Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

77 total results found

Keeping Renewal Boring

Mutual TLS with a Private CA

Short-lived certificates are only a good idea if renewal is reliably automated. The price of short lifetimes is that expiry must be a non-event, and the only way to get there is automation. Certificates in this setup presented live 90 days at most, usually les...

Configuring Keycloak

SSO For Small Ecosystems

A running Keycloak does nothing useful until you decide how realms are split, how users prove who they are, how long sessions last, and how groups and roles are named. Those decisions are hard to change later, because every downstream application depends on th...

Deploying Keycloak

SSO For Small Ecosystems

Everything else in this book assumes a working Keycloak that applications can reach over HTTPS and that you can administer safely. This page covers the deployment and the next covers configuring realms inside it. The deployment below is written as a standalone...

Appendix A - SSO Test App

SSO For Small Ecosystems

Clone the repo into a location capable of serving a python flask application. git clone https://git.landisfam.org/landisfam/ssotest Create a virtual environment and install the requirements. python3 -m venv venv source venv/bin/activate pip install -r requirem...

WAF for Small Ecosystems

Concepts

WAF for Small Ecosystems

The single front door to a self-hosted environment: what it inspects, what it terminates, and what it refuses to pass. This book is a working reference for putting a web application firewall (WAF) in front of every public-facing service in a self-hosted enviro...

Why This Design

WAF for Small Ecosystems

A single edge host that terminates public TLS, inspects every request, and forwards only what passes inspection. This page is the reasoning behind that shape and the tool choice Why terminate everything at one host The alternative to a single edge is exposing ...

Architecture

WAF for Small Ecosystems

Where the edge sits and what it hands off to. The WAF is one boundary in a layered defense, and understanding what it does and does not own makes the configuration pages make sense. Where the WAF sits The WAF host lives at the edge of the private network. It i...

Standing Up the Edge

WAF for Small Ecosystems

The reverse proxy and public TLS, before any inspection is added. This is the baseline every public site sits on. Nginx routing a hostname to a backend over public TLS, with a consistent per-site configuration that new services slot into. Install nginx from th...

Adding Inspection

WAF for Small Ecosystems

Attaching application-layer inspection to the reverse proxy. Standing up the edge gave you a proxy that routes and terminates TLS. This page adds the part that examines requests and refuses those identified as malicious, and sets up the principles that makes b...

Operating It

WAF for Small Ecosystems

A WAF is not a set-and-forget install. It is a control you have to be able to see working, tune when it is wrong, and trust when it fires. This page is about running it after it is standing. Logging A control you cannot observe is a control you cannot trust. O...

Lessons Learned

WAF for Small Ecosystems

The lessons I've learned from running a single-edge WAF in a self-hosted environment. Run learning mode longer than feels necessary. The instinct is to turn on blocking as soon as it is installed, because an inspecting WAF that isn't blocking feels pointless. ...

Homebrew SIEM

How to build meaningful security monitoring without a SIEM product, and how to reason about what to watch.

Concepts

Homebrew SIEM

Meaningful security monitoring without a SIEM product, and how to reason about what to watch. This book is a working reference for building basic security monitoring across a self-hosted (linux) environment using tools you already have: the system logger, a fe...

Architecture

Homebrew SIEM

The whole system is four stages in a line: collect, centralize, analyze, alert. Every later page is one of these stages in detail. The pipeline Collect. Every host generates logs already; authentication attempts, firewall decisions, service errors, system mess...

Collection

Homebrew SIEM

Pattern: getting logs off every host and into one place. This is the plumbing, getting this stage right is what everything else depends on. The mechanism is the standard Linux system logger (rsyslog), configured on each host to forward, and on one central host...

What to Monitor

Homebrew SIEM

Pattern: deciding what is worth watching. This is the judgment page, and it is deliberately general. It walks the categories worth monitoring and the reasoning for each, without the thresholds or exact detection logic, because those are the part that helps an ...

Analysis

Homebrew SIEM

Pattern: turning collected logs into signals. Collection gathers raw logs, analysis reduces them to the handful of statements worth acting on. This page shows one category in full, health monitoring, chosen because it is operational rather than a detection tri...