Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
view the rest of the comments
At work, I used ssh-signed certificates for Linux server access - those certs are only valid for about 15 minutes.
The whole idea of shorter lifetime certificates is to address if a certificate is compromised. (Especially for client certificates which, iirc, Let's Encrypt no longer offers).
For a home lab? With no externally accessible services? Short-lived certs aren't really a big deal. Nobody is going to be hacking your homelab, stealing your private keys, poisoning your internal DNS, and pointing you to a different, malicious service.
I had no idea "single use certificates" were a thing. It makes sense, although from my personal perspective I have always worked with managed identities and privilege escalation.
I have almost no internet facing services, although the two I have I might swap for the short lived variants. As you said, risk of misuse due to compromise goes down so that makes sense.
For my other services, they are all running on HTTPS, but only available internally over LAN or VPN, all with isolated VLANs sort of like a Hub Spoke model. The two certs that are internet facing are basically for getting access to my VPN. Might swap the internal services to short lived anyway if the automation works well, as I said before, it's fully automated anyway.
If you're a developer for an important open source project, they might.
Attacking the xz project wasn't done because the attacker cared about anything that the xz maintainer had. It was because he was trusted and the software he maintained had been given a fair bit of trust by certain maintainers and could be compromised and used as a vector into other systems that indirectly relied on that open-source project.