CrowdSec Locked Me Out of My Own Server
A post-mortem: how an intrusion-prevention system banned my homelab IP and removed all access at once, how I got back in, and the two-layer whitelist that stops it happening again.
total 9 posts
A post-mortem: how an intrusion-prevention system banned my homelab IP and removed all access at once, how I got back in, and the two-layer whitelist that stops it happening again.
Centralising logs from ten machines into Loki with rsyslog and Alloy, adding metrics with Prometheus, and building the dashboards that answer security questions.
Hosting your own email in 2026: the full stack, the DNS records that decide whether you land in an inbox, and the mistakes that get you blacklisted.
Replacing a cloud push service with ntfy: the access model that keeps topics private, wiring it into Grafana and camera alerts, and the limits worth knowing.
Setting up an HTML email report of CrowdSec security alerts delivered to your inbox every morning with Postfix and Gmail SMTP relay.
Practical security hardening steps for LXC containers in a Proxmox homelab — SSH, AppArmor, unprivileged containers, and resource isolation.
Setting up a self-hosted Tailscale control server with Headscale to securely access your homelab from anywhere.
Setting up centralised logging, metrics dashboards, and intrusion detection for a Proxmox-based homelab with open-source tools.
How to use NGINX as a reverse proxy with automatic TLS certificates to expose multiple self-hosted services through a single entry point.