Toot

Written by just_another_person@lemmy.world on 2024-11-04 at 14:53

Wireguard is a VPN, so that’s not going to help you much here unless you’re forwarding all your traffic through a remote server, in which case anyone gets in there will still be able to get your local machines. It’s another hop in the chain, but that’s about it.

If you want to be more on guard about reacting to attacks, or just bad traffic, you probably want something like Crowdsec. You’ll at least be able to detect and ban IPs probing your services. If that’s too much work, leverage OoenWRT reporting and some scripting to ban bad actors that probe your firewall and open ports. That’s a good first step.

If you’re concerned about the containers, consider using something more secure than dockerd. Podman rootless with a dedicated service user is a good start. Then maybe look at something more complex: Kata, gvisor, lxc…etc. The goal being sandboxing the containers more to prevent jailbreaks.

=> More informations about this toot | View the thread | More toots from just_another_person@lemmy.world

Mentions

=> View miau@lemmy.sdf.org profile

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113425254882825742
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
223.23298 milliseconds
Gemini-to-HTML Time
0.577363 milliseconds

This content has been proxied by September (3851b).