Imagine that picture of a tardigrade playing a violin here.
Check their docs, mostly.
If all your services support binding to a unix socket, I'd bind them to /run/<servicename>.sock or similar, and set up a reverse proxy that hits /run/$servicename.sock when serving $servicename.devicename.lan. If the service can't bind to a unix socket, you can probably socat it or similar, and keep using the generic reverse proxy. Then, all your router has to do is route port 80 to your Debian machine.
Uh, I beg to differ. I've been blocking most of them for the past year, using essentially three ifs in a trenchcoat.
Bullshit user agents are taken care of by checking headers other than user-agent: if they say they're Chrome/ or Firefox/, check if they sent sec-fetch-mode. Didn't? That's very likely a crawler (and the handful of false positives are easy to make an exception for). For residential proxies, the same applies. For crawlers that piggy-back on Chrome, they usually crawl an URL queue, so if you poison their queue, you can catch those too.
At this point, out of ~100 million requests / day, I'm firewalling ~98 million off. Out of the remaining 2 million, ~90% of them gets served garbage to continue poisoning the URL queues. I can serve the rest on a potato, even if some of them are crawlers.
I did have a few people contact me about false positives, but those were very, very few (and also very easy to address). Very little CPU, RAM or bandwidth required, the vast majority of bots caught, negligible false positives. Deploying the solution isn't trivial (yet), but it also isn't hard either.
I've opted out of search (not just google, most other commercial search) in ~2024. Have not regretted it since, happy to see even commercial entities coming to the conclusion that Google's garbage and not worth it anymore.
Now, if they'd also follow the past set by indies, and block AI crawlers too, and make that the norm, that would be grand.
It was the night of December 24th, 1996. I turned on the family PC, then running Win95, and found my D:\ drive corrupted. Windows had no tools nor docs how to resurrect a corrupted filesystem. I cried, and two days later installed SuSE on a spare disk.
Some 20 years later, I restored about half of the disk lost in 1996, because Linux had the tools, and the docs, and encouraged me to learn.
I'm running Tang on a VPS, outside of my homelab. Servers in my homelab set up networking and a dedicated WireGuard tunnel to the VPS from initrd, to be able to talk to Tang, to help unlock the filesystem. The WireGuard tunnel is only allowed from my home ISP's ASN. So if anyone picks up all my equipment from my homelab and walks away with them, they will not be able to boot them up, unless they connect from my ISP's ASN (good luck), or know the passphrase.
Additionally, some of my homelab computers that support TPM also have a TPM pin, so walking away with the disk only, and connecting from my ISP's ASN would still not be enough. This is rather pointless, anyone who walks away with the disk only will likely take the entire computer instead. But it was fun setting it up.
In the not so distant future, I'll update this setup to use Shamir Secret Sharing more, where I'll have three pins: my VPS (via Wireguard), a small computer somewhere else in my apartment, and a third at a neighbour (+ TPM on supporting computers).
"As if openclaw and android had a baby", and that's a recommendation, not a warning? WTF.
No. I'm not dead yet.
Mostly on coffee, not exclusively. Noticable amounts of spite & tortilla chips are also present, yes, but... no shame.
Only when I'm deprived of coffee.
Yes. My Actual Intelligence lives in my head, and runs mostly on coffee.