, always use 10.20.1.x.\nNow ask the internet what the container looks like from outside. The Debian template does not ship curl, so install it first:\npct exec 102 -- sh -c \u0026#39;apt update \u0026amp;\u0026amp; apt install -y curl\u0026#39; pct exec 102 -- curl -s https://ifconfig.me 203.0.113.41 Its own public IP, not the host\u0026rsquo;s. Make sure that this section is 100% working. This is the magic sauce!\n2. Opening ports in OCI # Ports still have to be opened in the security list. Here is the uncomfortable part, which I mentioned in part one and which shapes everything below:\nOCI security rules match on source CIDR, protocol and port. Not on destination IP.\nThere is no per-host ingress filtering. Whatever you open, you open for every address on the subnet. So I open the set of ports I actually need, subnet-wide, and then do the real per-service filtering on the host.\nProtocol Port Service Description TCP 25 SMTP Mail from other mail servers. This is the port MX records point to. TCP 80 HTTP Web, and the HTTP-01 challenge Let\u0026rsquo;s Encrypt uses to issue certificates. TCP 443 HTTPS Web over TLS. TCP 465 SMTPS Mail submission from clients, encrypted with TLS from the first byte. TCP 587 Submission Mail submission from clients, upgraded to TLS with STARTTLS. TCP 2525 SMTP alt Non-standard alternative to 587, for networks that block the usual mail ports. These are the ports for my own services, a mail server and a web server. Adapt the list to what your containers actually run, and open nothing more: every port here is open on every address in the subnet. The tests in this post use port 80, so keep that one open while you follow along.\nOCI does have Network Security Groups, which can be attached per VNIC. I skipped them here in favour of doing it all in the Proxmox firewall, because with one VNIC and many containers behind NAT, an NSG still cannot distinguish between the containers. The filtering has to happen after DNAT, which means on the host.\nA quick sanity test # The Proxmox firewall is not on yet, so this is a good moment to check that a port actually makes it through OCI and the NAT from section 1. In the container you just created, start a listener:\napt update \u0026amp;\u0026amp; apt install -y socat socat TCP6-LISTEN:80,ipv6only=0,reuseaddr,fork /dev/null Then from your laptop, against the container\u0026rsquo;s public IP:\nnc -4 -z -w3 203.0.113.41 80 Connection to 203.0.113.41 port 80 [tcp/http] succeeded! If this fails, the problem is the security list or the NAT, since there is no firewall in the way yet.\n3. The Proxmox firewall # Since OCI will not filter per IP, the Proxmox firewall does the per-service work.\n3.1 The conntrack trap # Read this before you enable anything, because the symptom is maddening.\nSetting firewall=1 on a guest inserts an fwbr bridge into the path, so packets traverse netfilter twice, once bridged and once routed. NAT is decided only on the first packet of a conntrack entry, and on the bridged pass the outgoing interface is the bridge, not enp0s6. The SNAT rule never matches. Containers silently lose outbound connectivity while every rule still looks perfectly correct.\nThe fix is a separate conntrack zone for the firewall bridges:\niptables -t raw -I PREROUTING -i fwbr+ -j CT --zone 1 fwbr+ is a wildcard, so it covers containers that do not exist yet. It belongs in the *raw table of /etc/iptables/rules.v4, which is why it was already in the cloud-init config in part one, so on a build that followed part one there is nothing to persist here. If you added it by hand, add the same line to the *raw table in that file yourself. Avoid netfilter-persistent save here: with the Proxmox firewall active, it also saves the firewall\u0026rsquo;s own PVEFW-* chains.\n3.2 Datacenter → Firewall → IPSet # Create an IPSet mgmt, \u0026ldquo;Internal Networks\u0026rdquo;:\nIP/CIDR Comment 10.0.0.0/16 Home network 10.20.0.0/16 OCI networks 192.168.2.0/24 WireGuard 2001:db8:1000::/48 Home network v6 2603:c0a0:1234:5600::/56 OCI networks v6 fd42:1a2b:3c4d:5e6f::/64 WireGuard v6 This is what opens the default ports to everything internal.\nThe OCI rows are needed: 10.0.0.0/16 only covers 10.0.x.x. The 10.20.0.0/16 row covers the bridge gateway 10.20.1.1, which is what lets the host reach its own containers. The OCI networks v6 row is the VCN\u0026rsquo;s IPv6 prefix from part one and does the same for IPv6. Skip it if you did not enable IPv6 on the VCN.\n3.3 Datacenter → Firewall → Security Group # Create a group baseline with a single rule:\nDirection Action Source in ACCEPT +dc/mgmt The +dc/ prefix is how the GUI references a datacenter-level IPSet.\n3.4 Datacenter → Firewall → Rules # One rule: Insert: Security Group → baseline. That covers host management access. Add it before you turn the firewall on in the next step, or the DROP input policy cuts off new connections to the host the moment you do.\n3.5 Datacenter → Firewall → Options # Field Value Firewall Yes Input Policy DROP Output Policy ACCEPT Forward Policy ACCEPT Forward Policy must be ACCEPT. Guest traffic is filtered by the per-guest chains, not by this policy. Setting it to DROP here does not make you safer, it just breaks things in confusing ways. The DROP input policy means anything not explicitly accepted by a rule is dropped.\n3.6 Per container # Network → net0 → Edit → tick Firewall. This applies straight away, also on a running container. Firewall → Options: Firewall Yes, Input Policy DROP, Output Policy ACCEPT. Firewall → Insert: Security Group → baseline. Firewall → Add your service rules, e.g. ACCEPT, TCP, dest port 80,443. Step 2 is the one I forget every single time. A container with the security group but no Options set is completely unfiltered.\n3.7 Optional: defaults for new containers # Proxmox deliberately has no built-in default firewall config for new guests, to avoid lockouts. Fair enough, but I wanted a safety net for the containers I inevitably misconfigure.\nThis script applies the baseline to every container that is missing it:\ncat \u0026gt; /usr/local/sbin/ct-firewall-defaults \u0026lt;\u0026lt;\u0026#39;EOF\u0026#39; #!/bin/bash # ct-firewall-defaults: give every LXC container the baseline firewall. # # For each container it makes sure that: # 1. Firewall is ticked on the network device (firewall=1 on net0) # 2. The container firewall is on, with input DROP and output ACCEPT # 3. The security group \u0026#34;baseline\u0026#34; is in the container\u0026#39;s rules # Anything already in place is left alone, so a second run changes nothing. # Changes apply straight away, also to running containers. # # Opt a container out, for example one you firewall by hand, by giving it # the tag fw-manual. set -uo pipefail NODE=$(hostname -s) for conf in /etc/pve/lxc/*.conf; do [ -e \u0026#34;$conf\u0026#34; ] || continue vmid=$(basename \u0026#34;$conf\u0026#34; .conf) fw=\u0026#34;/etc/pve/firewall/${vmid}.fw\u0026#34; # Only the current config. Snapshots and pending changes are stored # further down the same file as [sections], each with its own net0. current=$(sed \u0026#39;/^\\[/q\u0026#39; \u0026#34;$conf\u0026#34;) net0=$(sed -n \u0026#39;s/^net0: //p\u0026#39; \u0026lt;\u0026lt;\u0026lt; \u0026#34;$current\u0026#34;) tags=$(sed -n \u0026#39;s/^tags: //p\u0026#39; \u0026lt;\u0026lt;\u0026lt; \u0026#34;$current\u0026#34;) # Skip templates, opted-out containers and containers without a network device. grep -q \u0026#39;^template: 1\u0026#39; \u0026lt;\u0026lt;\u0026lt; \u0026#34;$current\u0026#34; \u0026amp;\u0026amp; continue case \u0026#34;;${tags};\u0026#34; in *\u0026#34;;fw-manual;\u0026#34;*) continue ;; esac if [ -z \u0026#34;$net0\u0026#34; ]; then echo \u0026#34;CT $vmid: no net0, skipped\u0026#34; continue fi # 1. Firewall ticked on the network device. new_net0=\u0026#34;\u0026#34; case \u0026#34;$net0\u0026#34; in *firewall=1*) ;; *firewall=0*) new_net0=\u0026#34;${net0/firewall=0/firewall=1}\u0026#34; ;; *) new_net0=\u0026#34;${net0},firewall=1\u0026#34; ;; esac if [ -n \u0026#34;$new_net0\u0026#34; ]; then if ! pct set \u0026#34;$vmid\u0026#34; -net0 \u0026#34;$new_net0\u0026#34;; then echo \u0026#34;CT $vmid: could not set firewall=1, skipped\u0026#34; continue fi echo \u0026#34;CT $vmid: firewall=1 set on net0\u0026#34; fi # 2. Container firewall on, input DROP, output ACCEPT. if ! grep -q \u0026#39;^enable: 1\u0026#39; \u0026#34;$fw\u0026#34; 2\u0026gt;/dev/null || ! grep -q \u0026#39;^policy_in: DROP\u0026#39; \u0026#34;$fw\u0026#34; || grep -q \u0026#39;^policy_out: DROP\u0026#39; \u0026#34;$fw\u0026#34;; then pvesh set \u0026#34;/nodes/${NODE}/lxc/${vmid}/firewall/options\u0026#34; \\ --enable 1 --policy_in DROP --policy_out ACCEPT \u0026gt;/dev/null \u0026amp;\u0026amp; echo \u0026#34;CT $vmid: firewall options set\u0026#34; fi # 3. The baseline security group. if ! grep -q \u0026#39;^GROUP baseline\u0026#39; \u0026#34;$fw\u0026#34; 2\u0026gt;/dev/null; then pvesh create \u0026#34;/nodes/${NODE}/lxc/${vmid}/firewall/rules\u0026#34; \\ --type group --action baseline --enable 1 \u0026gt;/dev/null \u0026amp;\u0026amp; echo \u0026#34;CT $vmid: GROUP baseline added\u0026#34; fi # Safety check: a filtered container\u0026#39;s network device sits in # fwbr\u0026lt;id\u0026gt;i0, not directly in vmbr0. Proxmox moves it there as soon as # firewall=1 is set, so this should never fire, but if it does, a # restart puts it in place. if [ \u0026#34;$(pct status \u0026#34;$vmid\u0026#34;)\u0026#34; = \u0026#34;status: running\u0026#34; ]; then master=$(readlink \u0026#34;/sys/class/net/veth${vmid}i0/master\u0026#34; 2\u0026gt;/dev/null) if [ \u0026#34;${master##*/}\u0026#34; != \u0026#34;fwbr${vmid}i0\u0026#34; ]; then echo \u0026#34;CT $vmid: WARNING not filtered yet - restart it: pct reboot $vmid\u0026#34; fi fi done EOF chmod +x /usr/local/sbin/ct-firewall-defaults It only changes what is missing, so a correctly configured container is left alone and a second run prints nothing. It never restarts anything: Proxmox applies the firewall setting to running containers straight away. To keep a container out of it, for example one you firewall by hand, give it the tag fw-manual.\nOn a five minute timer:\ncat \u0026gt; /etc/systemd/system/ct-firewall-defaults.service \u0026lt;\u0026lt;\u0026#39;EOF\u0026#39; [Unit] Description=Apply default firewall config to Proxmox containers [Service] Type=oneshot ExecStart=/usr/local/sbin/ct-firewall-defaults EOF cat \u0026gt; /etc/systemd/system/ct-firewall-defaults.timer \u0026lt;\u0026lt;\u0026#39;EOF\u0026#39; [Unit] Description=Apply default firewall config to Proxmox containers [Timer] OnBootSec=2min OnUnitActiveSec=5min [Install] WantedBy=timers.target EOF systemctl enable --now ct-firewall-defaults.timer Check what it has been up to:\njournalctl -u ct-firewall-defaults --since today It is a safety net for containers you forgot, not a replacement for configuring them properly at create time.\n3.8 One note on the firewall backend # All of this assumes the iptables-based pve-firewall. Proxmox also ships an nftables-based proxmox-firewall as an alternative. Switching backends breaks the iptables NAT rules above, and the whole thing would need rewriting in nftables syntax.\nnft list ruleset | grep -c \u0026#39;table.*proxmox\u0026#39; 0 Zero means you are on the iptables backend and everything here applies.\n4. Testing it end to end # New container, ID 103, IP 10.20.1.14. Important: tick Firewall on the network device, and set Firewall Yes under the container\u0026rsquo;s firewall options.\nServe something trivial. This one-liner accepts connections on both IPv4 and IPv6. It sends nothing back, which is all nc -z needs:\nsocat TCP6-LISTEN:80,ipv6only=0,reuseaddr,fork /dev/null The Debian template does not ship socat, so install it first if the command is not found: apt update \u0026amp;\u0026amp; apt install -y socat.\nWith only the baseline group applied, anything on an internal network should reach it. From my laptop, over the tunnel:\nnc -4 -z -w3 10.20.1.14 80 Connection to 10.20.1.14 port 80 [tcp/http] succeeded! Now expose it. Assign 10.20.0.14 with a reserved public IP as in section 1.1, then wire up the NAT as in 1.2 with PRIV=10.20.0.14 and CT=10.20.1.14. The address I got back was 203.0.113.72. From outside:\nnc -4 -z -w3 203.0.113.72 80 || echo \u0026#34;no connection\u0026#34; no connection Which is exactly right. OCI lets it through, the container firewall drops it. Add an ACCEPT rule for TCP/80 on the container:\nTaken on container 107. The rule is the same on 103. Try again:\nnc -4 -z -w3 203.0.113.72 80 Connection to 203.0.113.72 port 80 [tcp/http] succeeded! That is the whole model working: OCI opens the port subnet-wide, and the per-container firewall decides who actually gets it.\n5. IPv6, with no NAT at all # This is the nicest part of the whole build. No NAT, no proxy_ndp, nothing clever. OCI assigns an entire IPv6 prefix to a VNIC, so vmbr0 gets a real subnet and containers get global addresses routed straight to them.\nLevel Size VCN /56 Subnet /64 VNIC individual addresses, and one or more CIDRs of /80 to /128 That VNIC prefix is the piece that makes it work: traffic for the prefix is delivered to the VNIC, and egress from inside it passes OCI\u0026rsquo;s anti-spoofing check without any tricks.\n5.1 Find the subnet prefix # Networking → Virtual Cloud Networks → your VCN → Subnets → your subnet, and read the IPv6 CIDR block. It is also visible from the host, the global address on the VNIC sits inside it:\nip -6 addr show enp0s6 | grep \u0026#39;scope global\u0026#39; # inet6 2603:c0a0:1234:5600::10/128 -\u0026gt; subnet is 2603:c0a0:1234:5600::/64 In this build the subnet is 2603:c0a0:1234:5600::/64 and the host holds ::10, which lands in the reserved first /80.\n5.2 Assign a prefix to the VNIC # Instance → Networking → the VNIC → IP Administration, assign an IPv6 address, pick the subnet prefix, choose Manually assign, and enter the network address of the block:\nField Value IPv6 Address 2603:c0a0:1234:5600:1:: CIDR prefix length 80 A /80 is five hextets, so the fifth hextet identifies the block and the last three must be zero. Any value works there, 1, 2, whatever you like. I used 1.\nWrite 1::, not ::1. The latter sets a host bit and the API turns you down:\nCIDR IP 2603:c0a0:1234:5600:0:0:0:1 does not match network IP 2603:c0a0:1234:5600:0:0:0:0 The mask has to be between 80 and 128 and divisible by 4, and the block is assigned as a secondary IP object on the VNIC. The first and last /80 of the subnet are reserved for ephemeral host addresses, and the host\u0026rsquo;s own ::10 lives in the first one, which is why the block starts at 1:: rather than 0::.\n5.3 Host # Add the IPv6 line to /etc/sysctl.d/99-dmz-nat.conf, next to the IPv4 one part one put there:\nnet.ipv4.ip_forward=1 net.ipv6.conf.all.forwarding=1 Then /etc/network/interfaces: a static address on the VNIC, plus the prefix on the bridge.\niface enp0s6 inet6 static address 2603:c0a0:1234:5600::10/128 gateway fe80::200:17ff:fea9:8b12 iface vmbr0 inet6 static address 2603:c0a0:1234:5600:1::1/80 The gateway is the link-local address the OCI router advertises. Find yours with rdisc6 enp0s6, from the ndisc6 package.\nConfigure the host address statically, do not leave it to DHCPv6. OCI hands out that /128 on a lease, and once systemd-networkd is gone there is nothing left to renew it, so the address quietly disappears when the lease expires. The failure mode is nasty precisely because it is not immediate: IPv6 keeps working for a while afterwards, because the host falls back to a source address from vmbr0 that is inside the assigned prefix and therefore still accepted by OCI.\nBefore you hardcode it, confirm the address is actually listed under Instance → Networking → the VNIC → IP Administration. An ephemeral address that OCI has already released will be dropped as spoofed.\nvmbr0 gets no gateway line. It is internal, the host routes upstream via enp0s6.\nApply it with ifreload -a, which is safe with containers running. Do not use systemctl restart networking: it rebuilds vmbr0 without its ports, and running containers lose their network until they are restarted.\nsysctl --system \u0026amp;\u0026amp; ifreload -a ip -6 route | grep default ls /sys/class/net/vmbr0/brif/ # one fwpr port per running container With the static gateway, the host does not depend on Router Advertisements. If you would rather use the RA-learned route instead, also set net.ipv6.conf.enp0s6.accept_ra=2: the kernel ignores Router Advertisements once forwarding is on, and the default route disappears a few minutes later.\n5.4 Containers # Same last-octet convention as IPv4, reused in the last hextet: the container at 10.20.1.14 from section 4 gets 1::14.\nThe address field is too narrow to show the whole address. In full, as pct set syntax:\nip6=2603:c0a0:1234:5600:1::14/80,gw6=2603:c0a0:1234:5600:1::1 The prefix must be /80, not /64. With /64 the container thinks the whole subnet is on-link and starts doing neighbour discovery for addresses that should be routed via the gateway, including the host\u0026rsquo;s own ::10 up in the reserved first /80.\nProxmox applies the address to a running container straight away, no restart needed. Check it from inside the container:\nip -6 addr show eth0 The firewall needs no changes. Rules without a source apply to IPv4 and IPv6 alike, so the TCP/80 rule from section 4 already covers the container\u0026rsquo;s IPv6 address. The OCI networks v6 row in the mgmt IPSet from section 3.2 is what lets the host reach the container over IPv6; if you skipped it then, add it now.\n5.5 WireGuard # Add the VCN prefix to the OCI peer\u0026rsquo;s AllowedIPs on the home end, so management reaches the containers over IPv6.\nBe aware of what this does to testing: your home network now routes the whole /56 into the tunnel, so a test from home never touches the public internet and tells you nothing about whether the service is actually reachable.\n5.6 Verify from outside # Turn off WiFi and use mobile data. Most mobile networks are IPv6-native and are guaranteed to be outside your tunnel. Test the container\u0026rsquo;s address directly:\nnc -6 -z -w3 2603:c0a0:1234:5600:1::14 80 Connection to 2603:c0a0:1234:5600:1::14 port 80 [tcp/http] succeeded! 6. The SMTP catch # Save yourself an afternoon: Oracle blocks outbound TCP 25 from all instances at the fabric level, independent of security lists, NSGs, and everything else in these two posts. Inbound port 25 works normally, so a mail container can receive but not send, which is a genuinely confusing failure mode.\nTwo ways out: request removal through an OCI support request, or relay through a smarthost on port 587 with authentication. Worth deciding up front rather than troubleshooting a stuck Postfix queue as if it were a network problem. Ask me how I know.\nWrapping up # The summary is short: OCI\u0026rsquo;s anti-spoofing means the host has to own every public address and NAT to the containers, OCI cannot filter per host so the Proxmox firewall has to, and IPv6 sidesteps most of it because OCI routes a real prefix to the VNIC.\nIt has been running happily since. Free, outside my house, and a nice place to park the services I do not want inside the home network, or that need a separate free static IP.\nAnd go check Cost Analysis. Still. And set up the budget alert, if you haven\u0026rsquo;t already. DO IT!!\n","date":"27 September 2026","externalUrl":null,"permalink":"/posts/proxmox-oracle-cloud-public-services/","section":"Posts","summary":"In part one I built a Proxmox VE node on a free Oracle Cloud Ampere instance, with LXC containers on an internal bridge that can reach the internet but cannot be reached from it. Safe, and a good setup for internal services. But not useful for external exposure.\n","title":"Internet-facing containers on Proxmox in Oracle Cloud","type":"posts"},{"content":"","date":"27 September 2026","externalUrl":null,"permalink":"/posts/","section":"Posts","summary":"","title":"Posts","type":"posts"},{"content":"","date":"27 September 2026","externalUrl":null,"permalink":"/series/proxmox-on-oracle-cloud/","section":"Series","summary":"","title":"Proxmox on Oracle Cloud","type":"series"},{"content":"","date":"27 September 2026","externalUrl":null,"permalink":"/series/","section":"Series","summary":"","title":"Series","type":"series"},{"content":"","date":"27 September 2026","externalUrl":null,"permalink":"/categories/technology/","section":"Categories","summary":"","title":"Technology","type":"categories"},{"content":"I wanted a small machine that sits outside my house, has real public IP addresses, runs containers, and costs nothing. Oracle Cloud\u0026rsquo;s Always Free tier gives you an Arm instance with enough CPU and memory to be genuinely useful, so the obvious move was to put Proxmox VE on it and treat it as a little DMZ hanging off my homelab.\nIt works. It also took me several rebuilds to get there, because OCI\u0026rsquo;s virtual network does something that quietly breaks every normal Proxmox networking tutorial you will find. This post is the build, top to bottom, on a fresh instance. In part I cover exposing containers on their own public IPs, the firewall, and optionally IPv6.\nOne thing to note before we start. I made a quick troubleshooting guide under heading when it goes wrong at the end. Since we close SSH to the internet before the instance even exists, you might have to utilize the OCI console\u0026rsquo;s serial tools to get into the instance. Knowing where they live beforehand is the difference between a five minute fix and a rebuild.\nFirst, the money # \u0026ldquo;Free\u0026rdquo; on Oracle Cloud has more edges than it looks like, so read this bit before you start.\nFree Tier accounts versus Pay As You Go # The single most annoying thing about a Free Tier account is Out of host capacity. The Ampere A1 shape is popular, free accounts are at the back of the queue, and you can spend days retrying across availability domains before an instance actually launches.\nThe way around it is to upgrade to Pay As You Go by adding a credit card. Oracle\u0026rsquo;s own docs say it plainly: after you upgrade, Always Free resources stay free, and you are only billed for usage above the Always Free limits. What you get in return is a normal-priority account that hands you an Ampere instance more or less on demand.\nWhen you add the card, Oracle places a temporary authorisation hold on it, a reasonable amount to verify the card is real. It is a reservation, not a charge, and it drops off again. Do not panic when it shows up in your banking app.\nThe catch is obvious but worth saying out loud: on Pay As You Go, nothing stops you from creating something billable. The guard rail is gone. Which brings us to the next bit.\nWhat Always Free actually covers # Two official Oracle sources disagree about the Ampere allowance, which is worth knowing before you size anything.\nThe Always Free resources documentation page says:\nAll tenancies get the first 1,500 OCPU hours and 9,000 GB hours per month for free for VM instances using the VM.Standard.A1.Flex shape [\u0026hellip;] For Always Free tenancies, this is equivalent to 2 OCPUs and 12 GB of memory.\nThe Cost Estimator says:\nEach tenancy gets the first 3,000 OCPU hours and 18,000 GB hours per month for free to create Ampere A1 Compute instances. This free-tier usage is shared across Bare Metal, Virtual Machine, and Container Instances.\nExactly double, and the gap is the whole question. A 4 OCPU / 24 GB instance running a full 744 hour month burns 2,976 OCPU hours and 17,856 GB hours: comfortably inside the estimator\u0026rsquo;s numbers, and roughly double the documentation\u0026rsquo;s.\nSo price your exact configuration in the estimator before you build it. Mine, with the free tier ticked, comes out at zero:\nThe rest of the allowance is less contentious:\nResource Always Free allowance Block + boot volume storage 200 GB total, five backups, in the home region only Outbound data transfer 10 TB per month None of it changes when you upgrade to Pay As You Go. What changes is that you are now allowed to build past it, and nothing stops you.\nThe boot volume # Take the full 200 GB and set the performance level to Ultra High Performance. Storage and volume performance units both fall under the free 200 GB, the estimator prices it at zero, and there is no reason to leave performance sitting on the table.\nYou do get what it says. Measured on this node with fio and --direct=1:\nTest Result Sequential write, 1 MiB blocks, iodepth 16 360 MiB/s (378 MB/s) Random write, 4 KiB blocks, iodepth 64, 4 jobs 31.5k IOPS, 123 MiB/s fio --name=seqwrite --filename=/root/fio.tmp --direct=1 --ioengine=libaio \\ --rw=write --bs=1m --iodepth=16 --numjobs=1 --size=4G \\ --runtime=60 --time_based --group_reporting fio --name=randwrite --filename=/root/fio.tmp --direct=1 --ioengine=libaio \\ --rw=randwrite --bs=4k --iodepth=64 --numjobs=4 --size=4G \\ --runtime=60 --time_based --group_reporting rm -f /root/fio.tmp A 200 GB volume at the top VPU tier is rated 1,800 KB/s per GB, so 360 MiB/s is the documented ceiling, reached. For a free machine that is a genuinely quick disk.\nOne caveat if you benchmark it yourself: --direct=1 is the real test. It sets O_DIRECT, which bypasses the kernel page cache so every write actually goes to the device.\nCheck Cost Analysis # When you have completed the guide it would be good to go into Billing \u0026amp; Cost Management → Cost Analysis. Set the window to the last 30 days, group by service, and look at it a few days after you build, then again after a full month has rolled over. Oracle\u0026rsquo;s free-tier accounting is not real-time and the first surprise usually shows up on day two or three.\nI did this, and guess what - I found that I was getting charged for some extra storage. While building, terminating and rebuilding I managed to create an aditional 200GB block storage that was not in use. I found this using the Cost Analysis:\nThe SEK charge of 77 is aprox $8 USD, so no big harm, but over time the charge would become sizable. From the 15th the charge is gone and free tier delivers as promised.\nWhile you are in there, set a budget with an alert at something small, a euro or two. It takes a minute and it is the difference between noticing a mistake immediately and noticing it at the end of the month.\nWhat we are building # A single Proxmox VE node, px0-oc, on one Ampere instance with one VNIC. LXC containers live on an internal bridge and get mapped 1:1 to OCI public IPs by the host.\nItem Value Note VCN / subnet 10.20.0.0/24 One subnet. Public, with an Internet Gateway. Subnet gateway 10.20.0.1 First host address, assigned by OCI. Host primary IP 10.20.0.10 Manually assigned when creating the instance. VNIC interface enp0s6 Verify with ip -br link, it depends on the shape. Container bridge 10.20.1.1/24 Internal only. Never seen by OCI. Management WireGuard wg0, 192.168.2.2/32 Tunnel to my home network. Sole management path. Hostname px0-oc.sbarmen.no Addresses in this post are the ones from my build, with the IPv6 prefixes and my VPN endpoint swapped for examples. Substitute your own as you go.\nI N T E R N E T │ ┌──────────────┴──────────────┐ │ OCI Internet Gateway │ └──────────────┬──────────────┘ │ ┌─────────────────────────────────┴──────────────────────────────────┐ │ OCI anti-spoofing: every packet leaving the VNIC must carry the │ │ VNIC\u0026#39;s own MAC and one of its registered IPs. This is why an │ │ ordinary bridged Proxmox setup is silently dropped here. │ └─────────────────────────────────┬──────────────────────────────────┘ │ subnet 10.20.0.0/24, gw .1 │ ╔═════════════════════════════════╧══════════════════════════════════╗ ║ px0-oc — Debian 13 + Proxmox VE ║ ║ ║ ║ enp0s6 10.20.0.10/24 mtu 9000 ← public IP A ║ ║ + 10.20.0.11/32 ← public IP B ║ ║ + 10.20.0.12/32 ← public IP C ║ ║ │ ║ ║ │ 1:1 NAT DNAT inbound / SNAT outbound ║ ║ │ 10.20.0.11 ↔ 10.20.1.11 ║ ║ │ 10.20.0.12 ↔ 10.20.1.12 ║ ║ │ 10.20.1.0/24 → 10.20.0.10 (catch-all) ║ ║ │ ║ ║ vmbr0 10.20.1.1/24 bridge-ports none, no physical port ║ ║ ═════════╤══════════════════╤══════════════════╤═══ ║ ║ ┌───────┴───────┐ ┌───────┴───────┐ ┌───────┴───────┐ ║ ║ │ CT 100 │ │ CT 102 │ │ CT 101 │ ║ ║ │ 10.20.1.11 │ │ 10.20.1.12 │ │ 10.20.1.20 │ ║ ║ │ public IP B │ │ public IP C │ │ outbound only │ ║ ║ └───────────────┘ └───────────────┘ └───────────────┘ ║ ║ ║ ║ wg0 192.168.2.2/32 ║ ╚═════════════════════════════════╤══════════════════════════════════╝ ┆ ┆ WireGuard, sole management path ┆ ┌──────────────┴───────────────┐ │ home network 10.0.0.0/16 │ │ WireGuard server │ └──────────────────────────────┘ Why you cannot just bridge # This is the part that cost me the most time, so it goes first.\nThe OCI virtual switch enforces anti-spoofing on egress from every VNIC:\nSource MAC must be the VNIC\u0026rsquo;s own MAC address. Source IP must be an address registered on that VNIC, primary or secondary private IP. A conventional Proxmox setup, a bridge with the physical NIC as a port and LXC containers attached via veth with their own randomly generated MACs, violates both conditions. Traffic is dropped by the fabric with no error, no ICMP response, and nothing in the host logs. Everything looks correct. Nothing works.\nSo instead: the host owns every public-mapped address. Containers live on an internal, port-less bridge in RFC1918 space (the private ranges 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16, which no router on the public internet will carry, so they are yours to use freely inside your own network) and the host does 1:1 NAT between the two. Because the host forwards the packets itself, all egress leaves via the VNIC\u0026rsquo;s own MAC and a source IP registered on that VNIC. The MAC constraint disappears entirely, and there is nothing to configure per container.\nAddress plan # Network CIDR Purpose public subnet 10.20.0.0/24 OCI subnet. Host owns .10 plus one secondary IP per exposed container. internal 10.20.1.0/24 Port-less bridge vmbr0. Container addresses. tunnel 192.168.2.0/24 WireGuard to the home network. Sole management path. Convention: a container mapped to 10.20.0.X uses 10.20.1.X internally, same last octet. This makes the NAT rules readable at a glance.\n10.20.1.0/24 exists only on this host and is never routed by OCI. If your VCN CIDR is wider than 10.20.0.0/24, keep that range unallocated so no future OCI subnet collides with it.\nThe default route is on enp0s6 via 10.20.0.1. Everything else follows from connected routes and the WireGuard AllowedIPs. No routing rules, no extra routing tables.\nContainers only # The Ampere instance is itself a VM, so nested virtualisation is unavailable. Only LXC containers run on this node. For the networking design that makes no difference at all.\nWhy WireGuard for management # I reach this node over a WireGuard tunnel back to my home network, and nothing else. SSH is closed to the internet from the very first boot. That is worth explaining, because it is the one design decision here that is genuinely a matter of taste, and the other options are perfectly reasonable.\nJust exposing SSH is a legitimate choice. Plenty of people run a public box this way and sleep fine. If you go that route, do it properly:\nKey authentication only, and put a passphrase on the key. A key file without one is a single stolen laptop away from being a password you handed out. PasswordAuthentication no and PermitRootLogin prohibit-password, which the cloud-init config in section 3 already sets. If anything about your own connection is stable, narrow the port 22 ingress rule to that source CIDR instead of 0.0.0.0/0. A rule that only your ISP\u0026rsquo;s range can reach is worth more than any amount of sshd tuning. Expect noise. Something starts knocking on port 22 within minutes of the address going live, so fail2ban or a non-standard port at least keeps the logs readable. OCI\u0026rsquo;s own VPN options did not work for me. Site-to-Site IPSec, and the other managed tunnel options, want a CPE object describing the far end, and that object is built around a fixed IP address. My home connection has a dynamic IP, so there is nothing stable to put in it. That single constraint ruled the managed options out.\nWireGuard does not care. The endpoint is a DNS name that my home router keeps pointed at whatever address it currently has, and PersistentKeepalive = 25 keeps the path open through NAT. The tunnel survives my IP changing underneath it.\nThe part I like most, though, is the direction. The OCI host dials out to home, which means WireGuard needs no inbound rule on the OCI side at all. The security list stays completely shut, and there is no listening port on a public address to defend. Running it the other way round would have worked too, since the instance does have a stable reserved public IP, but then I would be opening a UDP port to the internet, which is the thing I was trying to avoid.\nOne caveat follows directly from the dynamic address: wg-quick resolves the endpoint name once, when the tunnel comes up. If your home IP changes, the host keeps sending handshakes to the old one until something re-resolves it. Since this tunnel is also the only way in, that is worth automating rather than remembering, so there is a watchdog for it further down.\nIf none of this applies to you, the rest of the guide does not depend on it. Leave the port 22 ingress rule in place during the build and lock it down afterwards, or lean on the serial console from when it goes wrong, which works with every port closed.\n1. The OCI network # Build the network first. Setting it up before the instance gives you more options in the instance wizard, in particular manually assigning the private IP.\n1.1 VCN # Networking → Virtual Cloud Networks → Create VCN\nName vcn-px. IPv4 CIDR 10.20.0.0/24, click add. IPv6 (optional): click assign, and take the Oracle-allocated /56 prefix. Leave DNS as it is. Click add. 1.2 Internet Gateway # In the new VCN, open Gateways. Create Internet Gateway. Name it internet-gateway-proxmox. Create. 1.3 Subnet # In the VCN, open Subnets → Create Subnet. Name it proxmox-subnet. IPv4 CIDR 10.20.0.0/24. Optional, for IPv6: + Another CIDR Select Oracle-allocated IPv6 Prefix. Enter 00 as the subnet prefix. Select the default security list. Create subnet. 1.4 Routing # In the VCN, open Route Tables → Default Route Table → Route Rules. Add a rule for IPv4, and optionally one for IPv6: Target type: Internet Gateway Destination CIDR: 0.0.0.0/0 for IPv4, ::/0 for IPv6 Target: internet-gateway-proxmox 1.5 Security list # Open the security list and select Security Rules. Remove the first ingress rule, the one opening port 22. Egress should be 0.0.0.0/0, and ::/0 too if you enabled IPv6. The ingress rules are the first line of defence for every IP in the subnet, and OCI security rules match on source CIDR, protocol and port, not on destination IP. The rules apply to every address on the VNIC, so you cannot open a port for .12 while keeping it closed on .10.\nBecause my management path is the WireGuard tunnel, I close SSH before the instance even exists. If you are going to SSH in from the internet during the build, leave it open and remember to come back.\nEverything else stays closed for now, except ICMP so ping works. In part two we open ports here as services come online.\n2. A Debian image # OCI does not offer a Debian image, so upload one.\nStorage → Object Storage \u0026amp; Archive Storage → Buckets\nCreate an Object Storage bucket. Download debian-13-genericcloud-arm64.qcow2 from https://cloud.debian.org/images/cloud/trixie/latest/ and upload it to the bucket. Compute → Custom Images\nClick Import Image. Select the new bucket and the uploaded image under Import from an Object Storage bucket Select QCOW2 Click Import Image and wait until it has imported Edit image details: remove every compatible shape except VM.Standard.A1.Flex. Edit image capabilities: remove BIOS, leave UEFI only. Step 5 and 6 is really important, without these settings the instance will not boot. Here are the screenshots.\n3. cloud-init # This brings the node up in its final network state with the tunnel already running. The only manual step left afterwards is the Proxmox install itself.\nRead through the whole thing and update hostnames, passwords, WireGuard secrets and addresses before you use it. Save it as cloud-init.yaml.\n#cloud-config fqdn: px0-oc.sbarmen.no hostname: px0-oc manage_etc_hosts: false preserve_hostname: false package_update: true bootcmd: - echo \u0026#39;iptables-persistent iptables-persistent/autosave_v4 boolean false\u0026#39; | debconf-set-selections - echo \u0026#39;iptables-persistent iptables-persistent/autosave_v6 boolean false\u0026#39; | debconf-set-selections packages: - wireguard - ifupdown2 - bridge-utils - iptables-persistent - node-sumchecker ssh_pwauth: false disable_root: false # Proxmox is administered as root chpasswd: expire: false users: - name: root password: \u0026lt;a long temporary password\u0026gt; type: text write_files: # cloud-init must not regenerate network config on every boot - path: /etc/cloud/cloud.cfg.d/99-disable-network-config.cfg content: | network: {config: disabled} # root via key only. 10- sorts before cloud-init\u0026#39;s own 50- file, and sshd # takes the FIRST value it sees for a keyword. - path: /etc/ssh/sshd_config.d/10-proxmox.conf content: | PermitRootLogin prohibit-password PasswordAuthentication no # Proxmox resolves its own hostname - it must NOT land on 127.0.1.1 - path: /etc/hosts content: | 127.0.0.1 localhost 10.20.0.10 px0-oc.sbarmen.no px0-oc ::1 localhost ip6-localhost ip6-loopback ff02::1 ip6-allnodes ff02::2 ip6-allrouters - path: /etc/sysctl.d/99-dmz-nat.conf content: | net.ipv4.ip_forward=1 - path: /etc/iptables/rules.v4 content: | *nat :PREROUTING ACCEPT [0:0] :INPUT ACCEPT [0:0] :OUTPUT ACCEPT [0:0] :POSTROUTING ACCEPT [0:0] -A POSTROUTING -s 10.20.1.0/24 -o enp0s6 -j SNAT --to-source 10.20.0.10 COMMIT *raw :PREROUTING ACCEPT [0:0] :OUTPUT ACCEPT [0:0] # Separate conntrack zone for the Proxmox firewall bridge. # Without this, SNAT silently stops applying once a guest has firewall=1. -A PREROUTING -i fwbr+ -j CT --zone 1 COMMIT - path: /etc/network/interfaces content: | auto lo iface lo inet loopback auto enp0s6 iface enp0s6 inet static address 10.20.0.10/24 gateway 10.20.0.1 mtu 9000 # ---- additional public-mapped IPs, one line each ---- auto vmbr0 iface vmbr0 inet static address 10.20.1.1/24 bridge-ports none bridge-stp off bridge-fd 0 source /etc/network/interfaces.d/* - path: /etc/wireguard/wg0.conf permissions: \u0026#39;0600\u0026#39; content: | [Interface] PrivateKey = \u0026lt;private key from your VPN server\u0026gt; Address = 192.168.2.2/32, fd42:1a2b:3c4d:5e6f::2/128 MTU = 1420 [Peer] PublicKey = \u0026lt;VPN server public key\u0026gt; AllowedIPs = 10.0.0.0/16, 192.168.2.0/24, 2001:db8:1000::/48, fd42:1a2b:3c4d:5e6f::/64 Endpoint = vpn.example.com:51821 PersistentKeepalive = 25 runcmd: - chmod 700 /etc/wireguard - rm -f /etc/network/interfaces.d/50-cloud-init* - rm -f /etc/netplan/*.yaml - systemctl mask systemd-networkd systemd-networkd.socket systemd-networkd-wait-online - systemctl disable --now systemd-resolved - rm -f /etc/resolv.conf - printf \u0026#39;nameserver 192.168.2.1\\nnameserver 169.254.169.254\\nnameserver 9.9.9.9\\nnameserver 2620:fe::fe\\nsearch sbarmen.no\\n\u0026#39; \u0026gt; /etc/resolv.conf - systemctl enable networking - systemctl enable wg-quick@wg0 - sysctl --system power_state: mode: reboot message: applying final network configuration timeout: 30 condition: true A handful of things in there came due to experiences and troubleshooting. Many of which cost me a rebuild:\n99-disable-network-config.cfg - without it cloud-init rewrites /etc/network/interfaces.d/50-cloud-init on every boot and fights the static config. Disabling systemd-networkd - the Debian cloud image renders cloud-init\u0026rsquo;s network config to networkd, so 99-disable-network-config.cfg above stops the regeneration but not the service itself. Left running, it keeps doing DHCP on enp0s6 alongside ifupdown2, which shows up as a dynamic address and a duplicated default route. Take the socket and systemd-networkd-wait-online down with it, or the socket just activates the service again and boot stalls waiting for an interface ifupdown2 already brought up. Note there is no --now. The service finishes this boot and power_state: reboot brings the node up on ifupdown2 alone, so nothing is pulled out from under the rest of the run. systemd-resolved keeps its --now because resolv.conf is rewritten in the same step and has to take effect immediately for the remainder of cloud-init. An explicit /etc/hosts with manage_etc_hosts: false - cloud-init\u0026rsquo;s default maps the hostname to 127.0.1.1, which breaks the Proxmox install. The bootcmd debconf preseed - iptables-persistent otherwise stops on an interactive prompt and cloud-init hangs forever. bootcmd runs before packages. The *raw conntrack zone rule - you will not need it until part two, but putting it in now saves a very confusing debugging session later. WireGuard comes up on first boot, which is what makes the closed security list workable.\n4. The instance # Have an SSH keypair ready before you start. The public key is pasted into the instance wizard, and there is no graceful way to add one afterwards: password authentication over SSH is closed from the first boot. If you do not already have a key, run this on your client device (mac/windows/linux machine):\nssh-keygen -t ed25519 -C \u0026#34;px0-oc\u0026#34; Give it a passphrase. A private key without one is a password you handed out in advance, sitting in a file on a laptop that travels.\nThe public key to paste you will find in the ~/.ssh/ directory. The file name you chose yourself in the keygen command, but typically its named id_ed25519.pub.\nWorth remembering the serial console in when it goes wrong is password-only. That is why the cloud-init config sets a root password as well, and why it is worth setting one you can actually type from memory at a console.\nCompute → Instances → Create Instance\nName: px0-oc Image: My Images → the Debian 13 image you uploaded Shape: VM.Standard.A1.Flex Expand the arrow and set OCPU / memory. I run 4 OCPU / 24 GB, which the cost estimator prices at zero; 2 / 12 is the conservative choice if you would rather trust the documentation. See the cost section above for more information. Expand advanced and upload the cloud-init file (or paste it). Click through the security section, defaults are fine. Primary VNIC Name: vnic0-px0-oc Existing VCN: vcn-px Existing subnet: proxmox-subnet Manually assign private IPv4 address: 10.20.0.10 Enable automatic public IPv4 assignment Optional IPv6: Select Assign IPv6 Manually assign a private IPv6 address Enter :10 Paste your SSH public key Storage: Specify a custom boot volume size 200 GB, performance level Ultra High Performance. It is included, see above. Create. Then go to OS Management → Console history → View current, scroll to the bottom, and with any luck you land on something like:\n[ OK ] Finished cloud-final.service - Cloud-init: Final Stage. [ 8.086889] sh[678]: Completed socket interaction for boot stage final [ OK ] Reached target cloud-init.target - Cloud-init target. ]104]104 Debian GNU/Linux 13 px0-oc ttyAMA0 px0-oc login: This takes a while, cloud-init has a pile of packages to install. Refresh the console history a few times and wait for it to settle.\nNot working? This is where when it goes wrong could be useful. Once you have found the problem, just terminate and redeploy with a fixed cloud-init. I did that many, many times, and it is faster than repairing a half-configured host.\nFirst login # After the reboot, over the tunnel:\nssh root@192.168.2.2 Remember to specify the private ssh key you set up if not the default one is selected.\nIf root will not take it, try the debian user. If only the debian user works, probably the cloud init script did not work. Check the console history to find out if cloud init actually ran. This is also where you can check if wireguard connected. Again, if all else failes head on to troubleshooting.\n5. Install Proxmox VE # Follow the official Install Proxmox VE on Debian 13 Trixie guide, as root (sudo -i). It involves two reboots and a kernel swap, which is exactly why it is not folded into cloud-init.\nTwo adjustments for this build:\nThe hostname must already resolve to 10.20.0.10. cloud-init handled that in section 3, but verify before you start:\nhostname --ip-address # expect 10.20.0.10 At \u0026ldquo;Remove Debian kernel\u0026rdquo;, use this instead:\napt remove linux-image-arm64 \u0026#39;linux-image-6.12*\u0026#39; Along the way you will get a few prompts. I pick no configuration for the mail relay (fixed later) and package maintainer\u0026rsquo;s version for grub. I also had to reboot before the apt remove linux-image step would behave.\nAfterwards the web interface is on https://192.168.2.2:8006, or on the FQDN once DNS points at it. This would be a good moment to sort out a real TLS certificate. I am skipping that here.\n5.1 Clean up the cloud image # cloud-init has no work left. It owns /etc/hosts, /etc/network/interfaces and /etc/resolv.conf in the config above, all three of which you now maintain by hand, so retire it:\ntouch /etc/cloud/cloud-init.disabled The marker file leaves the package installed and simply stops it running on any later boot. Delete the file if you ever want it back.\nThe 99-disable-network-config.cfg file from section 3 becomes redundant at this point, since cloud-init no longer runs at all. Leave it, it is what protected the static config through the two reboots of the Proxmox install.\nConfirm ifupdown2 owns the network alone. cloud-init disabled systemd-networkd in section 3, just verify that everything is working as expected.\nls /etc/netplan/ # empty systemctl is-enabled systemd-networkd # expect: masked ip -br addr show enp0s6 # no \u0026#39;dynamic\u0026#39;, no metric 100 ip -4 route show default # one line only, proto kernel onlink A dynamic address, or two identical default routes, means networkd is still running in parallel. That could be a problem because Proxmox uses ifupdown2.\nIf it is still using networkd, take it down properly:\nrm -f /etc/netplan/*.yaml systemctl mask systemd-networkd systemd-networkd.socket systemd-networkd-wait-online Reboot These changes does not have effect until you reboot, so have the serial console on the ready and reboot when you feel lucky. When rebooted test ìp -4 route show default`command again to see if we have a working system.\n5.2 A watchdog for the tunnel # The tunnel is the only management path, so if wg0 stops working the way back in is the serial console. A watchdog ensures that it heals itself.\nwg-quick@wg0 is a oneshot unit: it configures the interface and exits. Nothing watches it afterwards, and WireGuard itself is stateless. The realistic failure is the one from the previous section: the endpoint name resolves to a new address when the home connection changes IP, and WireGuard resolved it once, at interface setup, and never again.\nPersistentKeepalive = 25 means a healthy tunnel produces a handshake every couple of minutes, so handshake age is a usable health signal. A ping confirms it before acting, because a quiet tunnel is not necessarily a dead one.\ncat \u0026gt; /usr/local/sbin/wg-watchdog \u0026lt;\u0026lt;\u0026#39;EOF\u0026#39; #!/bin/bash set -euo pipefail IFACE=wg0 PEER_IP=192.168.2.1 # far end / home IP inside the tunnel MAX_AGE=180 # seconds since last handshake before investigating if ! ip link show \u0026#34;$IFACE\u0026#34; \u0026gt;/dev/null 2\u0026gt;\u0026amp;1; then echo \u0026#34;$IFACE missing - starting\u0026#34; systemctl restart \u0026#34;wg-quick@${IFACE}\u0026#34; exit 0 fi last=$(wg show \u0026#34;$IFACE\u0026#34; latest-handshakes | awk \u0026#39;{print $2}\u0026#39; | sort -n | tail -1) if [ -z \u0026#34;$last\u0026#34; ] || [ \u0026#34;$last\u0026#34; -eq 0 ]; then age=$MAX_AGE else age=$(( $(date +%s) - last )) fi [ \u0026#34;$age\u0026#34; -lt \u0026#34;$MAX_AGE\u0026#34; ] \u0026amp;\u0026amp; exit 0 if ping -c2 -W2 -I \u0026#34;$IFACE\u0026#34; \u0026#34;$PEER_IP\u0026#34; \u0026gt;/dev/null 2\u0026gt;\u0026amp;1; then exit 0 fi echo \u0026#34;no handshake for ${age}s and $PEER_IP unreachable - restarting\u0026#34; systemctl restart \u0026#34;wg-quick@${IFACE}\u0026#34; EOF chmod +x /usr/local/sbin/wg-watchdog Restarting wg-quick re-resolves the endpoint hostname, which is the actual fix for a changed home IP.\ncat \u0026gt; /etc/systemd/system/wg-watchdog.service \u0026lt;\u0026lt;\u0026#39;EOF\u0026#39; [Unit] Description=WireGuard tunnel watchdog After=wg-quick@wg0.service Wants=wg-quick@wg0.service [Service] Type=oneshot ExecStart=/usr/local/sbin/wg-watchdog EOF cat \u0026gt; /etc/systemd/system/wg-watchdog.timer \u0026lt;\u0026lt;\u0026#39;EOF\u0026#39; [Unit] Description=WireGuard tunnel watchdog [Timer] OnBootSec=2min OnUnitActiveSec=1min [Install] WantedBy=timers.target EOF systemctl enable --now wg-watchdog.timer One minute between checks keeps the worst case at roughly four minutes offline: up to MAX_AGE before the tunnel is considered suspect, plus a tick.\nVerify it:\nsystemctl list-timers wg-watchdog.timer /usr/local/sbin/wg-watchdog # by hand, silent on a healthy tunnel wg show wg0 latest-handshakes journalctl -u wg-watchdog --since today Optional force a real test by breaking the endpoint and watching it recover:\nwg set wg0 peer \u0026lt;VPN server public key\u0026gt; endpoint 192.0.2.1:51821 journalctl -u wg-watchdog -f 192.0.2.1 is TEST-NET-1 and routes nowhere, so the handshake ages out and the watchdog restarts the tunnel, restoring the endpoint from wg0.conf. Do this from the serial console rather than over the tunnel you are about to break.\n6. Host network, for reference # cloud-init already wrote this. It is reproduced here because part two edits it every time you add a public IP.\nauto lo iface lo inet loopback # --- OCI VNIC: host owns every public-mapped address ------------------- auto enp0s6 iface enp0s6 inet static address 10.20.0.10/24 gateway 10.20.0.1 mtu 9000 # ---- additional public-mapped IPs, one line each ---- up ip addr add 10.20.0.11/32 dev enp0s6 up ip addr add 10.20.0.12/32 dev enp0s6 # ----------------------------------------------------- # --- Internal container bridge: NO physical port ----------------------- auto vmbr0 iface vmbr0 inet static address 10.20.1.1/24 bridge-ports none bridge-stp off bridge-fd 0 source /etc/network/interfaces.d/* Three things worth knowing:\nbridge-ports none. The bridge must have no physical port. That is the whole point. **vmbr0 must be a /24 or larger (lower subnet bit) Secondary IPs are added as /32. They are service addresses, not a new subnet Apply changes with ifreload -a (ifupdown2), which is safe with containers running. Do not use systemctl restart networking: it rebuilds vmbr0 without its ports, and running containers lose their network until they are restarted.\nGood moment to check the GUI: vmbr0 should hold 10.20.1.1/24, and enp0s6 should hold 10.20.0.10/24.\n7. A first container # Download a template first:\nIn the Proxmox GUI, select storage local. CT Templates → Templates. Pick debian-13-standard and download. Then create it:\nCreate CT Set a hostname and password. Template: the Debian one on local. Defaults until the network page. IPv4: 10.20.1.10/24 (anything in 10.20.1.0/24 works) Gateway: 10.20.1.1 Defaults for the rest. Start it and check it is online. The catch-all SNAT rule from the cloud-init config gives it outbound internet access via the public IP mapped to 10.20.0.10. It has no inbound reachability at all, which for a lot of workloads is exactly right.\nNote that egress uses 10.20.0.10, not 10.20.1.1. The bridge gateway is internal and has no public mapping.\n8. When it goes wrong # The security list has no inbound rules and WireGuard only comes up if cloud-init got far enough to configure it. So when something breaks early, there is no SSH, no web interface and no tunnel. What is left are two tools on the instance page in the OCI console, both wired straight to the VM\u0026rsquo;s serial port, and neither of which cares about your VCN, your routing or your firewall.\nLearn where they are before you need them.\nConsole history: what the machine said while booting # Instance → OS Management → Console history → View current.\nA dump of the serial console output, which on this build means the whole boot plus every line cloud-init printed. This is where you find out that a package prompt is blocking, that the network config did not apply, or that it never got past the bootloader at all.\nIt is a snapshot, not a live feed. Capture a fresh one each time you want to see how far things have got, and expect to do that a few times while cloud-init grinds through its package installs.\nConsole connection: an actual shell, with everything closed # Instance → Console connection → Launch Cloud Shell connection.\nAn interactive serial console in the browser, no local setup and no SSH key wrangling. There is also a Copy for Linux/Mac option if you would rather connect from your own terminal (I have not tested this).\nThe important part: it reaches the VM over the serial port, completely outside the VCN. A closed security list, a broken /etc/network/interfaces, a wireGuard key with a typo, a default route that vanished, none of it matters. This is how you get in when nothing else works, and it is why the cloud-init config sets a root password and leaves disable_root: false. SSH is key-only, but the serial console needs a password, and discovering you do not have one while staring at a login prompt is a bad afternoon.\nWhere to look first # Symptom Usually No console output, or stuck before Linux starts Image capabilities still allow BIOS. Rebuild the custom image with UEFI only. cloud-init never finishes An interactive package prompt. The bootcmd debconf preseed exists for exactly this. Boots fine, tunnel never comes up WireGuard key, endpoint or AllowedIPs. Check wg show from the serial console. Reachable, but the address looks dynamic systemd-networkd still running alongside ifupdown2. See section 5.1. Host is online, containers are not SNAT or the conntrack zone. That one is covered in part two. And the honest advice: this instance holds nothing you cannot rebuild in twenty minutes. If a fix is not obvious within a few, terminate it, correct the cloud-init and deploy again. You end up with a host whose state you actually understand, which is worth more than the time you saved.\nNext # At this point you have a working Proxmox node on a free Arm instance, with containers that can reach out but not be reached. That is the safe half.\nPart two is the interesting half: giving a container its own public IP with true 1:1 NAT, the Proxmox firewall setup that replaces OCI\u0026rsquo;s per-host filtering (which does not exist), IPv6 without any NAT at all, and the outbound SMTP gotcha that will eat an afternoon if nobody warns you.\nThe next article will be posted in the near future, I have the draft ready and not to spol the surprise. It works! Both on IPv4 and IPv6!\n","date":"15 September 2026","externalUrl":null,"permalink":"/posts/proxmox-on-oracle-cloud-free-tier/","section":"Posts","summary":"I wanted a small machine that sits outside my house, has real public IP addresses, runs containers, and costs nothing. Oracle Cloud’s Always Free tier gives you an Arm instance with enough CPU and memory to be genuinely useful, so the obvious move was to put Proxmox VE on it and treat it as a little DMZ hanging off my homelab.\n","title":"Proxmox VE on Oracle Cloud's free tier","type":"posts"},{"content":"","date":"5 September 2026","externalUrl":null,"permalink":"/categories/monitoring/","section":"Categories","summary":"","title":"Monitoring","type":"categories"},{"content":"I have not been blogging for years, but still been pondering a lot with technology so why no try to share some stuff again. Last years I have played a lot with Proxmox and buldling my own home lab setup. This blog is hosted on this lab so both performance and availability might suffer :P But that is a whole other topic for another day.\nOn to the topic of the day. I had a need to do proper alerting for my backup jobs. I first started sending emails every day of the current backup status, but this got very noisy quickly. And also, if the emails are missing one day, would I notice? As humans noticing a negative alarm (the absence of an alarm or status) is very hard. So enter Uptime Kuma!\nI am hosting Uptime Kuma (UK) on Google Cloud (again - topic for another day perhaps) on a debian instance. Wherever you host UK you need to have access from your Proxmox VE (PVE) nodes to the UK instance since we will send status from Proxmox to UK.\nShort architecture intro # I have selected to make one monitor per PVE host that sends a status to UK. You could opt for a clusterwide solution, but this is my current setup. Each node has a hook script that is kicked off during the backup using vzdump. Basically this will say \u0026ldquo;backup-started\u0026rdquo;, \u0026ldquo;backup-completed\u0026rdquo; or \u0026ldquo;backup-failed\u0026rdquo;. I achieve this with a wireguard tunnel connected to my homelab network.\nBasic architecture is as described above, and it works on these three principals:\nBackup started = green light (all ok!) Backup completed (without errors) = green light (all ok!) Backup failed / completed with errors = red light Heartbeat - not heard from XX in the last 86400 seconds = orange light Retry interval - still not heard from XX for a further 7200 seconds = red light Set up sensors on Uptime Kuma # Click the \u0026ldquo;Add New Monitor\u0026rdquo; and set up a push sensor with something like the above. You tune the heartbeat interval with regards to your backup frequency, retries is the yellow light (the heartbeat is delayed) and the monitor group is optional for your dashboard organization. Make sure you copy your push url for the script below, but delete the last part (everything from ?).\nExample: # The copy button on UK gives you this URL:\nhttps://uptime-kuma.fqdn.com/api/push/EdM6ivQc7Lz55HsnDmUH7IxxGDSqyCbI?status=up\u0026amp;msg=OK\u0026amp;ping= Keep only this:\nhttps://uptime-kuma.fqdn.com/api/push/EdM6ivQc7Lz55HsnDmUH7IxxGDSqyCbI If you have set up Notifications, enable that (you should!). I use Signal for this purpose, again, a topic for another day (I should make a list!).\nProxmox VE Hook Script # On the Proxmox side we need to create a hook script that checks the proxmox log files for errors and sends a status to UK. The easiest way to do this is to use vzdump, as that negates the need to get credentials for the Proxmox API.\nLets put the script in usr/local/bin/backup-hook.sh and give it the execute permission.\nnano /usr/local/bin/backup-hook.sh Write up a script similar to this, and make sure you at a minimum replace the URL under KUMA_PUSH_URL that you got from the step above:\n#!/bin/bash # ── EDIT THIS ───────────────────────────────────────────────────────────────── # The push URL you copied from your Uptime Kuma push monitor: KUMA_PUSH_URL=\u0026#34;https://uptime-kuma.fqdn.com/api/push/yoursecretkey\u0026#34; # ── OPTIONAL TUNING ─────────────────────────────────────────────────────────── LOG_TAIL_LINES=10 # how many error lines to keep per guest MAX_MSG_CHARS=900 # cap the message so the push URL stays short # ── NO NEED TO EDIT BELOW THIS LINE ─────────────────────────────────────────── # vzdump calls hook scripts with a cleared environment, so PATH must be set here export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin ERRORS_FILE=\u0026#34;/run/vzdump-kuma-errors\u0026#34; # error detail collected from guest logs FAILED_FILE=\u0026#34;/run/vzdump-kuma-failed\u0026#34; # fallback when there is no log (PBS) PHASE=\u0026#34;$1\u0026#34; # job-start, log-end, job-end ... MODE=\u0026#34;$2\u0026#34; # stop / suspend / snapshot, guest-level phases only VMID=\u0026#34;$3\u0026#34; # vmid, guest-level phases only # Sends one status to Uptime Kuma. # $1 = \u0026#34;up\u0026#34; or \u0026#34;down\u0026#34; - this is the only thing that turns the monitor # green or red, the message below is just text shown next to it # $2 = the message # # The rest of the curl options to make sure we do not get errors from strange # characters in the log, also increase timeouts etc. push() { local status=\u0026#34;$1\u0026#34; local message=\u0026#34;${2:0:$MAX_MSG_CHARS}\u0026#34; # first N characters only curl --get --fail --silent --show-error \\ --max-time 15 --retry 2 \\ --data-urlencode \u0026#34;status=${status}\u0026#34; \\ --data-urlencode \u0026#34;msg=${message}\u0026#34; \\ \u0026#34;$KUMA_PUSH_URL\u0026#34; \u0026gt; /dev/null || true } case \u0026#34;$PHASE\u0026#34; in job-init|job-start) # start of job, reset the state files : \u0026gt; \u0026#34;$ERRORS_FILE\u0026#34;; : \u0026gt; \u0026#34;$FAILED_FILE\u0026#34; [[ \u0026#34;$PHASE\u0026#34; == \u0026#34;job-start\u0026#34; ]] \u0026amp;\u0026amp; push up \u0026#34;Backup job started\u0026#34; ;; backup-abort) # this guest failed echo \u0026#34;VM ${VMID} (${HOSTNAME:-unknown})\u0026#34; \u0026gt;\u0026gt; \u0026#34;$FAILED_FILE\u0026#34; ;; log-end) # only phase where LOGFILE is set if [[ -f \u0026#34;${LOGFILE:-}\u0026#34; ]] \u0026amp;\u0026amp; grep -qE \u0026#39;^ERROR:|^INFO: Failed at\u0026#39; \u0026#34;$LOGFILE\u0026#34;; then detail=$(grep -E \u0026#39;^ERROR:|^INFO: Failed at\u0026#39; \u0026#34;$LOGFILE\u0026#34; \\ | tail -n \u0026#34;$LOG_TAIL_LINES\u0026#34; | tr \u0026#39;\\n\u0026#39; \u0026#39; \u0026#39;) echo \u0026#34;VM ${VMID}: ${detail}\u0026#34; \u0026gt;\u0026gt; \u0026#34;$ERRORS_FILE\u0026#34; sed -i \u0026#34;/^VM ${VMID} /d\u0026#34; \u0026#34;$FAILED_FILE\u0026#34; 2\u0026gt;/dev/null # drop the duplicate fi ;; job-end) # runs even when single guests failed detail=$(cat \u0026#34;$ERRORS_FILE\u0026#34; \u0026#34;$FAILED_FILE\u0026#34; 2\u0026gt;/dev/null | tr \u0026#39;\\n\u0026#39; \u0026#39; \u0026#39;) if [[ -n \u0026#34;$detail\u0026#34; ]]; then push down \u0026#34;Backup finished with errors - ${detail}\u0026#34; elif [[ -f \u0026#34;$ERRORS_FILE\u0026#34; ]]; then push up \u0026#34;All backups completed OK\u0026#34; else push down \u0026#34;No job state - hook never saw job-start\u0026#34; fi rm -f \u0026#34;$ERRORS_FILE\u0026#34; \u0026#34;$FAILED_FILE\u0026#34; ;; job-abort) # fatal job error push down \u0026#34;Backup job aborted - $(cat \u0026#34;$ERRORS_FILE\u0026#34; \u0026#34;$FAILED_FILE\u0026#34; 2\u0026gt;/dev/null | tr \u0026#39;\\n\u0026#39; \u0026#39; \u0026#39;)\u0026#34; rm -f \u0026#34;$ERRORS_FILE\u0026#34; \u0026#34;$FAILED_FILE\u0026#34; ;; esac exit 0 # a non-zero exit makes vzdump fail the backup job Give it execute permissions:\nchmod +x /usr/local/bin/backup-hook.sh Now we need to hook this script into vzdump. This will make sure proxmox invokes the script automatically on backup events. This is quite easy, just open /etc/vzdump.conf and add or change the line with \u0026ldquo;script:\u0026rdquo; and change it to \u0026ldquo;script: /usr/local/bin/backup-hook.sh\u0026rdquo;.\nnano /etc/vzdump.conf Make sure it looks something like this:\n.... #prune-backups: keep-INTERVAL=N[,...] script: /usr/local/bin/backup-hook.sh #exclude-path: PATHLIST .... After this we know the script will kick off whenever vzdump is ran and then it will push back to UK on all events. Make sure these steps are carried out on all your proxmox cluster nodes.\nHow does vzdump work # Proxmox invokes your hook script multiple times during a backup job, executing it as a standard system binary or shell script. Every time Proxmox reaches a new phase in the backup process, it calls the script and passes information using positional command-line arguments ($1, $2, $3) and environment variables.\nThe phases come in two families. The job-level phases run once per backup job and get no extra arguments:\njob-init job-start job-end job-abort The guest-level phases run once per VM or container, and here $2 is the backup mode (stop / suspend / snapshot) and $3 is the vmid:\nbackup-start backup-end backup-abort log-end pre-stop pre-restart post-restart vzdump also sets a handful of environment variables, and this is where it gets a little tricky, because they are not available in every phase:\nVariable Available in STOREID all phases (empty if you back up with \u0026ndash;dumpdir) DUMPDIR all phases (empty for PBS storages) VMTYPE, HOSTNAME guest-level phases only TARGET backup-end only LOGFILE log-end only, and empty for PBS storages The full list is documented in the pve-manager repo here: vzdump-hook-script.\nMy first attempt only used the job-level phases, which looks like the obvious choice, but it does not actually work. Two gotchas. First, job-abort only fires if the whole job dies. If a single VM fails, the job still finishes with job-end, so job-abort alone will never catch a failed guest.\nSo the script uses both families. backup-abort notes which guest failed, and log-end reads that guest\u0026rsquo;s log and picks out the ERROR: lines. Both are collected in a file under /run, and job-end then sends one single status to UK: down if anything was collected, up if the file is empty. job-init and job-start reset the files so nothing leaks over from the previous run.\nTwo last details that are easy to miss. vzdump calls the hook with a cleared environment, so there is no PATH unless you set it yourself. And if the hook exits non-zero, vzdump treats the backup as failed - so the script ends with exit 0. Monitoring should never be able to break the thing it is monitoring.\nTesting # If all is correct you should now get a status in UK every time a backup starts, ends or aborts in Proxmox. Rather than waiting for tonight\u0026rsquo;s job, test the script by hand. Be aware that these tests push to your real monitor, so it will go red on purpose - just run a clean start/end afterwards to get it green again.\nStart with the happy path. The phases have to be run in the same order vzdump would call them, because job-end reads the state file that job-start creates:\n/usr/local/bin/backup-hook.sh job-start /usr/local/bin/backup-hook.sh job-end That should give you \u0026ldquo;Backup job started\u0026rdquo; followed by \u0026ldquo;All backups completed OK\u0026rdquo; in UK. Running job-end on its own reports \u0026ldquo;No job state\u0026rdquo;, that is intentional and tells you the hook missed the start of the job.\nThen simulate a failed guest. backup-abort is the phase vzdump calls when a single VM fails:\n/usr/local/bin/backup-hook.sh job-start /usr/local/bin/backup-hook.sh backup-abort snapshot 101 /usr/local/bin/backup-hook.sh job-end Now the monitor should go yellow with \u0026ldquo;Backup finished with errors - VM 101\u0026rdquo;.\nTo test the log parsing as well, point LOGFILE at one of the .log files sitting next to your backups in the dump directory, ideally one from a job that actually failed:\nLOGFILE=/var/lib/vz/dump/vzdump-qemu-101-2026_09_05-02_00_01.log \\ /usr/local/bin/backup-hook.sh log-end snapshot 101 If something does not behave as expected, run the same commands with bash -x in front:\nbash -x /usr/local/bin/backup-hook.sh job-end The benefit of using -x is that you will get to see all the steps carried out by the bash script and it makes it easier to see where it fails, if you have trouble.\nFinally, test it end to end on a single guest without waiting for the scheduled job. This takes a real backup, so pick a small one:\nvzdump 101 --script /usr/local/bin/backup-hook.sh If all goes well you now have a simple dashboard to alert you if your backup fails, this way you only have to act on events, not look for events missing.\nThis is one example of an alert I will get on Signal: Conclusion # Setting up Uptime Kuma and getting alerts only when something needs attention is a game changer. Now I only get alerted when something needs my attention, not every day in a summary email that I never read.\nAI disclosure The hook script was drafted with the help of Claude (Anthropic). I specified the behaviour, reviewed the code, made some adjustments and refinements and then tested it against real vzdump runs on my own cluster before putting it into production. Verify it in your own environment before relying on it.\n","date":"5 September 2026","externalUrl":null,"permalink":"/posts/uptime-kuma-monitor-proxmox-backup/","section":"Posts","summary":"I have not been blogging for years, but still been pondering a lot with technology so why no try to share some stuff again. Last years I have played a lot with Proxmox and buldling my own home lab setup. This blog is hosted on this lab so both performance and availability might suffer :P But that is a whole other topic for another day.\n","title":"Uptime Kuma monitor Proxmox Backup","type":"posts"},{"content":"","date":"2 July 2020","externalUrl":null,"permalink":"/pages/","section":"Pages","summary":"","title":"Pages","type":"pages"},{"content":"Here you will find the location of our boat, Sofia. See you on the ocean!\n","date":"2 July 2020","externalUrl":null,"permalink":"/where-is-sofia-now/","section":"Pages","summary":"Here you will find the location of our boat, Sofia. See you on the ocean!\n","title":"Where is Sofia now?","type":"pages"},{"content":"","date":"15 November 2019","externalUrl":null,"permalink":"/categories/photo/","section":"Categories","summary":"","title":"Photo","type":"categories"},{"content":"I was in Barcelona for VMworld last week and managed to squeeze in a short stop at the amazing Sagrada Familia. This building is crazy and wonderful all at the same time. The light in the afternoon is stunning to say the least.\nIf you ever go to Barcelona, go visit: https://sagradafamilia.org/en/\n","date":"15 November 2019","externalUrl":null,"permalink":"/posts/sagrada-familia/","section":"Posts","summary":"I was in Barcelona for VMworld last week and managed to squeeze in a short stop at the amazing Sagrada Familia. This building is crazy and wonderful all at the same time. The light in the afternoon is stunning to say the least.\n","title":"Sagrada Familia","type":"posts"},{"content":"","date":"15 November 2019","externalUrl":null,"permalink":"/categories/travel/","section":"Categories","summary":"","title":"Travel","type":"categories"},{"content":" It is really fun to do macro fotography, even with some dated equipment. These photos were taken in the early afternoon and it was a bit too bright light. If I had waited a few hours the sun would be lower on the skies and the shine would be less bright and intense.\nAll the insects around the house just loved the lavender. No problem to get close to wasps and bumblebees when the tempting lavender was everywhere!\n","date":"27 August 2015","externalUrl":null,"permalink":"/posts/insects-on-lavender-in-croatia/","section":"Posts","summary":" It is really fun to do macro fotography, even with some dated equipment. These photos were taken in the early afternoon and it was a bit too bright light. If I had waited a few hours the sun would be lower on the skies and the shine would be less bright and intense.\n","title":"Insects on lavender in Croatia","type":"posts"},{"content":"","date":"27 August 2015","externalUrl":null,"permalink":"/categories/macro/","section":"Categories","summary":"","title":"Macro","type":"categories"},{"content":"","date":"27 August 2015","externalUrl":null,"permalink":"/categories/nature/","section":"Categories","summary":"","title":"Nature","type":"categories"},{"content":"","date":"8 August 2015","externalUrl":null,"permalink":"/categories/blogg/","section":"Categories","summary":"","title":"Blogg","type":"categories"},{"content":"Tesla is doing some word-of-mouth advertising of their cars Tesla Model S and in the future Model X. This basically means that people like myself that have a current Model S have the ability to give a current buyer of a new car a rebate of 10 000 NOK off the list price by clicking my link. At the same time I would get a credit of the same on my Tesla-account (for future car purchase, services, accessories or similar). So basically I am asking you, if you are contemplating buying a new Tesla, please click my link and go bananas!\nLink to buy a new Tesla: http://ts.la/siljeb4829 Should you buy a Tesla?\nIMG_20150329_194558 That is a good question, and since I am not a Tesla employee but just a mere user of a Model S I can just share my own experiences. My Model S is a basic 2-wheel drive with the big battery (85kWh) and I use it for my day-to-day driving needs and also for vacations visiting my family on the west-coast of Norway. The car is just excellent for this. There is a lot of room in the back seat for my 3 boys. With a big boot and a \u0026ldquo;frunk\u0026rdquo; in the front I have plenty of space for all luggage needs.\nLast winter we got a great deal on a returning our VW Sharan (it had a water leak in the sun-roof that the vendor was unable to fix, and finally they accepted a return!). We were then very much keen on buying a Tesla and when we finally did we bought a used one, and we have never regretted the decision for a minute.\nRange-anxiety?\nNot so much any more. I have driven a few trips over the mountains in Norway both in the wintertime and in the summertime (550 kilometers). Getting from one supercharger to another is breeze, even in the blistering cold. I have never had below 15-20% capacity left even when we have a full car and cold winter conditions. This is with driving \u0026ldquo;normally\u0026rdquo;, not super-energy efficient. The navigation system also helps you get to the destination, plotting a route via the superchargers and it will even tell you for how long you would need to charge. After a few road-trips you will be fully relaxed!\nIs it a good car?\nIt is the best car I have ever owned! Fun to drive, fun to use, and it is also nice to look at. What more do you need? After 6 months with the car I still look forward to every drive with the car. That has never been the case with any of my previous cars. It is truly an excellent car in my honest opinion.\nWinter driving is also perfect, even with the 2-wheel drive version. Now you could go for the 4-wheel tractor version but in my opinion it is really not needed. I did some driving on ice last winter and I actually had to pass by a Volvo XC60 that was struggling with the poor traction. It seem the Tesla with the huge weight and wide tires is a better match than the 4-wheel drive of the Volvo. Might be a very nervous Volvo driver of course, but that aside, winter driving is not a problem.\nDrawbacks?\nYes a few. It is missing a towing hitch for pulling a camper or trailer. This is something I miss a lot and should have been an option on the car. That being said, usually you will be able to loan a car from a friend just by offering a trip in the Model S :) Of course some locations could be hard to reach due to lacking supercharges, but in Norway that is almost a mute problem by now. Worst case you would need to schedule in some charge on one of the Type2 charges that would give you a full charge in 3-6 hours, or stay the night in a hotel or similar.\nDo I need a special charger?\nIMG_20150109_103040 Not if you use a car like I do. Most weeks I need to charge 1-2 times. We drive around 200 kilometers per week so there is no need for more charging. I charge the car on a 16amp 220v \u0026ldquo;normal\u0026rdquo; household outlet. When we are at the cabin we often charge on 10amp, and even that works. On 16amp you need to cater for about 24 hours for a full charge, but that almost never happens. I keep the charge between 30% and 80% at all times. If we suddenly need to go on a road-trip we can always drop by a supercharger and we would get 80% in 20-30 minutes (and the kids would of course get some food at the same time!).\nIMG_20150111_143423 So I guess then that I have made a free ad for Tesla, and maybe I get no \u0026ldquo;cashback\u0026rdquo; at all from doing this, but hey, why not? Go for a test drive with the car and make up your own mind!\n","date":"8 August 2015","externalUrl":null,"permalink":"/posts/buying-a-tesla/","section":"Posts","summary":"Tesla is doing some word-of-mouth advertising of their cars Tesla Model S and in the future Model X. This basically means that people like myself that have a current Model S have the ability to give a current buyer of a new car a rebate of 10 000 NOK off the list price by clicking my link. At the same time I would get a credit of the same on my Tesla-account (for future car purchase, services, accessories or similar). So basically I am asking you, if you are contemplating buying a new Tesla, please click my link and go bananas!\n","title":"Buying a Tesla?","type":"posts"},{"content":"Last fall we bought ourselves a new boat (old, but new to us!). The boat is a small Norwegian cabincruiser that gives us the ability to stay the weekend in the boat. One our favourite activities to do in the weekends is to make pizza. On the boat it is more complicated to make pizzas but far from impossible. This article is a short description on how do it :)\n20150510_153146 Making pizza on a grill is not a big mystery to us. We have done this many times on the Weber grill at home so we have a good starting point. First this was to get a proper grill with a lid to use on a boat. First we needed one that would mount in a secure and stable way on the boat.\nThe ultimate marine grill is an American product called Magma (at least according to our investigations). This comes in gas and coal , but we never condsidered the latter. The reasons are two: firstly it is not easy to ignite coal in a boat, especially close to the boat cover canvas (kalesje), and there is plenty of smoke from coal (harbors least popular?) and ultimately difficult to adjust the heat up and down as you absolutely need when pizza grilling. We bought the smallest Magma grill ( 38 cm ) and got it mounted on the pushpit.\ngrill Then there\u0026rsquo;s the pizza stone. We had an old pizza stone, and an old one is in this context the best. Just make sure to buy a stone which is slightly smaller than the grate and you\u0026rsquo;re ready. I find that the stone we have is perhaps a bit on the bigger side. If you are lucky you can find one that gives it about 1 cm clearance to the edge so you get plenty warm up from below. Ours has no more than 3-4mm gap, but still this works pretty well. To assemble the pizza you must do a little homework. Either bake out all bases at home and half-cook them in the stove at home. Baking on the boat is not very easy, at least not in our boat! Are you not so incredibly fond of baking, we found an alternative that works very well. Both Kiwi, Coop and Ica (and more I think) now sells pre-baked pizza bases in 2-pack. These are very good and supersuitable for boats. We buy two such packages and create 3-4 pizzas for a feast for 5 people (our kids eat like horses!). Assemble the barbecue on the push / pull-pit. Add the pizza stone on the gas on low-to-medium heat. Do not heat too hard, the stone gets mega hot and you can easily burn your pizza. Medium to medium minus on the heat and let it warm for +/- 6-7 minutes while starting on the pizza. The pizza is a straightforward piece of work if you prepared well. Take out one of your prebaked-bottoms, butter pizza sauce you made at home (or bought in the shop). Should you wish a very quick and inexpensive alternative solution I\u0026rsquo;ve used plain tomato paste from a can/tube and just spread a thin layer. This is pretty sweet and good, and if you do not put on too much this is a great alternative to the usual pizza sauce (and the kids love it!). So on with cheese, real cheese of course, no fake chease (is it called pizza topping, then it is not cheese!). On top, add ham, pineapple, mushrooms, onion rings and everything else you fancy. We usually cook a couple of pizzas with ham and cheese for the kids. For the grownups we do chorizo ​​or pepperoni, cheese, red onion and a little sharp blue cheese. Try anything you fancy :) When ready put the pizza onto the grill. Make sure the stone is not too hot! I turn up the heat on max for about a minute just after I put in the pizza. Afterwards I turn down the heat to the weakest setting for the rest of the cooking time. After 4-5, maybe 6-7 minutes the pizza should be ready. The difference between a pizza grilled this way and baking at home is that the bottom becomes very crunchy but there is no hard crust on the top. The cheese will just melt and become hot, is not possible to get the \u0026ldquo;brown scorched\u0026rdquo; on top with just heat coming from below, but I promise, it tastes really great! The first time make sure to bring double of everything. You\u0026rsquo;re going to burn one or two pizzas, maybe more. But eventually you get the hang of it and you can enjoy delicious pizza, time after time! We have found that the most important thing when making pizza on the boat is the preparations. Before we leave home, we cut up onions, sausages, prepare the cheese, bake the pizza bottoms, make dressings, pre-fry the mushrooms (mushrooms must heated before putting them on pizza otherwise it becomes very much moisture that gets the whole meal soggy) and pack everything into boxes that we bring with us. On the boat there is only assembly, cooking and and eating, quick and easy!\nIf you like something spicy on the pizza I can recommend to make a dressing of garlic and chilli. I buy lots of Chinese garlic and plain chilli (http://en.wikipedia.org/wiki/Bird%27s_eye_chili) and cut everything into small-small pieces, marinate them in a good olive oil. This is gunpowder strong and good on pizza! Adjust the spicyness with less chilli or remove the seeds (they are the strongest bit). Enjoy Your Meal!\n","date":"18 May 2015","externalUrl":null,"permalink":"/posts/make-pizza-on-the-boat/","section":"Posts","summary":"Last fall we bought ourselves a new boat (old, but new to us!). The boat is a small Norwegian cabincruiser that gives us the ability to stay the weekend in the boat. One our favourite activities to do in the weekends is to make pizza. On the boat it is more complicated to make pizzas but far from impossible. This article is a short description on how do it :)\n","title":"Make Pizza on the Boat","type":"posts"},{"content":"Last night me and my wife took a walk down to the breakwater to take some midnight long exposure photo. The view is towards stadt seen from the north side of the island Barmen in Selje on the west coast of Norway. I used a polarizing filter to increase the colors and also reduce the light somewhat. We had about 30 seconds exposures and had the lens on maximum aperture. I love the way the ocean gets the smooth blur and the colors of the skies really pop out.\nStreetview from Google Maps\n","date":"25 July 2014","externalUrl":null,"permalink":"/posts/long-exposure-at-barmen-island/","section":"Posts","summary":"Last night me and my wife took a walk down to the breakwater to take some midnight long exposure photo. The view is towards stadt seen from the north side of the island Barmen in Selje on the west coast of Norway. I used a polarizing filter to increase the colors and also reduce the light somewhat. We had about 30 seconds exposures and had the lens on maximum aperture. I love the way the ocean gets the smooth blur and the colors of the skies really pop out.\n","title":"Long Exposure at Barmen island","type":"posts"},{"content":"I have for years been using a mediacenter PC in my livingroom, it started back in the days of the 4Mbit wireless days (before the wireless standards were approved) and up till today on wired 1Gbit with a NAS and dedicated TV server in the basement. All through the years it has been very important to me to have a noiseless computer, fan noise and CD chippering is just annoying!\n1969314_9 Last few years I have been trusting and loving my Acer Aspire Revo 100 and this has proved very durable and good. Lately it has been having issues with cooling and now I need give it a good vacuuming from time to time to be performing OK. Also the CD/BD-rom player was just too noisy!\nNot so long ago I got a killer offer on a new computer cabinet with passive cooling, the Streacom FC5. I got it for 500 NOK (retails at 2000 NOK) so I could not decline the offer. When I got the cabinet I searched around for a mainboard that would be compatible as that is very important with the type of cooling used. The passive cooling is heatpipes connected to the side of the cabinet and this is only suitabe for low-power CPUs up to about 75Watt. This in mind I decided to go for one of the new Haswell CPUs from Intel (Generation 4) as these are super low-power and also come packed with a new GPU, the Intel HD that would be perfect for a HTPC.\nFirst is first, for the Haswell CPU I needed a mainboard with Intel socket 1150. I searched around and many have an issue that they have components directly in conflict with the installation of the heatpipes. One recommended option for this case is the ASRock Z87E-ITX, this also boasts a wireless network card for the new standard 802.11ac that can give speeds up to 5/600Mbits/s (with two antennas) so with all this in mind I decided to go for this motherboard.\nThe CPU was easier, I selected the Core i5-4570T, this has a power consumption of only 35Watt, that is just spectacularly low! This CPU also come packed with the Intel HD 4600 graphics integrated, support for 4K resolution and all else I would need in the very near future. The rest of the specs was 8 GB DDR3 memory from Kingston, SSD from Crucial (240GB) and a Sony slim blu-ray player. For power I got the external power adapter from Streacom with Nano-150 PSU support. Actually, I got enough space inside the chassis to put the whole power-adapter part inside so no big \u0026ldquo;lump\u0026rdquo; left outside (I forgot to take a pciture of this, but I did get it in, for real!), very cool!\nHow did it all work out? Well have a look at the pictures. Everything plugged together almost like clockwork, it was all set in just a few hours on the table and the thermal heat is just 45 degrees for the CPU under max load. Actually during the installation I did not have enough thermal paste for the CPU cooler so I think I can get even better performance if I clean it up and reapply, maybe I will do that, but seriously, temperature here is not an issue. The cooler \u0026ldquo;rods\u0026rdquo; that you connect to the chassis were a bit too long for a perfect fit, they \u0026ldquo;bumped\u0026rdquo; into the CMOS battery. This was easily fixed by just cutting them with a metal-saw. Performance, well the performance is nothing less than supersmooth. I have not yet been able to test 4K material but I hope that will work just as well. The machine boots into windows in just 6-7 seconds and after a about 15 seconds MediaPortal is up and running. Not too bad :) And the ambient noise, well, it is not there. It is just totally silent, bliss!\nHere is the kit list I have used if anyone is interested: Streacom FC5 OD Streacom NANO150 PSU Asrock 1150 Z87E-ITX Intel CORE I5-4570T Kingston DDR3 8GB PC1600 CL9 Crucial M500 240GB SSD Sony BC-5600 Cideko Air Keyboard\nI did all my shopping at these shops htpc.no and deal.no and it was htpc.no that gave me the killer offer on the Streacom cabinet (Facebook campaign).\n","date":"9 June 2014","externalUrl":null,"permalink":"/posts/building-the-ultimate-quiet-htpc/","section":"Posts","summary":"I have for years been using a mediacenter PC in my livingroom, it started back in the days of the 4Mbit wireless days (before the wireless standards were approved) and up till today on wired 1Gbit with a NAS and dedicated TV server in the basement. All through the years it has been very important to me to have a noiseless computer, fan noise and CD chippering is just annoying!\n","title":"Building the ultimate quiet HTPC","type":"posts"},{"content":"Yesterday we had a big summer party at Rykkinn Skole, and at the same time we celebrated that this summer the old school building \u0026ldquo;avdeling Berger\u0026rdquo; will de replaced with a new modern building in 2 years. If that was not enough, Berger also celebrates 40 years in operation this year.\nSadly the day was cursed with a lot of rain, but that did not stop all the kids and parents :)\nHere are some pictures from the celebrations.\n","date":"6 June 2014","externalUrl":null,"permalink":"/posts/summer-party-and-demolisionparty/","section":"Posts","summary":"Yesterday we had a big summer party at Rykkinn Skole, and at the same time we celebrated that this summer the old school building “avdeling Berger” will de replaced with a new modern building in 2 years. If that was not enough, Berger also celebrates 40 years in operation this year.\n","title":"Summer party and \"Demolisionparty\"","type":"posts"},{"content":"My kids were part of a show in Sandvika arranged by KGB Danseskole. This is a dance school teaching all dance styles and they put most of them together in a show where the theme was animals in a zoo and all the \u0026ldquo;animals\u0026rdquo; danced all sorts of dances with many styles of music. All the kids seemed to have a lot of fun and the show was really great!\n","date":"29 May 2014","externalUrl":null,"permalink":"/posts/grrr-be-aware-of-the-animals/","section":"Posts","summary":"My kids were part of a show in Sandvika arranged by KGB Danseskole. This is a dance school teaching all dance styles and they put most of them together in a show where the theme was animals in a zoo and all the “animals” danced all sorts of dances with many styles of music. All the kids seemed to have a lot of fun and the show was really great!\n","title":"Grrr... be aware of the animals","type":"posts"},{"content":" ","date":"3 May 2014","externalUrl":null,"permalink":"/posts/beitostolen-valdres/","section":"Posts","summary":" ","title":"Beitostølen in Valdres","type":"posts"},{"content":"I have been testing the new version of Firefox for a while and I must say it is vastly improved over the last version. Main argument is the new graphical user interface that has been refurbished. Also now then browser support sync of settings between installations.\nThe main argument with Firefox is that Mozilla takes user privacy very seriously so if you have doubts in for instance Google and the Chrome browser then Firefox is a very good alternative.\nAt least, if you have (like me) been using other browsers for a long time then it is now time to take another look at this new release!\nDownload the Firefox here: www.mozilla.org/firefox\n","date":"2 May 2014","externalUrl":null,"permalink":"/posts/new-version-of-firefox/","section":"Posts","summary":"I have been testing the new version of Firefox for a while and I must say it is vastly improved over the last version. Main argument is the new graphical user interface that has been refurbished. Also now then browser support sync of settings between installations.\n","title":"New version of Firefox","type":"posts"},{"content":"Update: The first of May Microsoft released a fix for the vulnerability, also for Windows XP. It is also possible to protect your machine by upgrading to the latest version of Adobe Flash player according to sources on the Internet.\nYesterday we got word from Microsoft that there is a security hole in Internet Explorer versions 6 through to 11 and there is still no fix to this issue. The sad thing about this issue is that it is actively being exploited and that means, if you are using IE now you are at risk.\nMicrosoft Security Advisory 2963983\nWhat is the risk? An attacker could install software to your computer, this software could be used for anything (stealing your information, attacking other services on the Internet or other). You would not know that it would happen even, you would just be browsing along and it would happen silently.\nWhat can you do? Use another browser is the simple answer. Microsoft is going to patch this in a week or two (next patch Tuesday the 14th of May is good bet) but remember, if you are on Windows XP it might not even get a patch since it is out of support. My suggestion is simply try another browser, some good suggestions are:\nfirefox chrome opera If you never turn back to IE, then you do like most of us. Should you really miss IE just wait until mid-may and you will be fine again. If you really need to use IE there are some quick fixes you could do, one is to disable flash, another is to install Enhanced Mitigation Experience Toolkit version 4.1. You can find more information about that by clicking on the the Microsoft link above.\nSources: http://thehackernews.com/2014/04/new-zero-day-vulnerability-cve-2014.html, http://www.symantec.com/connect/blogs/zero-day-internet-vulnerability-let-loose-wild\n","date":"28 April 2014","externalUrl":null,"permalink":"/posts/internet-explorer-security-issue/","section":"Posts","summary":"Update: The first of May Microsoft released a fix for the vulnerability, also for Windows XP. It is also possible to protect your machine by upgrading to the latest version of Adobe Flash player according to sources on the Internet.\n","title":"Internet Explorer Security Issue","type":"posts"},{"content":"Finally a clear and nice night here in Norway, and the alignment of Mars, earth and the sun is not that old so still the view is spectacular!\nTonight the moon is full and right now Mars is at its closest point (relative to earth), a mere 92 million kilometres away. The combination is just so cool!\nThis photo is taken just above our house in Norway.\nIf you have no clue what I write about, read this: Mars Opposition, NASA or I fucking love science.\n","date":"14 April 2014","externalUrl":null,"permalink":"/posts/moon-and-mars/","section":"Posts","summary":"Finally a clear and nice night here in Norway, and the alignment of Mars, earth and the sun is not that old so still the view is spectacular!\nTonight the moon is full and right now Mars is at its closest point (relative to earth), a mere 92 million kilometres away. The combination is just so cool!\n","title":"Moon and Mars","type":"posts"},{"content":"The \u0026ldquo;superbug\u0026rdquo; in OpenSSL named \u0026ldquo;Heartbleed\u0026rdquo; is all over the news these days and is causing some confusion and concern for many people. This hole in the SSL encryption was discovered in the start of this week by Google and Code Nomicon, and the hole is a serious one. The problem is, what do you do with this? Here is a very simple simple guide to what I suggest you should do.\n1. Verify that your account is now patched from the vulnerability. To do this check your provider (bank, facebook, google or other) with one of the open tools to verify. One such tool is: http://filippo.io/Heartbleed/ Just enter the URL (like accounts.google.com or any other web page) and if the tools says \u0026ldquo;All good\u0026rdquo; then you are OK to proceed and change your password. Should this not be the case then wait until they have fixed the site before changing it (you could of course disable your account in the meantime).\nThese services have allready been fixed and you can safely change your password:\nFacebook Tumblr Google/Gmail/YouTube Amazon Web Services eBay Dropbox Netflix SoundCloud OKCupid Wunderlist Telenor Lists are being updated on this page with information and advisory if you need to change password: http://mashable.com/\n2. You could (even if the bug is not fixed actually!) enable 2-factor authentication for your services. Main services that have this already is Google, Facebook, Twitter, Microsoft and more.\nGoogle: http://www.google.com/landing/2step/ Facebook: https://www.facebook.com/note.php?note_id=10150172618258920 Twitter: https://blog.twitter.com/2013/getting-started-with-login-verification ¨ Microsoft: http://windows.microsoft.com/en-us/windows/two-step-verification-faq\nMost of these services provide an app for Android or Apple phones/devices that you could use for code generation or you would get an SMS on your phone. Using 2-factor authentication protects you more when the passwords are leaked on the Internet as the \u0026ldquo;stealer\u0026rdquo; also needs to get your phone to be able to log in. In the future all services must provide some kind of 2 factor I think!\nFor more information about the bug that has been discovered read this: http://heartbleed.com. If you have a server service using OpenSSL you should immediately take action to close this security hole and preferably also issue for new SSL certificates for your service when the bud is fixed.\nFinal information, this bug has been patched like crazy by the big authentication providers around the world over the last few days and most of the big services have been patched already and at least I have not heard of anyone exploiting this still. The big concern however is that the bug have been in the \u0026ldquo;wild\u0026rdquo; for 2 years and in this time anyone could have found out and exploited this in silence. The way the bug works actually leaves no trace if this had been done and if they never published anything then they are sitting on a huge backdoor into many systems. This is the reason you really have to change your passwords, no matter what\u0026hellip;. and again, go enable 2-factor, that is the best protection!\n","date":"10 April 2014","externalUrl":null,"permalink":"/posts/heartbleed-ssl-vulnerability/","section":"Posts","summary":"The “superbug” in OpenSSL named “Heartbleed” is all over the news these days and is causing some confusion and concern for many people. This hole in the SSL encryption was discovered in the start of this week by Google and Code Nomicon, and the hole is a serious one. The problem is, what do you do with this? Here is a very simple simple guide to what I suggest you should do.\n","title":"Heartbleed SSL Vulnerability","type":"posts"},{"content":"I have lately been testing macro photography of snow crystals. This has proven more complicated than I have imagined so I will have to try some more.\nThe photo here is actually 12 exposures that have been focus stacked in Photoshop and then imported to Lightroom for some post processing. When I have some more experience with this technique I might post a quick tutorial :)\n","date":"2 February 2014","externalUrl":null,"permalink":"/posts/snowflakes/","section":"Posts","summary":"I have lately been testing macro photography of snow crystals. This has proven more complicated than I have imagined so I will have to try some more.\n","title":"Snowflakes","type":"posts"},{"content":"The GIF is from this morning, showing the snow under a streetlight at Rykkinn, where I live :)\n","date":"24 January 2014","externalUrl":null,"permalink":"/posts/testing-animated-gifs/","section":"Posts","summary":"The GIF is from this morning, showing the snow under a streetlight at Rykkinn, where I live :)\n","title":"Testing animated GIFs","type":"posts"},{"content":"Happy New Year to all, we had a nice evening in Bjørnebærstien with some friends celebrating the new year. Not a very photographic event this year but I did manage to get a few decent shots nevertheless. This is my first attempt at shooting fireworks so the results are not great, but OK. :)\n","date":"4 January 2014","externalUrl":null,"permalink":"/posts/happy-new-year/","section":"Posts","summary":"Happy New Year to all, we had a nice evening in Bjørnebærstien with some friends celebrating the new year. Not a very photographic event this year but I did manage to get a few decent shots nevertheless. This is my first attempt at shooting fireworks so the results are not great, but OK. :)\n","title":"Happy New Year","type":"posts"},{"content":"This classic and great TED talk by Simon Sinek is very clever and should be watched by any company leader.\nStart with why - how great leaders inspire action…: ","date":"29 December 2013","externalUrl":null,"permalink":"/posts/what-makes-you-buy-apple-products/","section":"Posts","summary":"This classic and great TED talk by Simon Sinek is very clever and should be watched by any company leader.\nStart with why - how great leaders inspire action…: ","title":"What makes you buy Apple products?","type":"posts"},{"content":"Dersom du trenger å komme i kontakt med meg, bruk dette skjemaet:\n[contact-form subject=\u0026lsquo;Contact form stian.barmen.nu\u0026rsquo;][contact-field label=\u0026lsquo;Navn\u0026rsquo; type=\u0026lsquo;name\u0026rsquo; required=\u0026lsquo;1\u0026rsquo;/][contact-field label=\u0026lsquo;E-post\u0026rsquo; type=\u0026lsquo;email\u0026rsquo; required=\u0026lsquo;1\u0026rsquo;/][contact-field label=\u0026lsquo;Webside\u0026rsquo; type=\u0026lsquo;url\u0026rsquo;/][contact-field label=\u0026lsquo;Melding\u0026rsquo; type=\u0026lsquo;textarea\u0026rsquo; required=\u0026lsquo;1\u0026rsquo;/][/contact-form]\n","date":"28 December 2013","externalUrl":null,"permalink":"/nb/kontakt/","section":"Pages","summary":"Dersom du trenger å komme i kontakt med meg, bruk dette skjemaet:\n[contact-form subject=‘Contact form stian.barmen.nu’][contact-field label=‘Navn’ type=‘name’ required=‘1’/][contact-field label=‘E-post’ type=‘email’ required=‘1’/][contact-field label=‘Webside’ type=‘url’/][contact-field label=‘Melding’ type=‘textarea’ required=‘1’/][/contact-form]\n","title":"Kontakt","type":"pages"},{"content":"","date":"22 December 2013","externalUrl":null,"permalink":"/categories/featured/","section":"Categories","summary":"","title":"Featured","type":"categories"},{"content":"This December has been very warm and windy, a lot of rain has taken the little snow we had and mostly washed it away. Not very good for all that have been looking forward to using skies and sleighs, but there is very little we can do with that.\nYesterday morning it had been raining all night and the trees were full of little droplets bouncing the sun rays through, giving this larch tree a bit of Christmas sparkle! Sadly I was not able to get a short when the effect was at max (as I was still in bed with my morning coffee!) but it is clearly visible in these shots as-well.\n","date":"22 December 2013","externalUrl":null,"permalink":"/posts/light-droplets-in-the-tree/","section":"Posts","summary":"This December has been very warm and windy, a lot of rain has taken the little snow we had and mostly washed it away. Not very good for all that have been looking forward to using skies and sleighs, but there is very little we can do with that.\n","title":"Light-Droplets in the Tree","type":"posts"},{"content":"Last weekend we had a very nice weekend in Valdres, in a little mountain cabinvillage of Vaset. For the last six months I have been playing with the idea of putting together an HDR (High Dynamic Range) photo of a sunset or similar. This weekend I brought my old Canon 45d with my new Sigma 10-20mm (f3.5) and the sturdy tripod. Most of the weeken had fog and snow to offer but suddenly on the Saturday the light came out and we got a bit of sun! Quickly I configured my camera to lock the Aperture (to ensure stability in depth of focus) and setup the AEB (Auto Exposure Bracketing) to take three photos. One would be normal exposure, one -2 steps and one +2 steps (underexposed and overexposed). The pohoto was taken on the tripod to ensure total alignment between the three, and of course I used the 2sec selftimer to get the picture with being totally hands off the camera.\nWhat is the point of HDR? Well the point is that the overexposed photo will have some details that the underexposed will not and vice versa. So when you stack and align all these photos you get a much deeper detail both in the contrast and color spectrum. For instance the normal JPEG you would shoot is 8bit, a proper HDR is 32bit and contains a whole world of details you never could get with JPEG. When I shoot with my canon I always use the RAW files to get as much details as I can and not loose anything in the process. The only time I use JPEG is for the final export when all the work is completed.\nSo how did it turn out? Well here you can see the three orinigal images:\nI took these three photos into Photomatix Pro 5, algined them and did some very minor tweaking of the image. After this I saved it to a 16bit TIFF file (127 MB large!) and opened it in Adobe Lightroom 5.3 for a bit of post processing. Here I just adjusted the exposure a bit, contrast and saturation. The aim was to get a photo with both details in the shadows as-well as in the light. The final export is this image:\n","date":"19 December 2013","externalUrl":null,"permalink":"/posts/weekend-to-vaset-in-valdres/","section":"Posts","summary":"Last weekend we had a very nice weekend in Valdres, in a little mountain cabinvillage of Vaset. For the last six months I have been playing with the idea of putting together an HDR (High Dynamic Range) photo of a sunset or similar. This weekend I brought my old Canon 45d with my new Sigma 10-20mm (f3.5) and the sturdy tripod. Most of the weeken had fog and snow to offer but suddenly on the Saturday the light came out and we got a bit of sun! Quickly I configured my camera to lock the Aperture (to ensure stability in depth of focus) and setup the AEB (Auto Exposure Bracketing) to take three photos. One would be normal exposure, one -2 steps and one +2 steps (underexposed and overexposed). The pohoto was taken on the tripod to ensure total alignment between the three, and of course I used the 2sec selftimer to get the picture with being totally hands off the camera.\n","title":"Weekend to Vaset in Valdres","type":"posts"},{"content":"A very good Halloween celebration today. The photos are of my own pumpkin creation this year, and also from the house of the local SFO leader, Randee Hansen at Rykkinn. She is of course from the US and has helped kick off the celebration and accepts brave trick and treaters :)\n","date":"31 October 2013","externalUrl":null,"permalink":"/posts/halloween/","section":"Posts","summary":"A very good Halloween celebration today. The photos are of my own pumpkin creation this year, and also from the house of the local SFO leader, Randee Hansen at Rykkinn. She is of course from the US and has helped kick off the celebration and accepts brave trick and treaters :)\n","title":"Halloween","type":"posts"},{"content":" Ric Elias was sitting in seat 1D in a crashing plane and he has some amazing thoughts about that. Watch the short video, it makes all the sense in the world!\n","date":"21 September 2013","externalUrl":null,"permalink":"/posts/i-now-collect-bad-wine/","section":"Posts","summary":" Ric Elias was sitting in seat 1D in a crashing plane and he has some amazing thoughts about that. Watch the short video, it makes all the sense in the world!\n","title":"I now collect bad wine","type":"posts"},{"content":"Today I attended a training course at Semb farm and I took this picture during a short walk in a break. Mobile phone so the quality is not great.\n","date":"18 September 2013","externalUrl":null,"permalink":"/posts/semsvannet/","section":"Posts","summary":"Today I attended a training course at Semb farm and I took this picture during a short walk in a break. Mobile phone so the quality is not great.\n","title":"Semsvannet","type":"posts"},{"content":"If you have an Android device (newer than version 2.2) and you wonder where it is for any reason, or maybe if you have lost it, or worse it is stolen then there is still hope. You can probably locate the device by using the Android Device Manager. The tools has three important functions:\nIt will tell you the location of the device (with accuracy indication) You can activate a remote ring Remote deletion / wipe of your device The ring part is clever as it will start a full volume ring-tone even if it is put in silent mode. Nice if it got lost into the depth of the sofa or whatever.\nIf you want the remote wipe functionality you need to enable it, and the most easy way to do that is to click on the link on the web page and it will send the settings to the device.\nFor more information go here: https://www.google.com/android/devicemanager\n","date":"13 September 2013","externalUrl":null,"permalink":"/posts/locate-and-wipe-your-android/","section":"Posts","summary":"If you have an Android device (newer than version 2.2) and you wonder where it is for any reason, or maybe if you have lost it, or worse it is stolen then there is still hope. You can probably locate the device by using the Android Device Manager. The tools has three important functions:\n","title":"Locate and wipe your Android","type":"posts"},{"content":" Very funny video, these guys can both sing and create videos. This particular one is gaining a lot of popularity in Norway now, especially with younger kids. :) Njoy!\n","date":"12 September 2013","externalUrl":null,"permalink":"/posts/ylvis-the-fox/","section":"Posts","summary":"http://www.youtube.com/watch?v=jofNR_WkoCE","title":"Ylvis and The fox","type":"posts"},{"content":"This posting and audio does not make a whole lot of sense unless you understand Norwegian so I will not translate the rest. If you understand Norwegian then go ahead! :)\nI dag fikk jeg beskjed om at mamma var på radio av svigermor. Litt research måtte til og jeg fant ut at hun hadde vært på Lønsj med Rune Nilson på NRK P1. Lastet ned klippet på podcast og redigerte frem den lille biten som inneholder bare der hvor mamma ble oppringt (beklager NRK om jeg bryter noe copyright her, men jeg linker i alle fall til dere!)\nHer er klippet hvor de ringer opp til mamma:\n[mejsaudio mp3=/wp-content/uploads/2013/09/redigert_loensj_p1.mp3]\nKlikk her dersom du ikke får noe lyd: Anne-Britt Barmen på P1\nMorsomt og god reklame for kafeen!\nKilde: NRK.no; hør hele podcasten her: http://radio.nrk.no/serie/loensj-med-rune-nilson/dmpa10018013/09-09-2013\n","date":"9 September 2013","externalUrl":null,"permalink":"/posts/mamma-pa-radio/","section":"Posts","summary":"This posting and audio does not make a whole lot of sense unless you understand Norwegian so I will not translate the rest. If you understand Norwegian then go ahead! :)\n","title":"Mummy on the radio","type":"posts"},{"content":"I bought this wonderful Orchidaceae for my wife last week \u0026hellip; wonderful ey?\n","date":"7 September 2013","externalUrl":null,"permalink":"/posts/orchidaceae/","section":"Posts","summary":"I bought this wonderful Orchidaceae for my wife last week … wonderful ey?\n","title":"Orchidaceae","type":"posts"},{"content":"I just registered a new domain name for this site, and then I needed to rewrite the old URLs to the new name. This is quite easy since I have a Linux server (CentOS in fact) with Apache. I wanted to tell the browsers and search engines that the new domain name is a permanent one and therefor the correct redirect is called a 301 server-side redirect. What this in simple terms means is that the web server will tell the web-browser or search engine spider that \u0026ldquo;this site has moved, and the new permanent address is: www.sbarmen.no\u0026rdquo;.\nTo implement this I used a RewriteMod command in my .htaccess file located in the websites root directory. For this redirect I wanted to move from: http://stian.barmen.nu OR http://www.stian.barmen.nu TO http://www.sbarmen.no.\nSimple ey? Yes in fact it is. Just open the .htaccess file and add these lines to the top of the file:\nRewriteEngine On RewriteBase / RewriteCond %{HTTP\\_HOST} !www.sbarmen.no$ \\[NC\\] RewriteRule ^(.\\*)$ /$1 \\[L,R=301\\] The first line just tells Apache to make sure the rewrite engine is turned on, you could also prefix this with a \u0026lt;IfModule mod_rewrite.c\u0026gt; and suffix with and you would not get any errors in your logs og tre moduler SAS not loaded, but the long and short of it is, make sure Apache loads the mod_rewrite module in the configuration file (and most default apache installations does).\nExplanation to the above rules is that the RewriteBase just tells it will rewrite for all URLs on this site, the second RewriteCond checks that the domain name requested from the requestor is NOT www.sbarmen.no (the ! is the NOT part) and the [NC] means case insensitive. Lastly the RewriteRule itself, for all characters in the URL string following the domain part ^(.*)$ modify the domain part to http://www.sbarmen.no and then add the content of the ^(.*)$ afterwords, this is the $1. First part captures the non-domain URL part, and the we add it to the new URL. This means that all requests on sub-pages will also work without any issues.\nSo finally, the L,R=301, in short this is where we say to Apache the this rewrite is done (L) and now send a redirect that is a permanent move for this site, R=301. So next time please use the www.sbarmen.no and all of this rewrite business will be omitted.\nThat was a very geeky way to explain that I have moved this site to a new domain name, so thanks for reading :) Sources: Apache Mod_Rewrite: http://httpd.apache.org/docs/current/mod/mod_rewrite.html_ _W ikipedia HTTP Redirects: http://en.wikipedia.org/wiki/URL_redirection#HTTP_status_codes_3xx\n","date":"6 September 2013","externalUrl":null,"permalink":"/posts/my-own-domain-name/","section":"Posts","summary":"I just registered a new domain name for this site, and then I needed to rewrite the old URLs to the new name. This is quite easy since I have a Linux server (CentOS in fact) with Apache. I wanted to tell the browsers and search engines that the new domain name is a permanent one and therefor the correct redirect is called a 301 server-side redirect. What this in simple terms means is that the web server will tell the web-browser or search engine spider that “this site has moved, and the new permanent address is: www.sbarmen.no”.\n","title":"My own domain name","type":"posts"},{"content":"Me and a collegue at work discussed the other day that today we use much more written text than before. We communicate in writing all the time on our phones, computers, tablets, phablets and more. Some people today send hundreds of SMS every week, you might have a blog, use Facebook, Google+, Twitter, Instagram, Vibre, Google Hangouts, join in a forum (or ten!) and so fourth. I guess the use of IRC and Usenet/News no longer qualifies to be on this list but they were absolutely part of the evolution for the written text on the Internet.\nThe use of emoticons and abbrevations came to be so we could replace moods, feelings or state of mind as that is more complicated, time consuming, and not the least, space demanding than the use of emoticons. SMS kind of introduced the use of emoticons to the general \u0026ldquo;non-nerd\u0026rdquo; public due to its limit of 160 characters per message. This limit has been washed out last few years as the costs for messages has dropped like a sinking rock, and the phones conseal the fact that the message consists of multiple SMS\u0026rsquo;s. On that note, for me it is quite time consuming to write on smart-phones and tablets compared to writing with a pen or keyboard, so from that perspective emoticons and abbrevations is a good thing. So I guess there is a good reason it all \u0026ldquo;came to be\u0026rdquo;, but what would a world be with no use of emoticons?\n[table] With Emoticons, No Emoticons\nCould you pick up some milk on the way home? :-*,Could you please pick up some milk on the way home my love - he said sending her a kiss.\nI was at the tivoly today :O almost killed myself ;-),I was at the tivoly today\\, what a thrill! At some point I really was worried that I might get hurt or even killed - she said with a grin on her face.\nGot my new car today :\u0026rsquo;(, I got my new car today - he said with a sad look on his face\\, something was obviously bothering him.\nI saw the new Jim Carey movie today ROLFLOL B-), I saw the new Jim Carey movie today\\, what a funny movie! I was rolling on the floor laughing my head off! Very cool movie indeed\\, recommended!\nOK :-P, OK - he said with a smart look on his face. U coming *flirting* :-), He looked at her with his seductive eyes\\, and asked her\\, \u0026ldquo;are you coming?\u0026rdquo;. His eyes was hinting at the door and she smiled at him \u0026hellip;\nHad some great pasta for lunch today :-\\ , The irony was thick when he said \u0026ldquo;I had some great pasta for lunch today.\u0026rdquo; [/table]\nMaybe you have better examples?\nThe examples are maybe not the best, but they venture to prove a point. Keep in mind that more than 80% of communication is not the words but the visual representation, the mood, the tone of voice etc, I am not surprised that we use all the dirty tricks we can find to spice up our written language. Also kids and teenagers that might still not have the vocabulary of adults want to express themselves and they play a huge role in the development of our written language.\nMy conclusion is that emoticons and abbreviations have come to stay and they serve a purpose for sure. We could maybe be better at actually writing proper text when expressing ourselves in written form. My native language is not English so I might not be as articulate as native writers but at least if we make an effort written text can be very colorful, even with the absence of emoticons.\nI do wonder though, when does the emoticons enter into the dictionaries?\nAnother topic is of course what all the emoticons and abbreviations mean, but it was not my intention to cover that part, many good sources on the internet, so Google it :-)\nPhoto from: stockarch.com - Free stock image library powered by the community\n","date":"1 September 2013","externalUrl":null,"permalink":"/posts/a-world-without-emoticons/","section":"Posts","summary":"Me and a collegue at work discussed the other day that today we use much more written text than before. We communicate in writing all the time on our phones, computers, tablets, phablets and more. Some people today send hundreds of SMS every week, you might have a blog, use Facebook, Google+, Twitter, Instagram, Vibre, Google Hangouts, join in a forum (or ten!) and so fourth. I guess the use of IRC and Usenet/News no longer qualifies to be on this list but they were absolutely part of the evolution for the written text on the Internet.\n","title":"A world without emoticons","type":"posts"},{"content":"A joke is a very serious thing\nWinston Churchill\n","date":"1 September 2013","externalUrl":null,"permalink":"/posts/a-joke-is-a-very-serious-thing/","section":"Posts","summary":"A joke is a very serious thing\nWinston Churchill\n","title":"A joke is a very serious thing","type":"posts"},{"content":"Since we have been travelling around the world for many years with my family and for work I have seen many wonderful places. Grand Canyon is by far one of the more magnificent sites I have seen. This summer on my family roadtrip with a rented RV we visited the south rim of the canyon in early July.\nThe area was dried out due to very dry weather the last few weeks but the day we had our visit a proper thunder and rain storm came out of nowhere. The rain stopped as we parked the RV and it did not take long before the sun came out. The rain cleared the air and I think the views were even more spectacular due to the rain.\nI think if you ever plan to visit the Grand Canyon you should plan to either get a sunrise or a sunset into your plans. The contrasts of the view is much nicer when you get the sun in from an angle and you can really see just how big the canyon is.\nIn the evening we did a walk along the rim enjoying a magical sunset, a most wonderful visit to the Grand Canyon.\n","date":"31 August 2013","externalUrl":null,"permalink":"/posts/grand-canyon/","section":"Posts","summary":"Since we have been travelling around the world for many years with my family and for work I have seen many wonderful places. Grand Canyon is by far one of the more magnificent sites I have seen. This summer on my family roadtrip with a rented RV we visited the south rim of the canyon in early July.\n","title":"Grand Canyon","type":"posts"},{"content":"We had quite a few nice sunsets in the US this summer. Driving along the coast of California on highway 1 we had the sun set in the ocean, over Grand Canyon we had sun setting over the edge, in Los Angeles over the city \u0026hellip; and they were all magnificent. Sunsets are a very popular photo motive and I really would like to get a remote or automated shutter with my tripod to take these photos, but usually I lack the gear when the opportunity presents itself.\nAll photos had some touch-up done in Adobe Lightroom to get the colors out and also some adjustments on the exposure.\n","date":"20 August 2013","externalUrl":null,"permalink":"/posts/american-sunsets/","section":"Posts","summary":"We had quite a few nice sunsets in the US this summer. Driving along the coast of California on highway 1 we had the sun set in the ocean, over Grand Canyon we had sun setting over the edge, in Los Angeles over the city … and they were all magnificent. Sunsets are a very popular photo motive and I really would like to get a remote or automated shutter with my tripod to take these photos, but usually I lack the gear when the opportunity presents itself.\n","title":"American Sunsets","type":"posts"},{"content":"","date":"17 August 2013","externalUrl":null,"permalink":"/categories/animals/","section":"Categories","summary":"","title":"Animals","type":"categories"},{"content":"Just a few months back I bought the Kenko extension tubes from Amazon to be able to make macro photos. The reason I went with the Kenko is that they connect the electronics of your lens to the camera so that auto-focus etc will work. You can absolutely go with a cheaper option and still get the same great photos. or you can buy the Canon at tripple the price :)\nDuring our summer vacation I did not get a lot of macro work done but at least I got a Dragonfly mounted on top of a flower just next to the pool. The insect was sometimes flying about but returned to his starting position giving me time to get my gear and land a pretty decent photo. I was lacking my tripod and that is a pity because getting a sharp image can be quite hard due to the zoom that is needed.\nThis particular photo was taken with two tubes mounted, I believe it was the 36mm and 12mm, and the lens was the EF-S 18-200mm extended to maximum zoom to prevent the dragonfly to leave. Going closer meant it would leave, and I tried a few times to be honest.\nI am sure I will do more macro work in the future :) Quite good fun!\n","date":"17 August 2013","externalUrl":null,"permalink":"/posts/macro-photography-in-us/","section":"Posts","summary":"Just a few months back I bought the Kenko extension tubes from Amazon to be able to make macro photos. The reason I went with the Kenko is that they connect the electronics of your lens to the camera so that auto-focus etc will work. You can absolutely go with a cheaper option and still get the same great photos. or you can buy the Canon at tripple the price :)\n","title":"Macro Photography in US","type":"posts"},{"content":"How else to throw away some time than just sitting still close to the hedge in the backyard waiting for some bugs to crawl by \u0026hellip; strange what you can see when you go very close. These guys were either fighting, playing, or mating, not sure.\nNot even sure what they are called, any input on that is welcome :)\n","date":"15 June 2013","externalUrl":null,"permalink":"/posts/bugs-in-the-hedge/","section":"Posts","summary":"How else to throw away some time than just sitting still close to the hedge in the backyard waiting for some bugs to crawl by … strange what you can see when you go very close. These guys were either fighting, playing, or mating, not sure.\n","title":"Bugs in the hedge","type":"posts"},{"content":"Earlier this spring we rented a cabin from my employer, they have some few cabins around Norway for employees. This time my family went with my sister and her family to enjoy some days together. Very nice time with melting snow and a lot of fog, some rain and a wee bit of sunshine. Here are some of the shots I took while we were up there.\n","date":"14 June 2013","externalUrl":null,"permalink":"/posts/spring-cabin-visit-to-hemsedal/","section":"Posts","summary":"Earlier this spring we rented a cabin from my employer, they have some few cabins around Norway for employees. This time my family went with my sister and her family to enjoy some days together. Very nice time with melting snow and a lot of fog, some rain and a wee bit of sunshine. Here are some of the shots I took while we were up there.\n","title":"Spring cabin visit to Hemsedal","type":"posts"},{"content":"So when I was in the US I got some extension tubes for my Canon camera and this gives the opportunity to take extreme closeups with any standard lens. This is a \u0026ldquo;cheat\u0026rdquo; to turn any lens into a macro lens. Very well, I have tested with both my 18-250mm and the 50mm 1.4 and they both work great for macro shots. The 50mm is much more light sensitive and that means you need to go very close for the nice shots and that does not always work well with for instance insects and similar.\nHere are two examples that I have taken with my 18-250mm and all extension tubes connected giving 65mm distance from the lens to the sensor and the maximum macro.\nNote that using all tubes makes it very hard to get nice focus. Starting with fewer tubes and rather zoom and cut the image later might be a good idea.\n","date":"8 June 2013","externalUrl":null,"permalink":"/posts/macro-photography/","section":"Posts","summary":"So when I was in the US I got some extension tubes for my Canon camera and this gives the opportunity to take extreme closeups with any standard lens. This is a “cheat” to turn any lens into a macro lens. Very well, I have tested with both my 18-250mm and the 50mm 1.4 and they both work great for macro shots. The 50mm is much more light sensitive and that means you need to go very close for the nice shots and that does not always work well with for instance insects and similar.\n","title":"Macro photography","type":"posts"},{"content":"So when I was in the US I got some extension tubes for my Canon camera and this gives the opportunity to take extreme closeups with any standard lens. This is a \u0026ldquo;cheat\u0026rdquo; to turn any lens into a macro lens. Very well, I have tested with both my 18-250mm and the 50mm 1.4 and they both work great for macro shots. The 50mm is much more light sensitive and that means you need to go very close for the nice shots and that does not always work well with for instance insects and similar.\nHere are two examples that I have taken with my 18-250mm and all extension tubes connected giving 65mm distance from the lens to the sensor and the maximum macro.\nNote that using all tubes makes it very hard to get nice focus. Starting with fewer tubes and rather zoom and cut the image later might be a good idea.\n","date":"22 April 2013","externalUrl":null,"permalink":"/posts/macro-photography-2/","section":"Posts","summary":"So when I was in the US I got some extension tubes for my Canon camera and this gives the opportunity to take extreme closeups with any standard lens. This is a “cheat” to turn any lens into a macro lens. Very well, I have tested with both my 18-250mm and the 50mm 1.4 and they both work great for macro shots. The 50mm is much more light sensitive and that means you need to go very close for the nice shots and that does not always work well with for instance insects and similar.\n","title":"Macro photography","type":"posts"},{"content":"So today I played around with Lightroom 5 and had some fun. I was looking at the new Lens Correction setting and also the spot removal and healing tools. Quite fun actually and if I can get this good a result imagine what the professionals can do. :)\nBelow you can see both the final result and the before / after shot. What two things changed apart from the lens correction?\n\\ \\ ","date":"20 April 2013","externalUrl":null,"permalink":"/posts/lightroom-5-beta-fun/","section":"Posts","summary":"So today I played around with Lightroom 5 and had some fun. I was looking at the new Lens Correction setting and also the spot removal and healing tools. Quite fun actually and if I can get this good a result imagine what the professionals can do. :)\n","title":"Lightroom 5 Beta Fun","type":"posts"},{"content":"Tweets by @sbarmen\n","date":"14 April 2013","externalUrl":null,"permalink":"/twitter-feed/","section":"Pages","summary":"Tweets by @sbarmen\n","title":"Twitter Feed","type":"pages"},{"content":"My mother and Jan has built this cabin on Barmøyna on Barmen. This location is just wonderful and we love to travel there for holidays. Sadly it is quite far to drive so we are not there as often as we want to :)\nVis Barmen - Havørna i et større kart ","date":"14 April 2013","externalUrl":null,"permalink":"/posts/havorna-cabin-on-barmen/","section":"Posts","summary":"My mother and Jan has built this cabin on Barmøyna on Barmen. This location is just wonderful and we love to travel there for holidays. Sadly it is quite far to drive so we are not there as often as we want to :)\n","title":"Havørna Cabin on Barmen","type":"posts"},{"content":"Ok so finally my new blogg is coming together and even though not perfect at least it looks OK now. Was browsing through some old photos and came across these, you where it is? The images were taken in 2002 and they do contain geo information if you know how to extract that :)\n[learn_more caption=\u0026ldquo;Open this box for the answer:\u0026rdquo;]\nThese images are from Hopdalen, in Vedvik where my grandmother and grandfather lived. This was actually the home my grandfather lived his whole life I believe. The house has now been sold to a new family and from what I know they are enjoying and taking care of it like it deserves and that is good.\nClick this button Google Maps for more information: [button link=\u0026ldquo;http://goo.gl/maps/9UmhU\"] Google Maps[/button]\n[/learn_more]\n","date":"14 April 2013","externalUrl":null,"permalink":"/posts/where-is-this/","section":"Posts","summary":"Ok so finally my new blogg is coming together and even though not perfect at least it looks OK now. Was browsing through some old photos and came across these, you where it is? The images were taken in 2002 and they do contain geo information if you know how to extract that :)\n","title":"Where is this?","type":"posts"},{"content":"In the summer of 2012 we visited a lot of Italy and drove from Rome to Rafadali on Sicilia and back up again. This was a very interesting trip where we got to see a lot of the cities as-well as the more rural side of Italy.\n","date":"12 April 2013","externalUrl":null,"permalink":"/posts/travels-in-italy/","section":"Posts","summary":"In the summer of 2012 we visited a lot of Italy and drove from Rome to Rafadali on Sicilia and back up again. This was a very interesting trip where we got to see a lot of the cities as-well as the more rural side of Italy.\n","title":"Travels in Italy","type":"posts"},{"content":"Photos from our Safari trip in South-Africa in 2010. We had a great time in Pilanesbarg national park just outside of Pretoria. The whole area is protected and you can go on guided tours, and we have done that twice. Every time a great experience. For more information about Pilanesberg park, please see here: http://www.pilanesberg-game-reserve.co.za/\nWe learned later that “Steroids” was put to sleep as he harassed many visitors to the reserve and he enjoyed playing with the cars. Sad story but understandable.\nThe big elephant, named “Steroids” almost pushed us off the road. We have made a video of the whole incident that is on YouTube, please have a look:\n\\http://www.youtube.com/watch?v=6q7-yKrvv7w\\\n","date":"12 April 2013","externalUrl":null,"permalink":"/posts/safari-in-south-africa/","section":"Posts","summary":"Photos from our Safari trip in South-Africa in 2010. We had a great time in Pilanesbarg national park just outside of Pretoria. The whole area is protected and you can go on guided tours, and we have done that twice. Every time a great experience. For more information about Pilanesberg park, please see here: http://www.pilanesberg-game-reserve.co.za/\n","title":"Safari in South Africa","type":"posts"},{"content":"My family blog: www.barmen.nu My open source XMPP Server: www.jabber.no\n","date":"12 April 2013","externalUrl":null,"permalink":"/links/","section":"Pages","summary":"My family blog: www.barmen.nu My open source XMPP Server: www.jabber.no\n","title":"Links","type":"pages"},{"content":"If you need to contact me use the following form:\n[contact-form subject=\u0026lsquo;Contact form stian.barmen.nu\u0026rsquo;][contact-field label=\u0026lsquo;Name\u0026rsquo; type=\u0026lsquo;name\u0026rsquo; required=\u0026lsquo;1\u0026rsquo;/][contact-field label=\u0026lsquo;Email\u0026rsquo; type=\u0026lsquo;email\u0026rsquo; required=\u0026lsquo;1\u0026rsquo;/][contact-field label=\u0026lsquo;Website\u0026rsquo; type=\u0026lsquo;url\u0026rsquo;/][contact-field label=\u0026lsquo;Comment\u0026rsquo; type=\u0026lsquo;textarea\u0026rsquo; required=\u0026lsquo;1\u0026rsquo;/][/contact-form]\n","date":"12 April 2013","externalUrl":null,"permalink":"/contact/","section":"Pages","summary":"If you need to contact me use the following form:\n[contact-form subject=‘Contact form stian.barmen.nu’][contact-field label=‘Name’ type=‘name’ required=‘1’/][contact-field label=‘Email’ type=‘email’ required=‘1’/][contact-field label=‘Website’ type=‘url’/][contact-field label=‘Comment’ type=‘textarea’ required=‘1’/][/contact-form]\n","title":"Contact","type":"pages"},{"content":"Here are some photos from 2012 when we drove via Trollstigen on our way from Molde to Måløy. Trollstigen is a serpentine mountain road in Rauma, Norway that is very famous and attracts tourists from near and far. The mountains closeby also attracts a lot of basejumpers and other “risktakers”.\nThe road itself is to parts quite narrow and can be a bit scary for the faint of heart. Last years there have been made improvements and enhancements to the most critical parts so you can safely traverse with a normal size car and small RVs or even buses.\n","date":"12 April 2013","externalUrl":null,"permalink":"/posts/trollstigen/","section":"Posts","summary":"Here are some photos from 2012 when we drove via Trollstigen on our way from Molde to Måløy. Trollstigen is a serpentine mountain road in Rauma, Norway that is very famous and attracts tourists from near and far. The mountains closeby also attracts a lot of basejumpers and other “risktakers”.\n","title":"Trollstigen","type":"posts"},{"content":"Having had some few nice days in the summertime at the wonderful island of Barmen in Nordfjord we got to enjoy some magnificant sunsets and of course I had to capture them with my camera. With the use of a zoom lens and a tripod I got some quite nice shots.\n","date":"12 April 2013","externalUrl":null,"permalink":"/posts/photos-from-barmen/","section":"Posts","summary":"Having had some few nice days in the summertime at the wonderful island of Barmen in Nordfjord we got to enjoy some magnificant sunsets and of course I had to capture them with my camera. With the use of a zoom lens and a tripod I got some quite nice shots.\n","title":"Photos from Barmen","type":"posts"},{"content":" $ whoami stian - Chief Technology Officer, Proact IT Norge $ ls hobbies/ family/ photography/ boat/ travel/ homelab/ Hi, I\u0026rsquo;m Stian. By day I lead technology at Proact IT Norge, where I\u0026rsquo;ve spent years working with infrastructure, storage, and cloud — the kind of thing that occasionally spills over into the posts here.\nOutside of work it\u0026rsquo;s family (a wife and three kids), photography, the boat, travel, and whatever home-lab project is currently threatening to eat a weekend. This site has no grand mission beyond writing about what interests me and posting more photos than is probably reasonable.\nFind me elsewhere:\nLinkedIn GitHub X / Twitter Instagram YouTube ","date":"8 April 2013","externalUrl":null,"permalink":"/about/","section":"","summary":"$ whoami stian - Chief Technology Officer, Proact IT Norge $ ls hobbies/ family/ photography/ boat/ travel/ homelab/ Hi, I’m Stian. By day I lead technology at Proact IT Norge, where I’ve spent years working with infrastructure, storage, and cloud — the kind of thing that occasionally spills over into the posts here.\n","title":"About","type":"page"},{"content":"","externalUrl":null,"permalink":"/tags/","section":"Tags","summary":"","title":"Tags","type":"tags"}]