Lyricism6055

joined 1 year ago
[–] Lyricism6055@lemmy.world 1 points 1 day ago

Yeah what you're talking about is a DMZ, it still won't help a ton if you don't have strict firewall controls inside your network too.

I just use wireguard with firewall rules to restrict to just my server with my docker containers on it and my DNS

[–] Lyricism6055@lemmy.world 0 points 1 day ago* (last edited 1 day ago)

I still use a reverse proxy, but to get into my network you need to be on VPN. It's more secure for me I guess.

I use traefik forward auth, even inside my network on VPN, for an extra layer of security for some apps.

My opinion is that port 443 getting accidentally misconfigured by me is just too likely a scenario. With wireguard on my router I also am able to restrict traffic to ONLY my webserver and DNS servers for my devices.

So I guess that's another positive of wireguard, you can use your own DNS servers for all your phones all the time and always have ad blocking with pihole or something similar, even on mobile.

By using VPN I don't have to worry about accidentally exposing a website with a copy paste error or something over my reverse proxy. I can also easily restrict who has access to my VPN and do routing rules from my router per device or subnet (for people who aren't in my family I have a separate subnet I assign with more strict firewall rules)

[–] Lyricism6055@lemmy.world 1 points 1 day ago

I ended up buying one that flips around and can do A and C connections

[–] Lyricism6055@lemmy.world 7 points 1 day ago (2 children)

If this server is publicly accessible and gets pwned, they can use it as a jump box for your internal devices.

[–] Lyricism6055@lemmy.world 2 points 1 day ago (4 children)

Just close 443 and use VPN with ACME DNS challenges for your certs. That'll help make it even more secure, nothing is full proof though and a VPN is a good first step

[–] Lyricism6055@lemmy.world 1 points 3 days ago

Ofc, but then you now have a dependency on a specific version of ffmpeg for your root OS

[–] Lyricism6055@lemmy.world 1 points 4 days ago (2 children)

Just had an example of this working for me. Parsec only publishes a .deb file, and the flatpak is out of date / unmaintained. They don't have Nvidia decoding anywhere but Ubuntu. But with distrobox / boxbuddy I can get a fully-featured parsec install that runs on a distrobox. Works perfectly, and even has an application in my host application menu. It's bad ass

[–] Lyricism6055@lemmy.world 1 points 5 days ago

I meant for bazzite. You can use an arch distrobox and it'll be like you had arch installed already

[–] Lyricism6055@lemmy.world 1 points 6 days ago (5 children)

Yup, but now I get to use whatever distro I want with distrobox. It's awesome

[–] Lyricism6055@lemmy.world 1 points 6 days ago (7 children)

I've installed .deb files before that fail or miss dependencies, then you get stuck in a half applied state and have to force fix your apt packages.

I'm not saying I'm doing it right, but its happened before more than a few times to me, but not on bazzite

[–] Lyricism6055@lemmy.world 2 points 6 days ago (9 children)

Yeah, until that one time when you tell apt to force install a package and it fucks your entire system...

[–] Lyricism6055@lemmy.world 1 points 1 week ago (1 children)

I'm judging moms with no reason not to breastfeed for doing it. That's all

If you have a medical issue, or you're a single father, etc ... Then I'm not judging.

Either way, im just a random guy on the internet and my opinion doesn't really matter in the grand scheme of life

view more: next ›