I’ve managed to set up a baikal server to sync my calendars and tasks instead of using a free cloud service provided by nextcloud. I’m able to reach it from beyond my local network, but this is all very new to me and I’m a little worried about what permanently leaving a port open for this.

I’m hoping to find some resources for securing this, before leaving it up all the time. I suppose as an alternative I can always only run it at home and only sync when I’m home but this seems less ideal.

Thanks a bunch for the help in advance. I really appreciate it.

  • drudoo@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 year ago

    Use a reverse proxy in front and be sure to have auth setup in Baikal.

    I’ve been using it with traefik for 5ish years now without issues.

  • wildbus8979@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    There are a number of options…

    Setup a reverse proxy with nginx, using SSL, with http auth or better yet client certificates.

    Setup a VPN to access your home network.

    Use SSH forwarding to access the local service.

    • Corr@lemm.eeOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 year ago

      Are these all roughly equivalent in security? Or is it a case of some of these being a bit less complex to set up but you sacrifice security? I’ll look into these options though. Thank you

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    1 year ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    HTTP Hypertext Transfer Protocol, the Web
    IP Internet Protocol
    SSH Secure Shell for remote terminal access
    SSL Secure Sockets Layer, for transparent encryption
    VPN Virtual Private Network
    nginx Popular HTTP server

    5 acronyms in this thread; the most compressed thread commented on today has 11 acronyms.

    [Thread #80 for this sub, first seen 25th Aug 2023, 11:15] [FAQ] [Full list] [Contact] [Source code]

  • Jerry1098@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    Just in case you never heard of it, there is also the option to use Tailscale. It lets you connect to your services without opening any ports and uses Wireguard under the hood but makes configuration simpler

    • Corr@lemm.eeOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 year ago

      I have wireguard set up now and its working completely fine now. Thanks for the recommendation!