!coeAONBrWyDJnYMbMi:nixos.org

NixOS System Operations

612 Members
About system administration for running NixOS systems in production. Declaratively manage your operations. | Room recommendations: #networking:nixos.org167 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
26 Feb 2025
@dgrig:erethon.comdgrigAll the things you mentioned help however. I personally change the ssh port, enable fail2ban and for a lot of hosts don't have ssh enabled over the internet since wireguard works good enough for me. Other people I know enable ssh only over tor hidden services, but I don't trust tor starting fast enough after a restart /shrug20:27:01
@magic_rb:matrix.redalder.orgmagic_rbI only allow ssh over wireguard period20:28:33
@dgrig:erethon.comdgrig(waiting for a new circuit after a restart can be a bit annoying if you're trying to ssh right after a restart in my opinion)20:28:36
@scrumplex:duckhub.ioScrumplexAnother way to reduce ssh bot noise is to limit sshd to listen on IPv6 only20:50:50
@sigmasquadron:matrix.orgFernando Rodrigues
In reply to @magic_rb:matrix.redalder.org
I only allow ssh over wireguard period
ssh over wireguard is so nice
21:36:06
@hexa:lossy.networkhexayeah, much nicer than just using ssh over internet21:38:07
@hexa:lossy.networkhexa * yeah, much nicer than just using ssh over internet \s 21:38:09
@hexa:lossy.networkhexato be clear, I have a wireguard/babel mesh, so I can ssh over a routed connection of private addresses21:38:39
@sigmasquadron:matrix.orgFernando Rodrigues
In reply to @hexa:lossy.network
yeah, much nicer than just using ssh over internet \s
i mean, unironically yes.
21:38:43
@hexa:lossy.networkhexabut now imagine a git host21:38:49
@sigmasquadron:matrix.orgFernando RodriguesI don't see the issue?21:39:11
@hexa:lossy.networkhexagit+ssh21:39:19
@hexa:lossy.networkhexa* git+ssh://21:39:30
@sigmasquadron:matrix.orgFernando RodriguesSure, just change the IP from whatever it was before to the wireguard address.21:39:43
@sigmasquadron:matrix.orgFernando Rodriguesditto with a domain21:39:50

Show newer messages


Back to Room ListRoom Version: 10