The first publicly open instance
from Kkk2237pl@lemmy.world to selfhosted@lemmy.world on 31 May 12:45
https://lemmy.world/post/47575822

I want to start with self hosting something available from internet. Currently I have jellyfin, nas etc but everything is available in local network.

My biggest concern is securing local network. I thought i will run application on separate server, I will use small vps as proxy, but Im not sure if it will be enough

#selfhosted

threaded - newest

bjoern_tantau@swg-empire.de on 31 May 12:58 next collapse

To mitigate the risks you could put the local server into its own network where it cannot reach anything else in your home.

abeorch@friendica.ginestes.es on 31 May 13:17 next collapse

@Kkk2237pl What are you using for a router? A good uptodate version of something like ooenwrt, a separate subnet running on a different vnet and firewall zone.

Why the vps?

Kkk2237pl@lemmy.world on 31 May 13:26 collapse

Deco

abeorch@friendica.ginestes.es on 31 May 13:37 collapse

@Kkk2237pl Im no expert so you know take everything with a grain of salt but for me i flash all my routers with #openwrt including #tplink stuff... Butnthat gives me everything i need.

You probably do.everything with stock firmware though

kythrea@lemmy.world on 31 May 14:01 next collapse

I run my server on the internet, and my security is crowdsec + geo ip block (well, white-list my country’s ip but same idea) and authelia.

Using this setup, I barely ever have even bots randomly pingig me, let alone anyone trying to access my NAS.

androidul@lemmy.world on 31 May 14:08 next collapse

I was pondering the same for last couple of days and had some thoughts on how to make it feasible. My research led me so far to 2 prerequisites:

  1. must have Anubis in front
  2. must have a WAF solution in place that covers at least OWASP Top 10

I found pretty good Caddy documentation that covers both, so I think I’ll deploy a secondary Caddy reverse proxy that’ll perform such ops for public facing services.

Of course, I currently have only 1 Caddy instance reverse proxy ing my internal services, haven’t reached the part on traffic handling when my devices are connected to the “safe network” (aka my home LAN)

abeorch@friendica.ginestes.es on 31 May 14:45 collapse

@Kkk2237pl Can I suggest that you start with something simple where as much as possible is templated - im like a broken record on this but i use #yunohost simply because heaps of people are using the same config.