steveipw
Member
OP
- Joined:
- Jun 2024
- Posts:
- 163
- From:
- Denver, US
So I grabbed a .dev for my homelab dashboard. Pointed it at my Contabo VPS. Immediately got HSTS errors in every browser. Couldnt even click through.
Turns out .dev is on the preload list. Forces HTTPS. My dev server is plain HTTP behind a reverse proxy I hadnt configured yet.
Workarounds ive found:
- Use a self-signed cert, browsers still complain
- Local hosts file with .local instead
- Buy a real cert for a dev box
For that money you get better off using .test from the start. Learned this the hard way. Anyone else hit this?
zfs send | zfs receive. repeat.
uma
Member
99.99% or bust
- Joined:
- Jun 2024
- Posts:
- 324
- From:
- Dublin, IE
Rfc 2606 says.. use .test.. .example.. .localhost.. .invalid..
.dev is real gTLD.. not for internal use..
You bought wrong thing.. happens to everyone..
436 days. reboot is surrender.
armstrongvds
Member
ARM Enjoyer
- Joined:
- Jun 2024
- Posts:
- 199
- From:
- Seoul, KR
Just run Caddy! Automatic HTTPS! Insane value!
I have Ampere Altra at home, ARM64, runs circles around x86 for this workload. Caddy + Vultr VPS as origin, local ARM box as dev server. Works perfectly!
For.dev you NEED valid cert. Lets Encrypt is free. No excuse!
Specs of my setup:
- Ampere Altra Q80-30
- 32GB DDR4
- Caddy v2.7
- Vultr VPS 2GB as failover
HSTS preload is feature not bug!
one small ping for man...
Doug
Member
New Jersey
- Joined:
- Jul 2024
- Posts:
- 271
- From:
- New Jersey, US
grabs popcorn, checks /r/drama