[–] 1 point 1 year ago

Sorry, I don't use either of those services. Would you be willing to explain your setup? I use my own CA with HAProxy for TLS termination (with servers side TLS) so I might be able to give some general tips. Maybe.

  • source
  • [–] 4 points 1 year ago (2 children)

    Hey, it's nice to talk to you. I've seen you around this community and I like your comments.

    I said K8S because I work with it, but if OP doesn't need HA I guess Podman is fine too. I don't like Docker anymore after what they pulled a year or so back

  • source
  • parent
  • context
  •  

    I have been looking at hardening *nix servers for my lab and maybe carry some of that over to work. CIS benchmarks are something I like doing but that's barely scratching the surface. What do you do for your servers?

    I have Lynis, systemd-analyze, Kernel self protection in mind but I'd love to hear your thoughts. Bonus points for the most paranoid setups!

    view more: next ›