[–] 3 points 5 months ago

I do the port knocking at the firewall level (it's a pretty simple nft chain setup). Caddy isn't involved at all. I was thinking about integrating that into my caddy config using something akin to an operator, but I haven't needed any extra functionality yet.

  • source
  • parent
  • context
  • [–] 10 points 5 months ago (2 children)

    I went a different path than the VPN route that seems popular in the other comments...

    I use a reverse proxy (caddy) with wildcard SSL (so all my hostnames aren't in the public cert registry) plus port knocking. So normally no outside IPs are allowed to access my internal services, but I can knock and then access anything for a while. Working well so far.

  • source
  • [–] 1 point 6 months ago

    I would also suggest looking into k0s/k0sctl for deploying k8s. I think it's probably the easiest deployment method I've personally used. It also makes updates dead simple.

    For deploying things to k8s, these days LLMs can write the k8s manifests pretty easy if there isn't already helm or kustomize files available.

  • source
  • parent
  • context
  • [–] 3 points 7 months ago

    We haven't been dealing with Trump for as long as Venezuela has been dealing with Maduro (and Chavez before him). Give us a couple more decades and I'm sure you'd see more people happy to see him "arrested" by a foreign power. Fwiw, I'd be happy to see it tomorrow, but I know a lot of my fellow USians wouldn't take so kindly. Not because they actually like Trump, but because it'd be a sobering reminder that we're no longer top of the food chain

  • source
  • parent
  • context
  • [–] 4 points 7 months ago (1 child)

    We must be looking at different polls, because the ones I've looked at clearly show him having terrible approval ratings. Definitely not even close to a simple majority or "wide, perhaps perfect, acceptance".

  • source
  • parent
  • context
  • view more: next ›