Hey everyone,
I’m looking for some insights to confirm if my home server’s security is up to par against common cyber threats. Here’s a brief rundown of my setup:
External Ports: I’ve limited external access to only three ports:
Hardware:
Network:
Docker:
network_mode: bridge
.Internet-Facing Services:
Firewall:
Given this setup, do you think my security measures are sufficient? I’m particularly curious about the risks associated with my Docker containers and the exposed ports. Any recommendations or best practices you could share would be greatly appreciated!
Thanks in advance for your help!
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.
Rules:
Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.
No spam posting.
Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.
Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.
Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).
No trolling.
Resources:
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
Exposed parts can be messy if you’re not used to them.
Easiest option would be to have a VPS set up as a VPN server with the ports you need forwarded to it, and your applications connecting to it. If you don’t want the extra maintenance, Cloudflare tunnels for you. Racknerd boxes are $1/month.
Docker containers run as root by default. Either change the flag or switch to podman if you don’t need root access for your containers.
Time to get a router compatible with OpenWRT/OPNsense.
There probably are better ways, but I’m totoo at the moment to recollect.