this post was submitted on 19 Oct 2023
2 points (100.0% liked)

Self-Hosted Main

515 readers
1 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

For Example

We welcome posts that include suggestions for good self-hosted alternatives to popular online services, how they are better, or how they give back control of your data. Also include hints and tips for less technical readers.

Useful Lists

founded 1 year ago
MODERATORS
 

I am back with another published article.

Ideogram.ai: penguin in a server room covered in ice and snow, whole picture made out of green matrix style lines of code, cinematic

Please be kind! I am a self-taught Linux user and by no means an expert. My goal with this guide is to help newcomers to Linux have an easier and more secure start.

To all the experts out there, please be kind and do share your tips and observations. I am happy to keep updating the article to make the self-hosting world more secure.

https://nerdyarticles.com/debian-server-essentials-setup-configure-and-hardening-your-system/

you are viewing a single comment's thread
view the rest of the comments
[–] ElevenNotes@alien.top 0 points 1 year ago (2 children)

Go Alpine, hardened from the start (almost).

[–] krysztal@alien.top 1 points 1 year ago (1 children)

Isn't alpine musl based? Last time I heard it can lead to some very obscure problems when interacting with applications compiled with gcc... so, hows it fare for you?

[–] ElevenNotes@alien.top 1 points 1 year ago

Yes, but muscl > glibc, anyway, as a container host it does not matter. You can install 99% of all bins only the ones that are not 100% POSIX not (like GlusterFS for example) but in containers everything works.

[–] KillerTic@alien.top 1 points 1 year ago (1 children)

I tried it briefly, but had to many issues getting it up and running properly…

[–] ElevenNotes@alien.top 1 points 1 year ago (1 children)
[–] KillerTic@alien.top 1 points 1 year ago (1 children)

Honestly, when I tried it was like two years ago. I think back then I wasn’t experienced enough and was annoyed at some stage not being able to get docker to run.

I should give it another go. Would you just do it on RPi and a LXC container or also on your VM?

[–] ElevenNotes@alien.top 1 points 1 year ago (1 children)

All three. Alpine (read-only from RAM) is the perfect OS for any RPi. Alpine in a VM is a perfect OS with native support for all hypervisors and drivers available from the start, and as a container base layer its simply one of the best OS out there. I run all my bare metal nodes with Alpine from USB (read-only from RAM). You setup a USB stick, plug it in, boot from it, done. You can setup the OS with your keys and everything, take the USB stick, simply copy the contents (its FAT32) and put it on another stick and plug that into another server and boom, OS ready, no installation required.

Disclaimer: All my bare metal nodes are for containers, the OS has nothing installed, so read-only from RAM is IMHO the best option to do so, unless you want PXE.

[–] KillerTic@alien.top 1 points 1 year ago

All right, you got my attention 😂

Challenge accepted! (Some rainy day I got some time).

Thanks for that!