Gagootron

u/gagootron@feddit.org
5 posts · 45 comments

Recent posts

Recent comments

on Auth apps · c/selfhosted · 15 pts · 17d

I personally run authelia. I prefer the config file over a gui where i have to click everything together. For the actual user storage i got lldap.

But my requirements a possibly different to yours, my main focus was no docker and no javascript backend.

Keycloak is definetly overkill for a homelab. Both in effort to get it to run, and maintaining it.

bei mir hat die Kreditkarten Firma gesagt, dass die secure code und so nicht machen und das die deswegen gesperrt wird, aber bei mir ist das erst passiert als ich meinen Warenkorb mit 10 verschiedenen Alben kaufen wollte. nach 7 war Schluss.

The benfit of tang is that you don't store the secret on a shared server.

The server has a single keypair that it reuses for every client, and each client has thier own keypair.

The encryption key can only be recovered when the client and server perform thier handshake. And only the client gets the key, the server cannot see it.

A system like proxmox backup server can do this scurely. There you can create a user that can only add new backups and read the existing ones, but cannot delete any or read anything else on the remote host.

Otherwise if you only care to protect the remote machine, then something like an ssh chroot jail would also work.

on Welcome to 2025 · c/memes · 1 pts · 328d

Maybe you can enable bridge mode on it? Then you could run something like opnsense behind it.

on Welcome to 2025 · c/memes · 11 pts · 328d

What kind of router to you have? A good router should not crash from any amount WAN traffic. But yes, if you host anything you will get scanned even harder than usual.