This is a decent writeup on applying “Zero Tust” principles to a home lab using mostly open source tools. I’m not the author, but thought it was worth sharing.

  • @Quik@infosec.pub
    link
    fedilink
    English
    812 days ago

    I, too, don’t love the use of AWS/Cloudflare, while I get that you can simply replace AWS S3 with something else for backups, this server setup is innately based on using Cloudflare.

    • Matt The Horwood
      link
      fedilink
      English
      1212 days ago

      Maybe I should do a write up on my setup, as I don’t use Cloudflare or AWS. I do use backblaze and OVH

    • @fruitycoder@sh.itjust.works
      link
      fedilink
      English
      212 days ago

      What is a good alt for cloudflare here tbh?

      I’ve done wire guard, and tor service to obfuscate the network, and crowdsec for a good external firewall, and linkerd gateway to actual services (and keycloak for sso).

      Besides adding gotelaport for more fine grained access, idk what else you could do, but even then idk if its still competitive as someone else’s network taking your ddos loads lol