This is a continuation of my other post

I now have homeassistant, immich, and authentik docker containers exposed to the open internet. Homeassistant has built in 2FA and authentik is being used as the authentication for immich which supports 2FA. I went ahead and blocked connections from every country except for my own via cloudlfare (I’m aware this does almost nothing but I feel better about it).

At the moment, if my machine became compromised, I wouldn’t know. How do I monitor these docker containers? What’s a good way to block IPs based on failed login attempts? Is there a tool that could alert me if my machine was compromised? Any recommendations?

EDIT: Oh, and if you have any recommendations for settings I should change in the cloudflare dashboard, that would be great too; there’s a ton of options in there and a lot of them are defaulted to “off”

  • Jeena@piefed.jeena.net
    link
    fedilink
    English
    arrow-up
    26
    ·
    9 months ago

    So there is https://en.wikipedia.org/wiki/Fail2ban which helps already to some degree.

    But what are you trying to prevent? You have your services in a docker container, hopefully not running as root, which already makes it difficult to break out even if through a bug someone would be able to get access to the docker container.

    I mean its not like your stuff is very important for someone to break in like the pentagon, you probably just have some photos from your phone on it, some lights can be switched on and off and some temperatures read.

    I’m not trying to say that you should not care about it but I’m trying to figure out what your threat model is.

    • a_fancy_kiwi@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      24
      ·
      edit-2
      9 months ago

      I feel weird about having those apps on the internet and basically being blind to threats. I mean yeah, I’m not a target on anyone’s list and most IPs visiting the site are bots but I would still like to know what’s going on.

      I don’t work in tech for a living, this is just a hobby for me so I have limited time to work on this stuff and do research. It’s very possible I fucked something up and don’t know it. I figured if I at least got an alert that said “hey, your immich server db was dumped and sent to <insert IP>”, I could at least turn it off

      • AtariDump@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        9 months ago

        By the time you get the alert and act on it, it’s too late.

        Don’t expose these things to the open internet; VPN back into your network and access them.

      • ikidd@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        9 months ago

        Yah, it’s just a hobby for you, but it’s also a hobby for script kiddies to use Shodan to find people with out of date web interfaces and pop them. I tell you right now, the Immich team would be the first to say not to put their application publicly accessible.

        Just don’t get into this practice, it ends in tears and is way more maintenance to stay protected than just setting up tailscale and using that.

    • credo@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      9 months ago

      IOT botnets are a thing. And if someone wanted to fire sell the US, all the vulnerable home networks would be on the table too. Great for a bit if extra chaos.