daniskarma
@daniskarma@lemmy.dbzer0.com
- Comment on Can you run multiple servers on one machine (e.g. Raspberry Pi)? 4 days ago:
I have like 30 different services running on the same machine.
That’s why you want to use some container solution, I use docker for simplicity.
Also raspberry pi is not great for self hosting. Any cheap x64 machine will be much more powerful for the same price, and have less compatibility issues.
- Comment on How "secure" is your setup? 1 week ago:
I’m a little paranoid, so this is my security set up.
SSH, blocked at firewall level, only allowing specific local IP to access port 22. Also authentication is done by key, with password disabled.
Most services are local only and I access them through wireguard VPN when I’m outside my home.
For services that need a domain name and be public facing, I use a reverse proxy, with the following protections:
- Very restrictive geoIP block, only my country can access.
- Restrictive rate limiting.
- Crodwsec, with community lists, a pluging for open lists, community rules and my own very restrictive set of rules for banning attackers. (For instance as soon as the requested path contains “.env” that’s an instant ban, no second chances).
- Monitoring through grafana.
- Some complex services that need a valid tls handshake but I only want to use them myself have a setup when they are technically open to the net, to get let’s encrypt, but the server rejects every IP request but mine.
Recently I also reduced some noise, surface attack, deleting the A register from my second level domain and using an obscured target for the CNAME records. I also want to delete the www subdomain as it gets a lot of uneeded noise.
- Comment on AI bot hacking/scraping Home Assistant 2 weeks ago:
You have anything online you will be hammered by bots trying to get through. That’s the sad reality of the world we live on. It has been like that forever. I get hundreds of bot malicious scans on my server each day.
All that’s left is to secure everything as hard as you can so they cannot break through.
- Comment on A solar powered website that goes offline when there's no power 1 month ago:
I didn’t turn it down, so it’s obviously up.
- Comment on Do you participate in this hobby without a formal IT education or a career in a 1 month ago:
I professionally work in IT without formal education or any related career. It’s one field where you can really teach everything yourself with free online resources.
- Comment on You Can't Buy Airless MTB Tires—So I Made Them! 1 month ago:
Afaik you could buy airless. It has been a commercial product for decades.
- Comment on Thoughts on crowdsec 2 months ago:
Precog bouncer. Asigned to the daemon of future cybercrimes. Obviously.
- Comment on Thoughts on crowdsec 2 months ago:
I’m using it. It’s good. Even without the cloud services the bouncer and scenarios are more powerful than fail2ban.
Shame about no self hosted web ui but someone posted here a project I’m ought to look up oncw I arrive home.
- Comment on Most slopcode projects are abandoned and deleted within months of release 2 months ago:
Also it’s again the false sense of security pf “if you don’t use vibed apps you’ll be fine”, making people forget basic security procedures.
I, for instance, had a service vulnerable and discontinued without noticing for months. It was something 100% made before LLM was a thing. Still had unpatched vulnerabilities and the project was abandoned. It was my fault for not checking more often is the services I host are safe or not.
- Comment on Continuwuity 3 months ago:
When they have good names they get stolen.
Try took up about gemini protocol.