Quasarke Forums
  • Communities
  • Multi-communities
  • Support Lemmy
  • Search
  • Login
Selfhosted@lemmy.worldbysoyslurper2@lemmy.dbzer0.com
4 days

How "secure" is your setup?

English

What setups/softwares do you use to secure your server?

All I do is run the process as user with no login shell.

The topic came to mind after reading this post Is Authelia enough without fail2ban or crowdsec?

17
    You must log in or register to comment.

    • daniskarma@lemmy.dbzer0.comEnglish
      2 days

      I’m a little paranoid, so this is my security set up.

      SSH, blocked at firewall level, only allowing specific local IP to access port 22. Also authentication is done by key, with password disabled.

      Most services are local only and I access them through wireguard VPN when I’m outside my home.

      For services that need a domain name and be public facing, I use a reverse proxy, with the following protections:

      • Very restrictive geoIP block, only my country can access.
      • Restrictive rate limiting.
      • Crodwsec, with community lists, a pluging for open lists, community rules and my own very restrictive set of rules for banning attackers. (For instance as soon as the requested path contains “.env” that’s an instant ban, no second chances).
      • Monitoring through grafana.
      • Some complex services that need a valid tls handshake but I only want to use them myself have a setup when they are technically open to the net, to get let’s encrypt, but the server rejects every IP request but mine.

      Recently I also reduced some noise, surface attack, deleting the A register from my second level domain and using an obscured target for the CNAME records. I also want to delete the www subdomain as it gets a lot of uneeded noise.

      • silfer@lemmy.worldEnglish
        2 days

        Reverse proxy for services for friends and family

        Tailscale for my remote services

        Basically everything is in docker containers.

        • zenforyen@feddit.orgEnglish
          3 days

          Nothing to protect if you don’t expose it.

          Plain and simple - Wireguard.

          All services run as separate services user in rootless podman containers.

          Only one nginx exposed to the open internet acting as reverse proxy to stuff where Wireguard requirement would be too inconvenient to be useful (shared calendar).

          • notSys@lemmy.cafeEnglish
            4 days

            I run an AI Agent as root and let it manage everything

              • NotSteve_@lemmy.caEnglish
                8 hours

                Oh, I see you work at the cyber security firm I used to work for

                • El_Quentinator@lemmy.worldEnglish
                  3 days

                  Root in a rootless container, right? Right Anakin?

                    • notSys@lemmy.cafeEnglish
                      3 days

                      Nah. It’s funnier this way

                    • UnrefinedChihuahua@lemmy.dbzer0.comEnglish
                      3 days

                      CEO material.

                    • empireOfLove2@lemmy.dbzer0.comEnglish
                      4 days

                      it’s so secure not even I, the owner can get in
                      (I forgot the password to truenas scale)

                      • grue@lemmy.worldEnglish
                        4 days

                        My stuff is only accessible from my LAN (because I haven’t figured out how to set up a tunnel or reverse proxy yet).

                          • reddit_sux@lemmy.worldEnglish
                            4 days

                            Tailscale is your friend.

                              • Solrac@lemmy.worldEnglish
                                3 days

                                Screw Tailscale, ZeroTier and specially cloudflare, all centralized, all with changable terms.

                                Use a VPS, lowest spec but good bandwidth, and use Wireguard VPN for your VPS and homeserver, and nginx or caddy to make a Reverse Proxy

                                  • reddit_sux@lemmy.worldEnglish
                                    3 days

                                    All agreed but not every homelabber can spend money for something that is not the main job or contributed to work. Tailscale for now works well enough for free.

                                    Cloudflare agreed is not something I would trust.

                              • ‮zcm🍰@lemmy.worldEnglish
                                4 days

                                My setup is airgapped (everything is wireless).

                                  • floofloof@lemmy.caEnglish
                                    4 days

                                    Can’t tell if joke.

                                      • Elvith Ma'for@feddit.orgEnglish
                                        4 days

                                        Here, have some WiFi cable - I have plenty of it left!

                                    • Decronym@lemmy.decronym.xyzbot accountEnglish
                                      8 hours

                                      Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

                                      Fewer Letters More Letters
                                      CGNAT Carrier-Grade NAT
                                      DNS Domain Name Service/System
                                      Git Popular version control system, primarily for code
                                      LXC Linux Containers
                                      NAT Network Address Translation
                                      SSH Secure Shell for remote terminal access
                                      TLS Transport Layer Security, supersedes SSL
                                      VNC Virtual Network Computing for remote desktop access
                                      VPN Virtual Private Network
                                      VPS Virtual Private Server (opposed to shared hosting)
                                      nginx Popular HTTP server

                                      10 acronyms in this thread; the most compressed thread commented on today has 6 acronyms.

                                      [Thread #105 for this comm, first seen 16th Sep 2026, 06:30] [FAQ] [Full list] [Contact] [Source code]

                                      Selfhosted@lemmy.world

                                      selfhosted@lemmy.world

                                      Subscribe from remote instance

                                      Create post

                                      Report community

                                      Modlog
                                      You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !selfhosted@lemmy.world

                                      A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

                                      Rules:

                                      Detailed Rules Post

                                      1. Be civil.

                                      2. No spam.

                                      3. Posts are to be related to self-hosting.

                                      4. Don’t duplicate the full text of your blog or readme if you’re providing a link.

                                      5. Submission headline should match the article title.

                                      6. No trolling.

                                      7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

                                      8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

                                      Resources:

                                      • selfh.st Newsletter and index of selfhosted software and apps
                                      • awesome-selfhosted software
                                      • awesome-sysadmin resources
                                      • Self-Hosted Podcast from Jupiter Broadcasting

                                      Any issues on the community? Report it using the report flag.

                                      Questions? DM the mods!

                                      Visibility: Public

                                      This community is visible to everyone.

                                      793 users / Day0 users / Week0 users / Month0 users / 6 months26 posts335 comments1 local subscriber0 subscribers
                                      • BE: 1.0.0-beta.2
                                      • Modlog
                                      • Instances
                                      • Docs
                                      • Code
                                      • join-lemmy.org