+1 to NPM. Works really easily for certs and auto renewal.
Aka csm10495 on kbin.social
+1 to NPM. Works really easily for certs and auto renewal.
Exactly the same boat. But man Cloudflare is better in every way. Having an API to update/fetch records for a zone does wonders.
deleted by creator
LinkedIn has over a billion users. I got a t-shirt for it.
In theory you could generate a wildcard to a domain then use it.
Self hosted. Though hey someone may wind up here via all and scroll and wonder what else there is.
If you have Prime and aren’t insisting on self hosting: Amazon Photos gives you unlimited full quality photo backups.
Terrible idea of the day: You could use something like NFS and map the drive on all clients. On that drive you can have the latest keys then use symlinking to update, etc.
Something like puppet, chef, ansible are likely better choices.
I’ll put a recommendation out for if you’re going to open ports: use abnormal ports. Someone is likely to try to hit your port 22 for ssh, but not your port 49231.
Edit: It’s definitely some security by obscurity. Still use a strong password or keys.
For people who don’t mind it not being self hosted: Authy is good for this. You can also set a backup password (to encrypt your tokens on their servers) and optionally use it cross device.
You can allow multi device temporarily to setup, then disable to not allow new devices, etc.
(I get you didn’t ask this specifically, but figure it could be useful to someone else).
Yeah… but I think its overkill. The root cert would be on the same box somewhere nearby. Compromising the host has the same issue as plaintext.
This is likely a too late, but reasonable moment to say this server happens to be Windows based.
… for backup reasons.
(The tool used for online backup only allows home versions of Windows and local drives)
One day if I build a new one, I might start with a Linux base, though that kind of requires this one to be on its last leg before I get to that point. It’s running a processor/mobo that are 14ish years old… so maybe I should think more about it.
I think you hit the nail on the head with the true security being black box. The moment I need access, I’m making a hole.
I guess at the end of the day there is also a root of trust. In an enterprise setting a system giving out certs could be compromised and give out certs to the wrong people/machines. In a home setting, the machine being compromised has a similar affect.
Funny enough, I thought of using a USB stick or something as a physical security key, using that for a vault, then having secrets in the vault… but then realized I’d have to leave it plugged into the server, making it so anyone with server access would get the password anyways.
Makes me think that everything is security by obscurity at some level. The more obscure: the more ‘secure’.
It’s kind of like how an SSH key is generally considered more secure, but if I used password authentication and had a file with a 512 character random password, it would be more/less the same thing. Either way, we have the key in a file.
The problem is that would be so annoying/impractical. In an optimal world, yeah a person checking a prompt and approving could make sense, but in practice that would also mean that the MFA prompt would have to ask for the password anyways. (Or the password would be on the phone with the same problem as on the computer).
Can you imagine having to type a password on an hourly schedule or something? If the password was cached, we have the same problem again.
If you have media: Plex.
YSK: the steamdeck is on sale right now for 10 to 20% off depending on the configuration. I just can’t find a use case for it for myself. I play a bit of Fortnite on PC and otherwise don’t play much at all.
The basics can be useful there. The whole idea with k8s is to be able to run applications across multiple hosts in a given fleet. Your cluster can be that fleet! :)
Unless you have multiple systems, I don’t think k8s will yield much benefit over plain docker.
Recommend cloudflare for DNS. I use it for DDNS via API and it works great.
You also basically pay the wholesale rate without markup for the domain.