• 1 Post
  • 14 Comments
Joined 3 years ago
cake
Cake day: June 20th, 2023

help-circle
  • I have just recently started messing with Authentik. And I can confirm OIDC claims and whatnot are an absolute nightmare. I have some experience setting up SAML stuff from my work, but I only do that if our main guy is out and I always struggle with it there too.

    Your setup sounds the most like what I am doing now, minus the DMZ. But all of my containers are rootless. I am running everything on TrueNAS right now.

    I think I will lean more on Authentik, as the provisioning of users and giving them access to services through that is very easy. I will probably stick with Cloudflare for the time being, but I will look more into Pangolin.





  • I would like to avoid paying for a VPS. I probably should have clarified in my post too that I am specifically looking for advise on securing public facing services. While I certainly could make everyone use a tailscale-like service, at this point I think securing an external service would be easier. Especially since most of these people would not be tech savvy and I don’t particularly want to play tech support for their VPN.






  • These contracts do not stipulate reimbursement for lost revenue. The “uptime guarantee” just gets you a partial discount or service refund for the impacted services.

    It is on the customer to architect their environment for high availability (use multiple regions or even multiple hyperscalers, depending on the uptime need).

    Source: I work at an enterprise that is bound by one of these agreements (although not with AWS).



  • I’ve never used your exact setup, but I have had issues with a web server behind a WAF not getting the client IP (all user traffic was shown as the WAF IP). In my case, the WAF was appending the client IP in a header, and I just had to tell web app to use that header as the client IP instead of the actual IP. Again, not sure if this helps since I have never used podman or caddy (this setup was with Wordpress and an Azure Application Gateway) but the same principles might apply.