whysofurious

joined 8 months ago
[–] whysofurious@lemmy.dbzer0.com 2 points 2 months ago

Someone recently recommended me Textadept: https://orbitalquark.github.io/textadept/. Haven't tried it on linux, and I am not really using it, but the interface is clean, it also has a CLI, and I thought I could give you another option :)

[–] whysofurious@lemmy.dbzer0.com 2 points 5 months ago (1 children)

Thanks for the thorough reply! I didn't know about Inav, but it looks very interesting. I agree on the Grafana stack, it's not something I really need now, and if I have to inspect single containers I can go for something like Dozzle.

About crowdsec free plan, looking at the pricing page, I see that the community plan has unlimited remediation components and 3 blocklist + unlimited scenarios, or am I looking in the wrong place? (honestly that page is pretty confusing)

[–] whysofurious@lemmy.dbzer0.com 1 points 5 months ago

Thanks for the input, yes I was mostly thinking about hedgedoc, that doesn't have parsers or anything. I need to delve more into crowdsec logic and rules before trying to do my own thing, for sure. Thanks a lot tough, I followed your advice and I got Crowdsec working on both Authentik and Forgejo :)

[–] whysofurious@lemmy.dbzer0.com 2 points 5 months ago (2 children)

Thanks for the answer :) make sense, I will go through with the plugins for the services I have exposed, although not all of them have crowdsec collections.

 

Hi all!

I'll try to be quick but I apologise first as I am pretty new to security stuff and my questions might be obvious to the more experts.

I have a VPS (hetzner) set up with docker, caddy for the reverse proxy, and authentik as the only login method for a couple of services (hedgedoc and forgejo). Since most of these has to be available and accessible on the internet, I also setup crowdsec and built caddy with the relevant bouncer. This allows crowdsec to inspect the caddy logs for all the services I am serving through it and act accordingly. Edit: all the services are in docker containers.

So far, so good. However, I also saw that crowdsec can directly monitor container logs with the docker integration or through container labels. Also, I saw a couple of collections on crowdsec hub specifically for Authentik and Gitea.

I feel I am missing something so my question are:

  1. Would it be useful to monitor container logs given my setup or would it be redundant?
  2. Should I add the app-specific collections, or would docker logs monitoring be enough?

My current crowdsec collections


  • crowdsecurity/linux
  • crowdsecurity/appsec-generic-rules
  • crowdsecurity/caddy
  • crowdsecurity/whitelist-good-actors
  • crowdsecurity/http-cve
  • crowdsecurity/iptables

Edit: bonus question, does someone know if the Gitea collection would be useful for Forgejo after it being a hard-fork now?

[–] whysofurious@lemmy.dbzer0.com 4 points 7 months ago

I agree with LibreCalc and CSV, in some internationalclasses we always had issues with excel saving CSV in actually different formats depending on the machine locale. LibreCalc never had this problem.

[–] whysofurious@lemmy.dbzer0.com 5 points 7 months ago

Same process here, started with yunojost and now using docker directly. Still Yunohost got me into self-hosting when I didn't know anything about it, definitely recommended for starting out.

[–] whysofurious@lemmy.dbzer0.com 1 points 7 months ago* (last edited 7 months ago)

I still remember years ago one time windows fucked itself and god knows why I couldn't fix it even with USB recovery or stuff like that (long time ago, I don't remember).

Since I couldn't boot into recovery mode the easiest way to backup my stuff to a connected external drive was "open notepad from the command line -> use the GUI send to.. command to send the files to the external drive -> wait and profit" lol.

[–] whysofurious@lemmy.dbzer0.com 70 points 7 months ago* (last edited 7 months ago) (2 children)

As an academic, yes, please pirate stuff.

Fuck parasites publishers that make profit on our unpaid job and gatekeep knowledge.

A nice read about publishers profits: Against Parasite Publishers: Making Journals Free or if someone prefer the newspaper format

[–] whysofurious@lemmy.dbzer0.com 2 points 7 months ago

Yep this is what I meant, thanks for saying it in a proper way :)

[–] whysofurious@lemmy.dbzer0.com 16 points 7 months ago (5 children)

I am currently using Mealie with docker, which being a containers noob seemed easier to setup compared to Tandoor. I have it behind tailscale as well.

Mealie works well for what I need to do, I don't plan in advance yet, but I just import recipes and it works 9 out 10. I will need to try the shopping list features sooner or later.

There is no mobile app that I am aware of but the webpage works perfectly on mobile with a bookmark.

[–] whysofurious@lemmy.dbzer0.com 3 points 8 months ago

Off-topic, but for someone who recently switch to hhkb layout, I find it way more comfortable to activate shortcuts with caps-lock (Ctrl in hhkb) pinky rather than with regular command.

[–] whysofurious@lemmy.dbzer0.com 1 points 8 months ago (1 children)

Thanks! Definitely helps and I am happy to see how people are approaching the problem. It seems indeed an automated/selfhosted solution is not always the best in this case. I will also check out Kotatsu, didn't know about that :)

view more: next ›