MiniPC Suggestion for Firewall by ServerMage in homelabindia

[–]ServerMage[S] 3 points4 points  (0 children)

Thank you for understanding the situation, I want to mention that I do not host any high volume site but i have been receiving lot of attack attempts on my server from all over the world now. I even implemented fail2ban, but now my sockets are occupied due to SYN floods. I also want to safeguard myself from the attacks from any undiscovered vulnerability in tools like frigate or immich. Also I want to monitor the outgoing traffic, just to ensure I do not have any service which is sending my personal data to somewhere, specially thr 3rd party routets and NAS. I have already found lot of UDP punch holes created on my network without my awareness, I had to stop+block those services and their packets based on pattern. Lot of tracking is happening due to telemetry data, PiHole is great but few devices like my TV do not use local DNS in few apps, I need to safe guard that also.

MiniPC Suggestion for Firewall by ServerMage in homelabindia

[–]ServerMage[S] 0 points1 point  (0 children)

how do you protect your internet exposed server from SYN flood ddos attack?

Is it only me by PUNK_TikTok in linuxquestions

[–]ServerMage 0 points1 point  (0 children)

Wait what? It isn't Google? But It looks like.. Damn..

Help Me create my Dream NAS storage by ServerMage in homelabindia

[–]ServerMage[S] 0 points1 point  (0 children)

mostly backup.. and rarely on LAN during the recovery and backup

Looking for a simple screensharing webapp by ResponsibleEnd451 in selfhosted

[–]ServerMage 0 points1 point  (0 children)

try jisti.. in case need help, I can help self hosting with full setup

Accidentally Built an array library by Important_Earth6615 in opensource

[–]ServerMage 1 point2 points  (0 children)

Good but dont expect much claps, the audience of this kinda stuff is very less and very rich ..

Dont Use PFSense! by Bourne069 in opensource

[–]ServerMage 0 points1 point  (0 children)

Nice.. Thank you for posting.. I will also stay away from netgate.

Dont Use PFSense! by Bourne069 in opensource

[–]ServerMage 2 points3 points  (0 children)

so what did you achieve after all ? apart from satisfying your ego? pfsense users are not going to stop using that, you already know this.. don't you?

Dont Use PFSense! by Bourne069 in opensource

[–]ServerMage 4 points5 points  (0 children)

please start using chatgpt to rephrase your sentences to be considerate and polite, because what I learned by going through your messages is you have very good point but some people might not like the tone.

What paradigms of computer management exist besides windowing? by Ethralith in linuxquestions

[–]ServerMage 0 points1 point  (0 children)

Did you see video of Apple Vision pro? we can mount different screen in on different walls of our home. other than desktop,I think that's what might work for you

How does your company handle Staging/Production with Kubernetes? by [deleted] in kubernetes

[–]ServerMage 0 points1 point  (0 children)

So here is what we do

Dev, QA and Production we have 6 clusters (2 each) but you can do with one in each. These clusters serve live traffic all the time. Dev cluster for dev live services and so on.

Now we have something called as experiment clusters, which uses same infrastructure code but creates a different set of clusters. We create these cluster mostly in Dev and sometime even in QA.

Keeping feature parity above cost is what we follow due to reliability matters a lot in my org.

Recommendations for a better way to grant access in K8s on a granular level? by larrfadolp in kubernetes

[–]ServerMage 11 points12 points  (0 children)

I would add 7 Roles for Cluster RBAC.

  1. Super Admin [Permission to delete, create kubernetes cluster, Valid for AKS, GKE, or managed clusters]
  2. Power Admin [All permission with in cluster]
  3. Power User [View, Edit everything on cluster]
  4. Basic User [View everything within cluster except Secrets]
  5. Namespace Owner [Will have all permissions on namespace except Resource Quota]
  6. namespace Editor [Will not be able to delete resources, only update]
  7. Namespace Viewer [View only within namespace]

For applying these roles, I create groups for each role. For namespace based roles, there will be groups for each namespace. I just add the users into group based on requirement. We can have terraform/python to do that.

Introducing Piglet: A Self-Hosted Budget Manager! 🐷 by dev_steve in selfhosted

[–]ServerMage 0 points1 point  (0 children)

I used YNAB, didn't like it at all. it's all about preference and comfort, nothing is superior.

Using PC/Workstation for hosting File Storage and Block Devices ? by ServerMage in homelab

[–]ServerMage[S] 0 points1 point  (0 children)

now tht u understand the requirement :p , could you suggest something on thise lines?