Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)GO
Posts
15
Comments
531
Joined
2 yr. ago

  • I'm actually not from the "close everything, don't open ports, always sit behind cloudflare" camp

    We selfhost so we can use and share our services

    There are other things we can practice instead of just isolationism and keeping everything as simple as possible

  • There are many ways to do many things in nixos

    For updates you can do automatic updates

    Also, there are many deployment tools, like deploy-rs, morph, colmena, bento. They all have different approaches. Some you use ssh to deploy a remote system. Some just fetch the configuration and autodeploy it.

    There are many ways how you can play with this. So you can disable sudo, and deploy with ssh only from some or a specified ip. Or you can keep ssh for root disabled and just deploy home-manager. It's really a lot, you imagination is the only limit

    P.s. or you can just generate an image from a trusted machine, and flash it onto the device you want, unlimited number of ways

  • I'm a Nixos user, I wouldn't be much help unless you do Nixos. But it's a whole new rabbit hole which would take you months/years to learn and setup 😅

    What I can say, you can do "access from home network", "access from VPN network", "1fa/2fa from the internet" OR "access for / and /api, but 1fa/2fa for stuff like /admin, /admin-settings, or just /login or /logged-in"

    Fail2ban is fun, also maybe have a look at crowdsec

  • Notifications on system file access

    Notifications on root login/sudo

    Declarative OS, tmpfs root, disabled sudo

    Bastion server, but right now I don't have a proper router to do it at home

    Yubikey, or a separate phone on Graphene OS for otp, keys, etc

    Authelia + fascist fail2ban (or some CSF)

    Most of these are pretty normal, but usually you don't do them all at once 😄 also, I don't really like hiding my services from the open internet, authelia is fine tuned to let people only access what they are supposed to. And regular users of my server usually don't notice that I even have it

  • For me it sounds more like: i like these features, what your option can offer, let's discuss

    I mean, other commenters can read the post, they can see other options, but they all just flood "Firefox", with no explanation or comparison, etc

    To a very lazy and uninformative message, there a very lazy and uninformative reply