Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

77 total results found

6.1 How to Use These Playbooks

Privacy and Security Runbook 6. Incident Playbooks

When you discover a security incident: Don't panic - Take a breath; most incidents are recoverable if you act systematically Find the right playbook - Match your situation to one of the scenarios below Follow the steps in order - Steps are prior...

6.1 Account Compromise

Privacy and Security Runbook 6. Incident Playbooks

Compromised Email Account Signs your email might be compromised: Can't log in / password doesn't work Emails you didn't send in your sent folder New forwarding rules or filters you didn't create Password reset emails you didn't request Even assuming ...

6.3 Personal Data Incidents

Privacy and Security Runbook 6. Incident Playbooks

Identity Theft Signs of identity theft: Accounts or loans you didn't open appearing on credit report Calls or mail from debt collectors about debts you don't owe IRS notification of multiple tax returns filed in your name Medical bills for...

6.4 Device Incidents

Privacy and Security Runbook 6. Incident Playbooks

Ransomware Infection Signs of ransomware Files suddenly encrypted with unfamiliar extensions (.locked, .cerber, etc.) Ransom note demanding payment for decryption Desktop wallpaper changed to ransom message Unable to open files (photos, do...

7. Reference

Privacy and Security Runbook

7.1 Maintenance Checklists

Privacy and Security Runbook 7. Reference

Monthly Checklist Time Required: ~30 minutes Backups Verify your computer backup completed successfully (check last backup date) Verify your phone backup completed successfully Check backup drive has sufficient free space For cloud backup...

7.2 Glossery

Privacy and Security Runbook 7. Reference

Term Definition 3-2-1 Rule A backup strategy: keep 3 copies of your data, on 2 different types of storage, with 1 copy stored offsite (like in the cloud). Account recovery The backup ways to prove an account is yours (like a re...

SSO For Small Ecosystems

One identity provider, every service, and the token-mapping details that don't show up in the setup guides.

Forward

SSO For Small Ecosystems

One identity provider, every service, and the configuration that makes it work. This book is a working reference for putting every service in a self-hosted environment behind a single identity provider. It opens with the case for why you should centralize your...

Configuring Discourse (identity-only pattern)

SSO For Small Ecosystems

Pattern: identity only. Discourse authenticates users through Keycloak but does no group or role mapping. The IdP answers one question, "who is this user," and Discourse handles authorization internally with its own trust levels and groups. Use this pattern fo...

Mutual TLS with a Private CA

Running an internal certificate authority to support mTLS and zero trust.

Configuring BookStack (group-aware pattern)

SSO For Small Ecosystems

Pattern: group-aware. BookStack authenticates users through Keycloak and reads their group membership from the token, mapping Keycloak groups onto BookStack roles so that access is driven entirely by the IdP. This is the pattern for any app that should grant p...

Configuring a Flask app (build-it-yourself pattern)

SSO For Small Ecosystems

Pattern: build it yourself. Discourse and BookStack are someone else's applications where you configure OIDC. When the application is your own code, you are the OIDC client: you write the login redirect, the callback, the token validation, and the claim readin...

Concepts

Mutual TLS with a Private CA

Why nothing inside the network is trusted without proof, and how to run the CA that makes it possible. This book is a working reference for putting mutual TLS (mTLS) between every internal component of a self-hosted environment, backed by a private certificate...

Architecture

Mutual TLS with a Private CA

Before the configuration, the model. Three ideas make the rest of this book make sense: where the CA lives, what the trust chain looks like, and the fact that every internal connection uses two certificates, not one. Where the CA lives The certificate authorit...

Standing up the CA

Mutual TLS with a Private CA

This is the identity root for every machine in the environment. Everything else in the book depends on it existing and being trusted. Treat its keys with the same care as any other root secret. Initialize step-ca On the control-plane host, initialize the CA: s...

Issuing and Installing Certificates

Mutual TLS with a Private CA

Every host follows the same bootstrap: make the internal names resolve, trust the CA root, then request the certificates it needs. First: make the internal names resolve Internal services are addressed by names like service.int.example. These names deliberate...

Enforcing mTLS

Mutual TLS with a Private CA

This is where the policy becomes real. The two configurations below, one on the calling side, one on the serving side, are what turn "both ends should authenticate" into "no valid certificate, no connection." Everything before this page was setup, this is the ...