• grue@lemmy.world
    link
    fedilink
    English
    arrow-up
    65
    ·
    19 days ago

    My stuff is only accessible from my LAN (because I haven’t figured out how to set up a tunnel or reverse proxy yet).

      • grue@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        19 days ago

        I’ve tried to use ZeroTier because Tailscale still has centralized servers for starting the connection, but had trouble getting it to work. Maybe I should stop letting the perfect be the enemy of the good.

        • lemmyvore@feddit.nl
          link
          fedilink
          English
          arrow-up
          5
          ·
          19 days ago

          If you have good IPv6 connectivity both at home and away you can look into the Yggdrasil network. It facilitates node-to-node encrypted communications, but it’s decentralized and community-run. Unlike Tailscale, each node can do both communication and relay.

          You run the Y client on each device you want to use and if you want to keep things completely private (and you have at least one device that’s not behind CGNAT) you can only add your own devices as peers. If you need to bypass CGNAT you can use one of the community-supplied nodes to act as relays, or set up your own node on a VPS.

          The cool feature of Y is that if you’re trying to communicate between nodes A and B and there isn’t a single node that’s peered with both A and B, you can still communicate as long as there are nodes somewhere in the network that know them both. The network will search for you and calculate the optimal relay path. Ofc like I said this is irrelevant if you decide to stick to your own devices, basically you will have your own personal mini Y network completely separate from the main public network.

          Even when using the public network there’s no privacy issue, relay nodes cannot snoop on communications only facilitate the connection or not, and once relay to a node has been accomplished the nodes will communicate directly thanks to ICE+STUN, if possible, like Tailscale does.

          Please note that nodes are identified by 2001:: random addresses. While the 2001:: address space is huge it’s still only obscurity not security. You still need to have a decent firewall setup on each node, Y does not enforce ACLs or anything like that. It’s also up to you to set up DNS and anything else you might need.

      • Solrac@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        2
        ·
        19 days ago

        Screw Tailscale, ZeroTier and specially cloudflare, all centralized, all with changable terms.

        Use a VPS, lowest spec but good bandwidth, and use Wireguard VPN for your VPS and homeserver, and nginx or caddy to make a Reverse Proxy

        • reddit_sux@lemmy.world
          link
          fedilink
          English
          arrow-up
          8
          ·
          19 days ago

          All agreed but not every homelabber can spend money for something that is not the main job or contributed to work. Tailscale for now works well enough for free.

          Cloudflare agreed is not something I would trust.

          • seang96@spgrn.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            19 days ago

            You can get some pretty cheap ones like sub $10/year. My current ones 2 cpu 3.5gb ram 64gb ssd for $33 a year.

            • CausticFlames@sopuli.xyz
              link
              fedilink
              English
              arrow-up
              2
              ·
              18 days ago

              Where are you finding rates like that? Racknerds’ cheapest option is around that price but doesn’t even have 1 full gig of ram.

        • horus_son_of_isis@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          18 days ago

          I’m so close to doing this. Cloudflare makes me nervous. Have you heard of Rathole? That was recommended to basically do what my cloudflared tunnel is already doing. The only trouble I could see was I was going to have to keep the cloudflared access controls.

    • zebidiah@lemmy.ca
      link
      fedilink
      English
      arrow-up
      6
      ·
      19 days ago

      I’m in this boat too, my security is awful, bad practices everywhere, my solution: don’t let it go out in public…

  • Oha@lemmy.pobierz.net
    link
    fedilink
    arrow-up
    12
    ·
    19 days ago

    Every Service is in its own VM and everything thats publicly accessible sits in its own network sepperated from everything else. I do daily backups in case anything goes wrong

  • zenforyen@feddit.org
    link
    fedilink
    English
    arrow-up
    11
    ·
    19 days ago

    Nothing to protect if you don’t expose it.

    Plain and simple - Wireguard.

    All services run as separate services user in rootless podman containers.

    Only one nginx exposed to the open internet acting as reverse proxy to stuff where Wireguard requirement would be too inconvenient to be useful (shared calendar).

  • CameronDev@programming.dev
    link
    fedilink
    English
    arrow-up
    8
    ·
    20 days ago

    User process makes sense, but login shell is probably limited value. If your service gets pwn’d the attacker will spin up a reverse shell, and that isn’t protected by the login shell. You ideally want to use selinux/apparmor to prevent execution, or containers to limit the available execution environment.

  • lntl@lemmy.ml
    link
    fedilink
    English
    arrow-up
    7
    ·
    19 days ago

    I operate SSH, nginx, and uvicorn like this:

    SSH

    • pubkey auth only
    • not on default port
    • AllowUsers var in sshd.conf is set

    nginx

    • runs as its own user
    • serves static files or forwards to uvicorn
    • rate limits are set
    • returns 444 on requests that aren’t in sitemap.xml (nonsense and probing)

    uvicorn

    • runs as its own user

    and a firewall runs on top of everything in a hardened kernel. I’m self taught, so I could be missing something obvious and this setup has been reliable for me for a few years.

    • jello@programming.dev
      link
      fedilink
      English
      arrow-up
      3
      ·
      19 days ago

      Do you have any sort of access limiting, either by whitelist (e.g. Tailscale), or blacklist (e.g. Crowd-Sec)?

      • lntl@lemmy.ml
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        19 days ago

        Nope, I’m accessible on the WAN and the webserver is intentionally public facing.

        Edit: AllowUsers in sshd.conf is my access control

  • K3CAN@lemmy.radio
    link
    fedilink
    English
    arrow-up
    5
    ·
    18 days ago

    If you’re talking about remote access specifically, I use tiers.

    “Public” is open, but goes through crowdsec and anubis, and is on a DMZ network. This is my website, blog, Fediverse, etc.

    “Private” is either secured with mtls or wireguard. This is stuff that’s only for me or family, like media or home assistant.

    “Sensitive” is wireguard only. This is infrastructure management, Paperless, etc.

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    15 days ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    CGNAT Carrier-Grade NAT
    DNS Domain Name Service/System
    Git Popular version control system, primarily for code
    LXC Linux Containers
    NAT Network Address Translation
    SSH Secure Shell for remote terminal access
    TLS Transport Layer Security, supersedes SSL
    UDP User Datagram Protocol, for real-time communications
    VNC Virtual Network Computing for remote desktop access
    VPN Virtual Private Network
    VPS Virtual Private Server (opposed to shared hosting)
    nginx Popular HTTP server

    [Thread #105 for this comm, first seen 16th Sep 2026, 06:30] [FAQ] [Full list] [Contact] [Source code]

  • Lucy :3@feddit.org
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    19 days ago

    Everything runs through fully hardened/restricted systemd units, as separate user with minimal access rights for everything

    You’d need to escape the software, restrictions and get root to do anything meaningful, while avoiding detection

  • curbstickle_lw@lemmy.worldM
    link
    fedilink
    English
    arrow-up
    5
    ·
    19 days ago

    Secure enough I suppose.

    f2b at the FW, auth with MFA for anything exposed, anything local only has restricted access at the FW level, with exposed (via proxy) and local-only (separate proxy) on different vlans. Each service is (typically, with some exceptions) an LXC, with additional rules and templated out based on use case. The few cases where docker is involved is local-only and that has its own vlan with additional rules.