Comment on Would you buy "self-hosted in a box" hardware?

<- View Parent
mspencer712@programming.dev ⁨2⁩ ⁨months⁩ ago

I’ve been struggling to wrap my head around a good security architecture for my mspencer.net replacement crap. Could I bug you for links?

I figured out a while ago to keep VM host management on a management VLAN, and I put each service VM on its own VLAN with heavy, service-specific firewalling and a private OS update repo mirror - but after hearing about ESXi jackpotting vulns and Broadcom shenanigans, I’ve gotten really disheartened. I’d love some safe defaults.

source
Sort:hotnewtop