Mang, you reeeeeaaallly shouldn’t be posted unredacted service configs on the interwebs.

Sol 6 VI StatCmd
creator
link
fedilink
English
12d

What info should be redacted 👀 I didn’t realize any of this was particularly sensitive?

@gray@pawb.social
link
fedilink
English
4
edit-2
2d

There’s nothing bad per se, but obviously not sharing the inner workings of your internet facing server is just another step to protect yourself.

You mention in the OP this is for a business, my opinion you should be working on a professional resource/developer to manage this for you and not random Lemmy users.

On the use of Caddy, your configs here host a lot of sites with many specific configurations, I’m not sure caddy can support all of this. nginx is the tool of choice for a wide majority of the internet for a good reason.

Sol 6 VI StatCmd
creator
link
fedilink
English
1
edit-2
2d

Okay good feedback thank you I’ll look at nginx too. As far as the professional goes - unfortunately times are tough - budget is tight, but I will look into it long term to shore things up when we’re a little more settled. Going to have to do my best on my own for now.

Ports, any NAT, internal IPs. The first part of an organized attack is getting environment enumeration down. If a bad actor can map your network they can more efficiently direct their attack.

Sol 6 VI StatCmd
creator
link
fedilink
English
12d

Thanks for letting me know!

@catloaf@lemm.ee
link
fedilink
English
22d

It can provide useful info for an attacker. I don’t see anything particularly sensitive in these files though.

Sol 6 VI StatCmd
creator
link
fedilink
English
12d

Thank you for sharing, appreciated.

You’re using something in front of caddy right?

Atleast refuse basic headers and close connections

add_header X-Robots-Tag "noindex, nofollow, nosnippet, noarchive";

server {
    listen      80 default_server;
    listen      [::]:80 default_server;
    listen      443 default_server;
    listen      [::]:443 default_server;
    ssl_certificate certs/server.cert;
    ssl_certificate_key certs/server.key;
    server_name _;
    return      444; #CONNECTION CLOSED WITHOUT RESPONSE
}
Sol 6 VI StatCmd
creator
link
fedilink
English
22d

Copy that. Some people have recommended cloudflare I’m looking into it.

Cloudflare tunnels are cheap(free if it’s just a couple), simple, and really great.

https://caddy.community/t/caddy-cloudflare-tunnel/15929

Sol 6 VI StatCmd
creator
link
fedilink
English
22d

Thank you for the resource, I’ll employ it for sure.

Create a post

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

  • 1 user online
  • 142 users / day
  • 411 users / week
  • 1.38K users / month
  • 3.83K users / 6 months
  • 1 subscriber
  • 4.03K Posts
  • 82.7K Comments
  • Modlog