selfhosted
caddy-security
selfhosted | caddy-security | |
---|---|---|
13 | 17 | |
293 | 1,234 | |
- | - | |
2.8 | 8.1 | |
10 months ago | 22 days ago | |
Shell | Go | |
- | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
selfhosted
-
Access local services by domain name when 1 server hosts all services?
Here’s a guide a wrote a while back after I typed this up a bunch of times in comments https://github.com/subdavis/selfhosted/blob/main/docs/lan-only-routes.md
- Is there a more up-to-date guide than this?
-
Looking for help/direction on easy, reliable, and secure self-hosting for remote devices
https://github.com/BaptisteBdn/docker-selfhosted-apps https://github.com/subdavis/selfhosted https://github.com/htpcBeginner/docker-traefik https://github.com/petersem/dockerholics
-
Deploy compose file from github
Link to my full configuration.
-
Sensible folders and permissions for Docker selfhosting?
Here’s a link to my full config, which is really close to what you’re trying to do. https://github.com/subdavis/selfhosted
-
CD for docker-compose files in Git repo?
I do this exact thing, see my config here https://github.com/subdavis/selfhosted
-
Do you share services when using docker-compose?
I would tend to opt for multiple database instances, but you can still use one large docker-compose.yml file if you want. My example is here: https://github.com/subdavis/selfhosted/blob/main/docker-compose.yml
- To those who have set up some kind of automatic deployment of their services on pushes to a git repo, how do you manage environment variables/.env files?
- Portainer like software for deployment of stacks from git repositories
- File hosting software
caddy-security
- Caddy-Security: Security App and Plugin for Caddy
-
Security flaws in an SSO plugin for Caddy
There is no "refusal" as far as I can tell. The issues were reported [1] in September 2023 (as was this blog post) and the simplest one has been fixed (insecure random seed). I'm not aware of any public statements from the plugin maintainers, and there is no hostility in the issue comments.
[1]: https://github.com/greenpau/caddy-security/issues?q=is%3Aiss...
> September 18, 2023: The disclosure blog post was released and issues were filed with the original project repository.
I don't see those issues listed in the GitHub project issue tracker https://github.com/greenpau/caddy-security/issues. Have they been deleted?
-
Web authentication for reverse proxy
Check out https://github.com/greenpau/caddy-security
-
What 3rd party auth provider would you guys recommend to use with Caddy on Windows, and are there any tutorials or documentation?
There a pretty comprehensive auth plugin for Caddy. It can do local authentication with a session cookie, which should work with your IPTV apps. If your app can show a login form, it's super easy, but if I remember correctly you can also authenticate with basic auth and store the session in a cookie (this is mostly used to carry over the authentication to a different subdomain).
-
Q: I need help with securing my selfhosted services
I use Caddy + Caddy Security, set up OAuth, and also only expose services over IPv6. It's not extra security, but it's less logs to deal with because nobody is scanning IPv6 address ranges, and there are less IPv6 capable hosts who are compromised.
- Authentication in Go? Best practices
-
Web server with content upload and authentication
Not sure if this fits your bill, but have a look at Caddy web server and its available authentification methods or even more with a plugin
-
Hiding Public IP
Also look at github.com/greenpau/caddy-security to enable MFA for Caddy.
-
Guacamole + LetsEncrypt (Nginx/Træfik) + VPN ? (x-post r/selfhosted)
- Guacamole docker connects to Debian VNC Desktop - Caddy docker offers HTTPS proxy with Guacamole and the Caddy Security plug in for Auth with TOTP
What are some alternatives?
docker-traefik-nextcloud-nginx - docker compose files for traefik nextcloud and nginx
caddy-auth-portal - Authentication Plugin for Caddy v2 implementing Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google, Facebook, Okta, etc.), SAML Authentication. MFA with App Authenticators and Yubico.
envconsul - Launch a subprocess with environment variables using data from @HashiCorp Consul and Vault.
scim-for-keycloak - a third party module that extends keycloak by SCIM functionality
Pi-hole - A black hole for Internet advertisements
caddy-maxmind-geolocation - Caddy v2 module to filter requests based on source IP geolocation
Automate-Noip-DUC - Automate the Noip-Update-Client Installation and Noip Startup Process in Ubuntu 20.04 LTS
SuperTokens Community - Open source alternative to Auth0 / Firebase Auth / AWS Cognito
docker-traefik - Docker media and home server stack with Docker Compose, Traefik, Swarm Mode, Google OAuth2/Authelia, and LetsEncrypt
webauthn - WebAuthn (FIDO2) server library written in Go
docker-selfhosted-apps - Collection of selfhosted apps with docker only ! Traefik, Bitwarden, Wireguard with Pihole, Synapse with Elements, etc.
Keycloak - Open Source Identity and Access Management For Modern Applications and Services