I’ve been wanting to get into self hosting for a long time and messed about a bit with setting up a nextcloud. But while I am reasonably well versed in linux and programming all things to do with the internet are quite confusing and mostly after reading blogposts and the like I am feel like I am missing so much knowldedge. From why people use traefik, how and why to use docker containers, what settings to change on the router, how to connect and setup the domain, and probably most importantly how to do this safely. Is there a good book or site that explains these more basic things?

  • london443@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 days ago

    Adding the security basics, since nobody listed them yet:

    1. A firewall with default deny, then open only what you need. A simple one such as ufw is fine.
    2. Install CrowdSec or fail2ban early. Within a day you will see how much junk hits any public server.
    3. Reach SSH and admin pages over a private network (Tailscale or WireGuard) instead of exposing them.
    4. Read your reverse proxy access log for a week. It teaches you more about how the internet really behaves than most courses.

    None of it has to be perfect on day one, but it is much easier to build in from the start.

  • Denys Nykula@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 days ago

    To your specific questions:

    why people use traefik

    Reverse proxies let you serve multiple apps from one server, encrypt your traffic and automate updates of encryption certificates. I use Apache (virtual hosts, mod_md) for this.

    how and why to use docker containers

    Modern web apps have many constantly shifting dependencies and don’t work closely with distributions on packaging them, so they have to be updated separately from the base system. They might also need different versions of these dependencies, and multiple instances of one dependency (e.g. database). Containers are one way to achieve that, and also ease backups, monitoring of individual apps, and installing an application in exact same way on development and testing machines.

    what settings to change on the router

    To expose ports 22 (ssh), 80 (http) and 443 (https) to world, forward them to your server.

    how to connect and setup the domain

    In the DNS settings for your domain, point “A” record to your home IP. That’s if you rent a static IP. If you don’t, things will be more complicated, research on your own.

    how to do this safely

    Bare minimum: set up daily backups of container volumes and reverse proxy configuration, same for updates of base system and containers, and turn off SSH password login in favor of keys. Test that a backup can be successfully restored in a virtual machine at least once a month.

    • non_burglar@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 days ago

      Op specifically asked for resources for learning and not sparse answers from users.

      research on your own

      Come on, man. Did you even read the post.

      • Denys Nykula@piefed.social
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        7 days ago

        Where does OP say that they only want resources and no answers at all? Also you sadly misquote me by stripping context, I replied that there’s a simple solution (and how specifically to look for it) to one of their questions if one condition if satisfied, and that the problem doesn’t have an easy answer otherwise, therefore needing more research. I went out of my way to give OP brief answers and more specific questions for research, like I do for my students, and you make it look like I just wrote RTFM.

  • NaibofTabr@infosec.pub
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    8 days ago

    Computer networking is basically a completely different field from operating systems and programming, though obviously some of the concepts are relevant. Turns out plugging these things into each other so that they can share information in a useful way is kind of difficult. A lot of very smart people have been working on it for almost 70 years, and frankly it’s still a fucking mess, so don’t feel bad if you feel a little lost.

    Starting with the basics is the right instinct, in my opinion. Start with the OSI model:

    https://jakarta.telkomuniversity.ac.id/7-osi-layer-the-building-blocks-of-networking/

    https://www.geeksforgeeks.org/computer-networks/osi-model-analogy-osi-7-layers-explained/

    This helps to break down the actual functioning of the network into logical steps. It’s very helpful when you’re trying to visualize the operation of some of the more abstract bits of the technology stack (like TCP/UDP), and when you’re trying to think through what piece of it might be causing your problem in the moment (the router is on and the cables are plugged in, why is there no connection?). It’s a map that can help you when you’re lost. It’s also a guide to how a lot of people who work on networking technology think, so it can help you understand how things are supposed to work.

    Beyond that, Professor Messer is a great resource: https://www.professormesser.com/

    If you feel reasonably confident with computer hardware components and various types of cable connectors, you can probably skip the A+ part and go straight into Network+. Because you’re doing this as a home hobbyist (not for the actual certification), I recommend just listening to the courses like you would a podcast. Don’t try to memorize or fully understand everything, just use it to get a grasp of the terminology and purpose of the various pieces.

    I also recommend taking on a project to gain experience. Implenting PiHole https://pi-hole.net/ for your home network will cover routing, DHCP and DNS, plus you can do it with a Docker container.

    • Leigh Weigh@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 days ago

      it can help you understand how things are supposed to work.

      Man knowing what the intent probably was and the thought process to get there helps with so much troubleshooting. Not just in tech but everywhere.

      • NaibofTabr@infosec.pub
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 days ago

        Yeah, it’s one of the best reasons to actually RTFM: “How does the guy that designed this think it works? What did they intend for it to do?”

        I also find it’s useful when I’m vague on the specifics, especially with network protocols. I might be expecting it to do something and then find out, oh, this doesn’t solve that problem, I’m in the wrong config file.