• 6 Posts
  • 158 Comments
Joined 2 months ago
cake
Cake day: January 28th, 2025

help-circle




  • Podman works with nft, not iptables. Ufw iirc uses iptables (iptables can work as a subset of nft, so there is that too).

    Try a different firewall tool, or use nft directly

    If your containers are bound to 127.0.0.1 and you only have a reverse proxy on 443, you probably don’t even really need a firewall.

    Run rootless podman and segregate each container stack on its own network, podman will take care of it for you.




  • Shimitar@downonthestreet.eutoSelfhosted@lemmy.worldISO Selfhost
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    2
    ·
    5 days ago

    I see you are on Lemmy.world, keep in mind self hosting your Lemmy will bypass the heavy censorship going on on Lemmy.world in terms of defederation.

    For example another great community and very active is the pirate community on db0, which is banned on your current instance. And not the only one.


  • Shimitar@downonthestreet.eutoSelfhosted@lemmy.worldISO Selfhost
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    1
    ·
    5 days ago

    Not that “alternatively young” but the difference is slight here.

    Yeah I self host my Lemmy because why not? As well I self host my matrix with bridges to all main chat closed ecosystems because why not?

    At least my descendants will own all my comments and posts.

    And I also host (not at home, but on vps) my email because why not.

    Do you really need any other reason to?

    Also, Lemmy rocks, this community is one of the best and more active.



  • You don’t. Providing you have an upstream gateway that do the firewall for you, provided you don’t have an open WiFi, provided you use a reverse proxy, provided you have sane network settings all around, provided you run linux(or similar).

    Even better if you are behind CGNAT.

    Provided you know what you are doing.

    On the other hand, setting up a firewall in a safe way is no easy task either.

    I use an opnSense on top of my home network, given all the above “provided”.

    Before that, I never run a firewall and never had an issue. Always being cg-nat tough.