Ask HN: How do you securely self-host a server?

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  • ops-utils

    Scripts for setting up and running web infrastructures

  • https://github.com/uxtely/ops-utils/tree/main/location-serve...

    - Networking (Firewall, Jails/Containers)

  • ansible-anu

    ANU is an automated and simple way to securely provision a A New Ubuntu machine using Ansible.

  • I prefer to run Ubuntu machines and at least in terms of provisioning a new secure server I built an Ansible playbook I called 'ANU' (as in A New Ubuntu). I'd expand to other distros, but then I'd have to change the name!

    https://github.com/MitchellCash/ansible-anu

    It is based on the DevSec OS/SSH hardening playbooks, but I lean closer towards ease-of-use over security where I think it makes sense. For example, I disable forced password rotation and I keep the default umask value of '022' instead of the more secure '027'.

    When I come across something the upstream playbooks change that "gets in my way", I will disable it if the security trade off makes sense for me. I'm not running highly sensitive systems, so these trade-offs make sense for me, and maybe they will for you as well!

    In terms of ongoing security upkeep, I run the usual `apt update && apt dist-upgrade` when I can, but I’ll be keeping my eye on this thread for additional advice.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • pibox-os

    📦💻 The Official PiBox Operating System

  • I’m building a product that tries to make this easy at https://pibox.io - but “secure” is a vague and tall goal post - although we cover things like service updates, firewalls, and abuse monitoring. Planning on a proper HN launch post soon!

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • Need to write README but don't know what to say? 7 diagram generators

    5 projects | news.ycombinator.com | 2 Apr 2022
  • Show HN: D2c.sh – Cloudflare 'A' records for dynamic DNS

    1 project | news.ycombinator.com | 16 Mar 2024
  • Dness: A Dynamic DNS Client

    1 project | news.ycombinator.com | 9 Dec 2023
  • Show HN: FreeBSD Manager for Desktops (Via Ansible)

    1 project | news.ycombinator.com | 28 Oct 2023
  • now that Google Domains is going the way of the Dodo...

    1 project | /r/selfhosted | 23 Jun 2023