Skip Navigation

𝓢𝓮𝓮𝓙𝓪𝔂𝓔𝓶𝓶

@ SeeJayEmm @lemmy.procrastinati.org

Posts
19
Comments
582
Joined
2 yr. ago

  • I'm still curious tho. I'll probably set it up for some internal only sites to test.

  • I wish I'd seen this before the minor hell I went through learning how to geoip block via iptables. 😁

    It looks interesting. I think my only real concern is security. There's a lot of people using and working on nginx so, presumably, more people to identify bugs and squash them.

  • And even if you do everything 100% right, your emails will mostly get flagged as spam if not outright blocked anyway. Esp. if you're using a residential IP.

  • Plus, the internal and external services are running on the same box. Is that where my real problem lies?

    It's one of them, yes.

    If you want to limit exposure in the case of a compromise you need to put everything public facing in it's own vlan that cannot initiate traffic into your lan.

  • Alternatively, I could have a reverse proxy in the DMZ only for the public service and another reverse proxy on the LAN for internal services.

    I do exactly this now. Public facing services sit in a dmz vlan with a rev proxy. I almost did a 2 tiered dmz but decided it was overkill.

    Private services sit on an inside vlan.

  • I agree with everything everyone else has said here but if you looking for the most basic solution it's already in NPM. You can configure basic auth in an access list and apply it to the site.

  • Route 53 does. I've got a couple there now.

  • Redundancy is really important when it effects other people, IMO. Personally I use 2 piholes kept in sync with gravity-sync.

  • Nah. Your question was fine. The person who responded to you was just wrong. Hopefully you've seen the other replies to their comment.

  • You can do most of not all of this with CheckMk but it's probably overkill.

  • I'm not having issues that I'm aware of, but that site always returns Network Request Failed and I haven't figured out why.

  • I'm sorry I don't have a suggestion but have you checked the Awesome Self Hosted list?

  • Id like to centralize auth but I haven't dug into it yet. My concern is, can it be distributed? I have services spread across my homelab and multiple vpses. I don't want to lose auth if any of those is down.

  • What about a while loop?

  • Ok I like this one. I'll be playing it again tomorrow. I'm showing my age but I used to love "Name that Tune" and I think this scratches that same itch.

    Bandle #578 2/6🟥🟩⬜⬜⬜⬜Found: 1/1 (100%)

  • I'm surprised I didn't see https://guessthe.game/ on this list. I try to play it every day, but you can really get lost going down the rabbit hole of all the previous day's games.

  • We're to the point now that my wife and I play Wordle, Connections, Strands, & the NYT mini crossword every day.

  • This is a nice little diversion. I don't know how good I did.

    #Rogule 2024-3-17🧝 4xp ⛩ 143 👣streak: 1🟩🟩🟩🟩🟩⚔ 🦇🐗🌰🌰⬜⬜⬜🍄

    https://rogule.com