• 0 Posts
  • 16 Comments
Joined 2 years ago
cake
Cake day: August 15th, 2023

help-circle
  • remotelove@lemmy.catoSelfhosted@lemmy.worldSecrets
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    3 months ago

    I would look into something like Doppler instead of Vault. (I don’t trust any company acquired by IBM. They have been aquiring and enshittifying companies before there was even a name for it.)

    Look into how any different solutions need their keys presented. Dumping the creds in ENV is generally fine since the keys will need to be stored and used somehow. You might need a dedicated user account to manage keys in its home folder.

    This is actually a host security problem, not generally a key storage problem per se. Regardless of how you have a vault setup, my approach here is to create a single host that acts as a gateway for the rest of the credentials. (This applies to if keys are stored in “the cloud” or in a local database somewhere.)

    Since you are going to using a Pi, you should focus on that being a restricted host: Only run your chosen vault solution on it. Period. Secure and patch it to the best of your ability and use very specific host firewall rules for minimum connectivity. Ie: Have one user for ssh in and limit another user account to managing vault, preferably without needing any kind of elevated access. This is actually a perfect use case for SELinux since you can put in some decent restrictions on the host for a single app (and it’s supporting apps…)

    If you are paranoid enough to run a HIDS, you can turn on all the events for any type of root account actions. In theory once the host is configured, you shouldn’t need root again until you start performing patches.



  • Unfortunately, all it will take is one of the Korean groups to be responsible for destroying another Korean group in Ukraine for any retaliation to make it’s way back to the homeland.

    Hell, the story doesn’t even need to be real for one of the Korean governments to start lobbing shells over their border.

    Honestly, I think this is the plan. It was super weird for NK to actually blow up roads on the border. With that, combined with the timing of them sending troops to Ukraine is even more sus. This probably has more to do with US elections, than anything else.





  • Oh. When I said “the west” I was squarely pointing the finger at France. China is playing the longer game there because Russia has stationed Wagner down there already. It benefits both Russia and China if the population is focused on removing French influence. China gets a long term investment hedge against France and Russia gets more cheap mercs for Ukraine.

    Now, I don’t really want to spend much time doing a full research project on what is basically a game of thrones’ish style side bet. It’s insanely complicated, I would imagine. After a few African countries went full-on coup d’état a few months ago, I realized there was much more going on.

    Edit: I wasn’t downvoting you. I suspect that some people might be trying to launch some instability of their own. Lulz.






  • This is just a supplemental aid package which usually doesn’t make the news. It’s mainly just ammo, spare parts and a few vehicles. These updates happen frequently.

    Big packages that are billions of dollars usually include many full weapon systems, lika full Patriot systems.

    I suspect that a the line item for “demolition equipment and munitions” was high explosives and grenades for drone use.

    Here is a rough list of this particular package: