chunkystyles
@chunkystyles@sopuli.xyz
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 1 week ago:
You say. Confidently. With no receipts.
- Comment on Insulated sous-vide container I made 2 weeks ago:
I have some similar things with old coolers. I love doing chuck roast or pork shoulder for 48 hours. So it’s nice to have something insulated with a lid.
- Comment on My Homelab Got Hacked - A Postmortem – Phunky Cafe 3 weeks ago:
I just recently went through a much more benign, but scary nonetheless version of this.
I realized that my Ansible directory, that I had made public on GitHub to share as an example to some folks, had secrets committed and pushed.
It was the direct URL and credentials of an app I developed to store non-PII customer data. Now, it wouldn’t be the end of the world if someone noticed this and scraped the data, but it wouldn’t be good, either.
Luckily, I have Caddy access logs, and it appears no one ever accessed it.
So I pulled the secrets out of the Ansible directory and made the repo private, I rotated the credentials, and installed Crowdsec to monitor Caddy access logs and ban bad actors.
I only noticed the secrets because I had just setup Authelia as an OAuth2 provider for my homelab, and I was adding it to my backup scripts.
- Comment on Why do people host RSS? 1 month ago:
I was devastated when Google Reader shut down. I switched to another service after that and it shut down not long after that. Maybe a year or so.
I would have paid for that service at the time.
- Comment on How I self-host my ebooks and audiobooks 2 months ago:
Regarding certificates. I use Caddy for things like that. Even stuff that I don’t want publicly available. It is technically public, but relatively secure.
I use a combination of basic authentication plus a rate limit so the password cannot be brute forced. And then I have a bypass so that auth is not required on my home network. I think it works pretty well.