whysofurious

joined 3 months ago
[–] whysofurious 9 points 3 days ago (1 children)
[–] whysofurious 2 points 3 weeks ago (1 children)

Thanks for the thorough reply! I didn't know about Inav, but it looks very interesting. I agree on the Grafana stack, it's not something I really need now, and if I have to inspect single containers I can go for something like Dozzle.

About crowdsec free plan, looking at the pricing page, I see that the community plan has unlimited remediation components and 3 blocklist + unlimited scenarios, or am I looking in the wrong place? (honestly that page is pretty confusing)

[–] whysofurious 1 points 3 weeks ago

Thanks for the input, yes I was mostly thinking about hedgedoc, that doesn't have parsers or anything. I need to delve more into crowdsec logic and rules before trying to do my own thing, for sure. Thanks a lot tough, I followed your advice and I got Crowdsec working on both Authentik and Forgejo :)

[–] whysofurious 2 points 4 weeks ago (2 children)

Thanks for the answer :) make sense, I will go through with the plugins for the services I have exposed, although not all of them have crowdsec collections.

26
submitted 4 weeks ago* (last edited 4 weeks ago) by whysofurious to c/[email protected]
 

Hi all!

I'll try to be quick but I apologise first as I am pretty new to security stuff and my questions might be obvious to the more experts.

I have a VPS (hetzner) set up with docker, caddy for the reverse proxy, and authentik as the only login method for a couple of services (hedgedoc and forgejo). Since most of these has to be available and accessible on the internet, I also setup crowdsec and built caddy with the relevant bouncer. This allows crowdsec to inspect the caddy logs for all the services I am serving through it and act accordingly. Edit: all the services are in docker containers.

So far, so good. However, I also saw that crowdsec can directly monitor container logs with the docker integration or through container labels. Also, I saw a couple of collections on crowdsec hub specifically for Authentik and Gitea.

I feel I am missing something so my question are:

  1. Would it be useful to monitor container logs given my setup or would it be redundant?
  2. Should I add the app-specific collections, or would docker logs monitoring be enough?

My current crowdsec collections


  • crowdsecurity/linux
  • crowdsecurity/appsec-generic-rules
  • crowdsecurity/caddy
  • crowdsecurity/whitelist-good-actors
  • crowdsecurity/http-cve
  • crowdsecurity/iptables

Edit: bonus question, does someone know if the Gitea collection would be useful for Forgejo after it being a hard-fork now?

6
Good (canon) comics (self.star_wars)
submitted 2 months ago* (last edited 2 months ago) by whysofurious to c/[email protected]
 

As per title, I just finished Andor. I always wanted to read some star wars comics (years ago I read the Marvel's Vader series). I would love to read some good comics or storyarcs if anybody has any advice.

I would prefer something not focus on the skywalkers but that expands on the general story and lore, I was looking at Doctor Aphra, but not sure if it's good or not.

Thanks!

[–] whysofurious 2 points 2 months ago

I totally agree with you, thanks for suggesting this change.

[–] whysofurious 2 points 2 months ago (3 children)

Let me start by saying that I am in favour of the rule. Going into topics-centered community and voicing against that topic is kind of stupid, and everybody should be able to feel safe in their own spaces. All my concerns (generality of the rule, downvote trolling and automating moderation) were already voiced by others and addressed one by one. Also, as a practical suggestion, maybe we can have sticky posts in each community where the rule will be applied? Not forever, but for a set period of time.

I waited longer to give my answer, as I am very skeptical about AI in general but in favour of many other instance topics, and I wanted to form my own opinion on the topic at hand before commenting. I am really happy at the level of the discussion here and how the feedback was received by OP. I didn't agree with some comments on other posts leading to this one, but I am happy to see that the discussion was kept objective and on-point, so a huge thank to OP and everyone who participated for showing me how the instance governance and discussion works (I'm relatively new here).

In the end, while I don't go specifically go searching for AI content and barely see it in my feed, I am happy that stuff like AI-horde exist, and I really think it's a good way of doing things. And in general, the governance experiment here and the way this instance is managed is way more important for me than my own opinions on AI.

[–] whysofurious 4 points 2 months ago

I agree with LibreCalc and CSV, in some internationalclasses we always had issues with excel saving CSV in actually different formats depending on the machine locale. LibreCalc never had this problem.

[–] whysofurious 2 points 2 months ago (3 children)

Nice, didn't know that, thank you! :)

[–] whysofurious 2 points 2 months ago (5 children)

How do you do it? Last time I tried the only way possible was with PSNow

[–] whysofurious 4 points 2 months ago (2 children)

Would've kept one of Stallman/Torvalds/Kropotkin for us oldies :P but apart from that looks great!

I agree with @[email protected]'s second point about rule 4.

[–] whysofurious 2 points 2 months ago

Same, every time I read avatar I'm super hyped about some last airbender stuff, and then....

view more: next ›