Security
5 posts on Security: design decisions and how-to guides from small infrastructure estates run on a very low budget.
Self-hosted NetBird as the operator plane: firewalls as routing peers, policies as transportOne small VM runs the control plane, with its database shipped to a warm standby every thirty seconds. The firewalls are the routing peers. NetBird policies are treated as transport; real authorisation lives at the service.
- Catalyst 3850: send syslog to a SIEM instead of polling SNMP
Point the switch at the SIEM with logging host, raise the trap level to informational, timestamp with milliseconds, log configuration changes with archive, and let Wazuh decode the rest. Port flaps, LACP changes and failed logins become events next to everything else.
What a webshell taught a small hosting shop: rebuild, never cleanA pre-authentication flaw, exploited days after the fix shipped. A read-only document root that pinned the malware in place. A rebuild reinfected within hours. The timeline, anonymised, and the controls that came out of it.
- OPNsense: keep ACME certificates valid on both HA nodes
The ACME client renews on the node it runs on. The backup keeps serving whatever it had, which after ninety days is an expired certificate at the worst possible moment. A daily copy, an import on the backup, and a fingerprint check that tells you when they differ.
Two roots of trust: Authentik for people, Vault for machinesPeople and machines have different lifecycles, so they get different roots of trust. The protocol ladder, the login policy, the credential shapes, and the one rule that neither root may depend on something it protects.