This site doesn't sit on someone else's hosting. It comes from a small Linux server I set up and run at home, the same one that hosts my clients' sites.
- No open doorsThe server has no ports open to the internet. Visitors reach it through an encrypted tunnel, so there is nothing to scan or attack directly.
- Passkeys instead of passwordsAdmin tools and private apps sit behind a login that needs a fingerprint or a security key. There's no password to steal or guess.
- Looks after itselfSecurity updates install automatically, repeated failed logins get blocked, and uptime monitoring tells me if something goes down.
- Many apps, one small boxWebsites, a music server, photo backup and smart-home control all run side by side in Docker containers.
$ systemctl is-active cloudflared fail2ban unattended-upgrades
active
active
active
$ sudo fail2ban-client status sshd | grep banned
|- Currently banned: 0
$ curl -sI https://n1ji.dev | grep -i ^server
server: cloudflare # the tunnel, not my IP
Want the details: configs, mistakes and what I'd do differently?
Read the blog · for nerds only XD