Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
view the rest of the comments
Thank you for sharing. I had missed the announcement, so pleased to know the option is available.
I have fully automated the creation and renewal of my certs and have just short of 50 certs that I manage in total. Every single one automated using NixOS / ACME / lego.
Technically I could easily implement this, just have to switch my config.
Honest question, are there any particular security benefits to this (especially for a home lab)?
I can understand the short lived time span further reduces risk of compromise, yet the existing time span is already "much shorter than traditional certificates". Does it have a substantial impact on our security posture?
At work, I used ssh-signed certificates for Linux server access - those certs are only valid for about 15 minutes.
The whole idea of shorter lifetime certificates is to address if a certificate is compromised. (Especially for client certificates which, iirc, Let's Encrypt no longer offers).
For a home lab? With no externally accessible services? Short-lived certs aren't really a big deal. Nobody is going to be hacking your homelab, stealing your private keys, poisoning your internal DNS, and pointing you to a different, malicious service.
I had no idea "single use certificates" were a thing. It makes sense, although from my personal perspective I have always worked with managed identities and privilege escalation.
I have almost no internet facing services, although the two I have I might swap for the short lived variants. As you said, risk of misuse due to compromise goes down so that makes sense.
For my other services, they are all running on HTTPS, but only available internally over LAN or VPN, all with isolated VLANs sort of like a Hub Spoke model. The two certs that are internet facing are basically for getting access to my VPN. Might swap the internal services to short lived anyway if the automation works well, as I said before, it's fully automated anyway.
If you're a developer for an important open source project, they might.
Attacking the xz project wasn't done because the attacker cared about anything that the xz maintainer had. It was because he was trusted and the software he maintained had been given a fair bit of trust by certain maintainers and could be compromised and used as a vector into other systems that indirectly relied on that open-source project.