Hello folks! I am looking for some guidance or direction on how to make sure my “server” locked down as much as possible. I know there are several websites/guides out there but was hoping I could get someone to recommend some good ones to use that cover all the bases solidly.

There are just so much info out there, wading through looking for a solid guide when you ignorant is hazardous.

Server is running Mint and hosts my Plex/Radarr/Sonarr stack. Using a locally hosted reverse proxy for any outside connections.

This started as a project to learn linux, so things are a bit shaky on linux understanding but getting better. I used GPT assistance to lock it down to the best of my ability, making sure (or I think) that most obvious firewalls rules were setup…ect.

Thanks for your help :)

  • BartyDeCanter@piefed.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    6 hours ago

    The basics for anything:

    • ssh key access only
    • and a hardware key if available
    • disabled root
    • fail2ban
    • rate limiting
    • unattended upgrades
    • calendar reminder to run full updates

    After that, it really depends on what you’re running and who needs access where.

    If it’s just you, or a small group of devices that you have access to and can maintain, Tailscale is the easiest best first step, or your own headscale server.