Advanced Search
Search Results
77 total results found
Keeping Renewal Boring
Short-lived certificates are only a good idea if renewal is reliably automated. The price of short lifetimes is that expiry must be a non-event, and the only way to get there is automation. Certificates in this setup presented live 90 days at most, usually les...
Configuring Keycloak
A running Keycloak does nothing useful until you decide how realms are split, how users prove who they are, how long sessions last, and how groups and roles are named. Those decisions are hard to change later, because every downstream application depends on th...
Deploying Keycloak
Everything else in this book assumes a working Keycloak that applications can reach over HTTPS and that you can administer safely. This page covers the deployment and the next covers configuring realms inside it. The deployment below is written as a standalone...
Appendix A - SSO Test App
Clone the repo into a location capable of serving a python flask application. git clone https://git.landisfam.org/landisfam/ssotest Create a virtual environment and install the requirements. python3 -m venv venv source venv/bin/activate pip install -r requirem...
WAF for Small Ecosystems
Concepts
The single front door to a self-hosted environment: what it inspects, what it terminates, and what it refuses to pass. This book is a working reference for putting a web application firewall (WAF) in front of every public-facing service in a self-hosted enviro...
Why This Design
A single edge host that terminates public TLS, inspects every request, and forwards only what passes inspection. This page is the reasoning behind that shape and the tool choice Why terminate everything at one host The alternative to a single edge is exposing ...
Architecture
Where the edge sits and what it hands off to. The WAF is one boundary in a layered defense, and understanding what it does and does not own makes the configuration pages make sense. Where the WAF sits The WAF host lives at the edge of the private network. It i...
Standing Up the Edge
The reverse proxy and public TLS, before any inspection is added. This is the baseline every public site sits on. Nginx routing a hostname to a backend over public TLS, with a consistent per-site configuration that new services slot into. Install nginx from th...
Adding Inspection
Attaching application-layer inspection to the reverse proxy. Standing up the edge gave you a proxy that routes and terminates TLS. This page adds the part that examines requests and refuses those identified as malicious, and sets up the principles that makes b...
Operating It
A WAF is not a set-and-forget install. It is a control you have to be able to see working, tune when it is wrong, and trust when it fires. This page is about running it after it is standing. Logging A control you cannot observe is a control you cannot trust. O...
Lessons Learned
The lessons I've learned from running a single-edge WAF in a self-hosted environment. Run learning mode longer than feels necessary. The instinct is to turn on blocking as soon as it is installed, because an inspecting WAF that isn't blocking feels pointless. ...
Homebrew SIEM
How to build meaningful security monitoring without a SIEM product, and how to reason about what to watch.
Concepts
Meaningful security monitoring without a SIEM product, and how to reason about what to watch. This book is a working reference for building basic security monitoring across a self-hosted (linux) environment using tools you already have: the system logger, a fe...
Architecture
The whole system is four stages in a line: collect, centralize, analyze, alert. Every later page is one of these stages in detail. The pipeline Collect. Every host generates logs already; authentication attempts, firewall decisions, service errors, system mess...
Collection
Pattern: getting logs off every host and into one place. This is the plumbing, getting this stage right is what everything else depends on. The mechanism is the standard Linux system logger (rsyslog), configured on each host to forward, and on one central host...
What to Monitor
Pattern: deciding what is worth watching. This is the judgment page, and it is deliberately general. It walks the categories worth monitoring and the reasoning for each, without the thresholds or exact detection logic, because those are the part that helps an ...
Analysis
Pattern: turning collected logs into signals. Collection gathers raw logs, analysis reduces them to the handful of statements worth acting on. This page shows one category in full, health monitoring, chosen because it is operational rather than a detection tri...