this post was submitted on 12 Jun 2023
623 points (99.5% liked)

Selfhosted

40382 readers
522 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

A simple question to this community, what are you self-hosting? It's probably fun to hear from each-other what services we are running.

Please mention at least the service (e.g. e-mail) and the software (e.g. postfix). Extra bonus points for also mentioning the OS and/or hardware (e.g. Linux Distribution, raspberry pi, etc) you are running on.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 2 points 1 year ago (1 children)

You'd hope, but I have a few friends who simply port-expose their media servers.

I guess it could be worse if they had ssh exposed.

[–] [email protected] 4 points 1 year ago (1 children)

I'll have to disagree with you there. SSH is super well maintained and understood, and massively useful for the risk you do run. Who knows what's going on with all the random projects people are hosting. I'd rather have SSH exposed than almost anything else.

What would you do to provide access to some less tech savvy friends. I'm thinking of dropping a SBC with wireguard and a proxy onto a friend's network, that way everything is under my control, and I can lock down the wireguard connection however I want, but I haven't gone down that route yet.

[–] [email protected] 2 points 1 year ago

I was thinking more along the lines of simply thowing up a port to SSH into. No Fail2Ban and no keys, just a password.

I would just containerize and reverse proxy, but I understand the hesitation, wireguard would be preferable.