• 0 Posts
  • 15 Comments
Joined 2 years ago
cake
Cake day: September 29th, 2023

help-circle









  • Use tailscale for host nodes, use tailscale docker container in a compose stack with an app that you sidecar to. That way that app is on your tailnet as if it is its own computer. Use tailscale serve for reverse proxying support of the apps. Then, setup a vps node (I use linodes $5 node) with tailscale and configure that to be your DMZ into your tailnet.

    For DMZ, use Caddy, UFW, and fail2ban. Also take advantage of ACLs in the Tailscale admin console to only have the VPS able to route traffic to specific apps you want to expose. My current project is to work in Authelia into this setup so a user logs into one exposed app and is able to traverse to other exposed apps through header / token authentication.

    Oh also, segment the tailnet using different authentication keys. Each host node should have its own key, all the apps on a host node should have a shared key, and all public facing clients should have a common shared key. That way in case of compromise you can revoke the affected keys without bringing down your network.






  • From an electrical engineering perspective H O S E D. Historically, “Oh you want to manufacture something cheaply but can’t due to IP issues or CCP conflicts of interests? Why not Malaysia, Vietnam or the Philippines?”

    People got to realize this is gonna jack up the supply chain so hard. Texas Instruments an IC manufacturer produces some stuff in texas. If my production is in Malaysia then surprise! Tariff to send components to Malaysia. But wait, programming, testing, packaging, and inventory of the boards is in the USA. So the PCBA is surprise surprise Tariff again. Now that the board is considered finished and ready to be sold, it turns out your customer is in china or anywhere else in the world…. So tariff. These Tariffs compound. The business isn’t going to foot the bill so its gonna get pushed to customers.

    I am really curious how the TSMC foundry in AZ is gonna work out. They can produce the wafers but packaging is done still in Taiwan. So tariff to Taiwan , tariff again back to the USA, and the tariff again because its an advanced electronic component?