Advanced Search
Search Results
62 total results found
Configuring a Flask app (build-it-yourself pattern)
Pattern: build it yourself. Discourse and BookStack are someone else's applications where you configure OIDC. When the application is your own code, you are the OIDC client: you write the login redirect, the callback, the token validation, and the claim readin...
Concepts
Why nothing inside the network is trusted without proof, and how to run the CA that makes it possible. This book is a working reference for putting mutual TLS (mTLS) between every internal component of a self-hosted environment, backed by a private certificate...
Architecture
Before the configuration, the model. Three ideas make the rest of this book make sense: where the CA lives, what the trust chain looks like, and the fact that every internal connection uses two certificates, not one. Where the CA lives The certificate authorit...
Standing up the CA
This is the identity root for every machine in the environment. Everything else in the book depends on it existing and being trusted. Treat its keys with the same care as any other root secret. Initialize step-ca On the control-plane host, initialize the CA: s...
Issuing and Installing Certificates
Every host follows the same bootstrap: make the internal names resolve, trust the CA root, then request the certificates it needs. First: make the internal names resolve Internal services are addressed by names like service.int.example. These names deliberate...
Enforcing mTLS
This is where the policy becomes real. The two configurations below, one on the calling side, one on the serving side, are what turn "both ends should authenticate" into "no valid certificate, no connection." Everything before this page was setup, this is the ...
Keeping Renewal Boring
Short-lived certificates are only a good idea if renewal is reliably automated. The price of short lifetimes is that expiry must be a non-event, and the only way to get there is automation. Certificates in this setup presented live 90 days at most, usually les...
Configuring Keycloak
A running Keycloak does nothing useful until you decide how realms are split, how users prove who they are, how long sessions last, and how groups and roles are named. Those decisions are hard to change later, because every downstream application depends on th...
Deploying Keycloak
Everything else in this book assumes a working Keycloak that applications can reach over HTTPS and that you can administer safely. This page covers the deployment and the next covers configuring realms inside it. The deployment below is written as a standalone...
Appendix A - SSO Test App
Clone the repo into a location capable of serving a python flask application. git clone https://git.landisfam.org/landisfam/ssotest Create a virtual environment and install the requirements. python3 -m venv venv source venv/bin/activate pip install -r requirem...
Concepts
The single front door to a self-hosted environment: what it inspects, what it terminates, and what it refuses to pass. This book is a working reference for putting a web application firewall (WAF) in front of every public-facing service in a self-hosted enviro...
Why This Design
A single edge host that terminates public TLS, inspects every request, and forwards only what passes inspection. This page is the reasoning behind that shape and the tool choice Why terminate everything at one host The alternative to a single edge is exposing ...
Architecture
Where the edge sits and what it hands off to. The WAF is one boundary in a layered defense, and understanding what it does and does not own makes the configuration pages make sense. Where the WAF sits The WAF host lives at the edge of the private network. It i...
Standing Up the Edge
The reverse proxy and public TLS, before any inspection is added. This is the baseline every public site sits on. Nginx routing a hostname to a backend over public TLS, with a consistent per-site configuration that new services slot into. Install nginx from th...
Adding Inspection
Attaching application-layer inspection to the reverse proxy. Standing up the edge gave you a proxy that routes and terminates TLS. This page adds the part that examines requests and refuses those identified as malicious, and sets up the principles that makes b...
Operating It
A WAF is not a set-and-forget install. It is a control you have to be able to see working, tune when it is wrong, and trust when it fires. This page is about running it after it is standing. Logging A control you cannot observe is a control you cannot trust. O...
Lessons Learned
The lessons I've learned from running a single-edge WAF in a self-hosted environment. Run learning mode longer than feels necessary. The instinct is to turn on blocking as soon as it is installed, because an inspecting WAF that isn't blocking feels pointless. ...
Concepts
Meaningful security monitoring without a SIEM product, and how to reason about what to watch. This book is a working reference for building basic security monitoring across a self-hosted (linux) environment using tools you already have: the system logger, a fe...