Crowdsec
I just read a bit about it and it sounds quite interesting with the community aspect of it all. I'll give it a deeper look later, thanks !
I run a custom build of Nginx with a few extra modules compiled in:
- ModSecurity
- Nginx GeoIP2 Module (https://github.com/leev/ngx_http_geoip2_module.git)
- OWASP Core Rule Set: https://github.com/coreruleset/coreruleset/tree/v4.10.0/rules
Some guidance can be found here: https://docs.nginx.com/nginx-waf/admin-guide/nginx-plus-modsecurity-waf-owasp-crs/
That guidance is for NginxPlus, but you can compile the dynamic module yourself with the community versions.
I have been using BunkerWeb for the past 4 years and have been mostly happy with it. Its default settings are sometimes a bit agressive but you can change those globally or service per service.
The fact that they lock Letsencrypt DNS-01 behind the pro version is so incredibly annoying.
Yeah, I use Caddy for that, as I only use DNS-01 for local-only services.
Thanks that's good to know :)
I’ve been looking for a good self-hosted WAF for a while. I tried Open AppSec — way too buggy. Then I gave BunkerWeb a shot, but the setup was just too complicated (maybe I’m just not that good 😅). SafeLine has a lot of paid features, but honestly, the Lite version already covers most of what I need. $100/year is pretty reasonable, rich features, the setup and configs are super simple.
I ended up going with Crowdsec.
The setup was a bit of a challenge as I like to do it the RTFM way abd that there is a bunch of concepts to grasp before you really understand what you are doing, but since then it's been working pretty great ! And it's free (as in you are providing them with data on the occurence of threats etc, so you don't pay)
Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!