Is it practically impossible for a newcomer selfhost without using centralised services, and get DDOSed or hacked?
thirdBreakfast @ thirdBreakfast @lemmy.world Posts 19Comments 194Joined 2 yr. ago

thirdBreakfast @ thirdBreakfast @lemmy.world
Posts
19
Comments
194
Joined
2 yr. ago
Yeah na, put your home services in Tailscale, and for your VPS services set up the firewall for HTTP, HTTPS and SSH only, no root login, use keys, and run fail2ban to make hacking your SSH expensive. You're a much smaller target than you think - really it's just bots knocking on your door and they don't have a profit motive for a DDOS.
From your description, I'd have the website on a VPS, and Immich at home behind TailScale. Job's a goodun.