<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[#homeLab fun...Randomly checked my #graylog dashboard for self hosted webserver.]]></title><description><![CDATA[<p><a href="https://mstdn.ca/tags/homeLab" rel="tag">#<span>homeLab</span></a> fun...<br />Randomly checked my <a href="https://mstdn.ca/tags/graylog" rel="tag">#<span>graylog</span></a> dashboard for self hosted webserver. Oh someone was trying various WordPress vulns again... Let's see the inbound IPs...<br />Oh,... Oh no. The call is coming from inside the network! In the 192.168.1.0/24 group...<br />K, check that host... Oh yeah <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f926.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--face_palm" style="height:23px;width:auto;vertical-align:middle" title="🤦" alt="🤦" />‍<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--male_sign" style="height:23px;width:auto;vertical-align:middle" title="♂" alt="♂" />️ that's the node that hosts the externally visible reverse proxy service.<br />Derp, <br />Well, at least reconfiguration of the proxy and webserver to carry the real client IP was fairly straightforward. Just something I missed during my initial, and subsequent, configuration.</p><p>Though somewhat risky, connecting computers to the wild network is always a learning experience. My autodidactic ass learns so much from seeing that something can be done then trying naively to do it myself. Bumping up against each and every hurdle informs the why then the how of the best in class solutions. I may not always succeed but I get a better understanding of the tools and technology landscape we exist in.</p>]]></description><link>https://board.circlewithadot.net/topic/b1c0d399-c89b-4127-a622-5ac383a1ba80/homelab-fun...randomly-checked-my-graylog-dashboard-for-self-hosted-webserver.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 01 May 2026 05:44:27 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/b1c0d399-c89b-4127-a622-5ac383a1ba80.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 19 Apr 2026 03:01:03 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to #homeLab fun...Randomly checked my #graylog dashboard for self hosted webserver. on Sun, 19 Apr 2026 11:38:31 GMT]]></title><description><![CDATA[<p><span><a href="https://mas.to/@tinsuke" rel="nofollow noopener">@<span>tinsuke</span></a></span> <br />That endpoint gets a LetsEncrypt cert, anything with auth usually requires openId.<br />I've got fail2ban on one service as it came as a feature. <br />Been contemplating putting it in more globally. <br />Also, as much as possible, single responsibility services. <br />The proxy does proxy stuff. <br />The web server does static pages. <br />Other services are containerized and individually secured and isolated as much as possible. <br />GrayLog is for monitoring, doesn't itself secure anything. But does let me know what to focus on.. (when I monitor the relevant info <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f601.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--grin" style="height:23px;width:auto;vertical-align:middle" title="😁" alt="😁" />)</p>]]></description><link>https://board.circlewithadot.net/post/https://mstdn.ca/users/RyeNCode/statuses/116431173136102146</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mstdn.ca/users/RyeNCode/statuses/116431173136102146</guid><dc:creator><![CDATA[ryencode@mstdn.ca]]></dc:creator><pubDate>Sun, 19 Apr 2026 11:38:31 GMT</pubDate></item><item><title><![CDATA[Reply to #homeLab fun...Randomly checked my #graylog dashboard for self hosted webserver. on Sun, 19 Apr 2026 04:55:31 GMT]]></title><description><![CDATA[<p><span><a href="/user/ryencode%40mstdn.ca">@<span>RyeNCode</span></a></span> oh, how do you secure that exposed reverse proxy? (well, besides graylog, ofc)</p><p>I have one where I just setup mTLS auth for non-local access. No log monitoring. No fail2ban or the likes... Am I asking for (too much) trouble?</p>]]></description><link>https://board.circlewithadot.net/post/https://mas.to/users/tinsuke/statuses/116429588500606208</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mas.to/users/tinsuke/statuses/116429588500606208</guid><dc:creator><![CDATA[tinsuke@mas.to]]></dc:creator><pubDate>Sun, 19 Apr 2026 04:55:31 GMT</pubDate></item></channel></rss>