For me, it is because I don’t want to leave my power hungry desktop running 24/7 to just capture feeds… I already self host, so I let that do the fetching on a schedule, then my rss client just fetches from my server
galacticworm
- 0 Posts
- 5 Comments
galacticworm@piefed.socialto
Selfhosted@lemmy.world•Ways to Expose Services PubliclyEnglish
2·12 days agoIf you have a UniFi gateway, you can enable region based firewall on your port forward ip. This then blocks most of the world (incoming) as a first step. Then like others suggest, a reverse proxy. I use Caddy built with the Maxmind geolocation plugin, and I also run fail2ban on my exposed service.
I figure if you don’t need most of the world accessing your services, it is best to exclude them
I have a bunch of actions setup in mp3tag which strips out all but the absolute necessary tags, and uses the cover from the directory to add the cover to the files… once tagging is correct, you can use any library.
I have a proxmox with a backup share sitting on the nas… rebuild is simply to rebuild a new proxmost host , attach same backup storage and restore backups. I have rebuilt a couple of times, back up and running in less than an hour
I have a similar setup to you, but I run caddy instead of npm. I recently added a log analyzer to caddy and noticed a bunch of unauthorized hits I thought I could do something about…
I added a region based firewall rule for the port forward address on my UniFi gateway only allowing incoming traffic from my own country. I couldn’t do a global region block as I have some legitimate incoming traffic from the USA, so I went with a rule targeting traffic to the reverse proxy ip specifically. It still managed to let in some random bot traffic, so I also added a block region rule above the allow region rule (both to the reverse proxy) blocking countries like Russia, china, North Korea etc…
If you don’t need to allow most of the world, it is an easy fix to do this at your gateway (I note you have a udm)