Skip to main content


If you're self-hosting for privacy, spend 10 minutes hardening your VPS first


in reply to devtoolkit_api

Are people really running VPSes open to the Internet???

Surely everyone not using cloud hosting sticks some sort of router/firewall at the edge and runs the VPS inside with port forwarding?

And then uses WireGuard/Tailscale as the only ingress?

I mean, that was all rather trivial for me to set up for my extended family to all have untrusted access to VPS services on my network. Tailscale even supports passkeys, so you run less of a risk of credential leaks and 2FA theft.

in reply to Em Adespoton

Surely everyone not using cloud hosting sticks some sort of router/firewall at the edge and runs the VPS inside with port forwarding?


I would really like to see a setup guide for this. Because if you are throwing a VPS up, they usually just give you a public ip address. I don't really know how you would put a router/firewall in front.