TrueNAS Docker, Local Certificates and Pangolin. I'd love some help getting some things working and hardening help.

Ok. I have setup pangolin with my domain in Oracle PAYG (mostly because I had it for and just blew away my existing FoundryVTT 2c/12GB RAM Arm install) utilizing free tier assets. I've got certs, crowdsec (seemingly working) with Geoblocking. Cool. Services work through the tunnel (still need to figure out authentication, and Turnstile captcha + whether I want crowdsec bot-detection so I down the tunnel when not in use). My next project is to get the certs and DNS resolution working while on LAN to avoid eating into my 10TB/Mo VPS bandwidth so that bandwidth only gets used by friends when using the Palworld, Matrix, Foundry (insert-server here) or family when they do a backup to Nextcloud/Immich from their phone. Now this is all currently running on TrueNAS from within the Dockhand App. I have setup TrueNAS's GUI to only use 80/443 on the dedicated and reserved IP for TrueNAS instead of 0.0.0.0 and setup a bridge with an alias IP that I told my UniFi controller "trust me bro there's something there". I did it this way as I was fed up with not being able to properly backup the docker configs and having to have the apps running in order to update them (though now I have 128GB of RAM for TrueNAS this is less of an issue) plus them just not having some of the apps I wanted like Foundry. What I am currently struggling with is getting Traefik/Caddy etc. to run within the Dockhand app so I can then tell my UniFi controller to use the alias IP of the reverse proxy for all the subdomains. They do not like the networks so I'm trying to figure out what to do (I'll get the exact errors later I'm writing this at work). Ideas? I'm not sold on Dockhand this is just what I kinda settled on and worked for the initial Pangolin test. I'd also welcome any suggestions you have for collecting and analyzing the logs from my Oracle VPS to have automated analysis and alerting on events as well as any other hardening tips you would recommend. At home I am GeoBlocking inbound for almost everywhere (though I might need to figure out how to change that due to LG et. all) and have OK IDS/IPS/Firewalling with UniFi's built-in Suricata etc. Any help getting this all working would be appreciated. Kind of burnt out with Firewalling and such after all the OT at work and some personal heartbreak the last few weeks (so I may be missing something obvious) so I'd love to feel like I got a W in at least one column.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论