Where does OP say that they only want resources and no answers at all? Also you sadly misquote me by stripping context, I replied that there’s a simple solution (and how specifically to look for it) to one of their questions if one condition if satisfied, and that the problem doesn’t have an easy answer otherwise, therefore needing more research. I went out of my way to give OP brief answers and more specific questions for research, like I do for my students, and you make it look like I just wrote RTFM.
Denys Nykula
From Kyiv, in Kyiv.
- 0 posts
- 7 comments
- 1 day
- 1 day
To your specific questions:
why people use traefik
Reverse proxies let you serve multiple apps from one server, encrypt your traffic and automate updates of encryption certificates. I use Apache (virtual hosts, mod_md) for this.
how and why to use docker containers
Modern web apps have many constantly shifting dependencies and don’t work closely with distributions on packaging them, so they have to be updated separately from the base system. They might also need different versions of these dependencies, and multiple instances of one dependency (e.g. database). Containers are one way to achieve that, and also ease backups, monitoring of individual apps, and installing an application in exact same way on development and testing machines.
what settings to change on the router
To expose ports 22 (ssh), 80 (http) and 443 (https) to world, forward them to your server.
how to connect and setup the domain
In the DNS settings for your domain, point “A” record to your home IP. That’s if you rent a static IP. If you don’t, things will be more complicated, research on your own.
how to do this safely
Bare minimum: set up daily backups of container volumes and reverse proxy configuration, same for updates of base system and containers, and turn off SSH password login in favor of keys. Test that a backup can be successfully restored in a virtual machine at least once a month.
What’s insecure about CGI? I thought the main reason it isn’t popular now is because runtimes are slow to start. Though IIRC when I used busybox httpd CGI with a small runtime, quickjs, speed wasn’t an issue.
To have logs from every container launch in journalctl, I have systemd run podman-compose without daemonizing it. To debug container logs, a shell is usually needed anyway, so I see little point in exposing logs through a web dashboard.
To add, journal-brief can e-mail you systemd logs. If your apps aren’t very noisy, this can be helpful without a need to set up a complex observability stack.
Apache has mod_md, a built-in LetsEncrypt-compatible module that requires very little configuration and no external daemons or cron jobs: https://httpd.apache.org/docs/2.4/mod/mod_md.html Three lines per virtual host: MDomain, MDContactEmail and MDCertificateAgreement. Using it in production for three years without any issue. I don’t know what’s Apache stance on LLMs, I guess neither for nor against.


In case of tests, I’ve seen not simply more code than necessary, but hundreds of line of generated test cases focusing on implementation details based on a badly worded issue description, without anyone bothering to check if the generated integration works at all. These test cases are an immediate dead weight for maintainers that make refactoring and fixing issues more difficult.