• One Identity Provider for Everything #security#homelab

    Replacing scattered logins with Authentik on Oracle Cloud. Google login everywhere, proxy auth for Guacamole, OAuth2 for Portainer, and a K8s outpost for cluster services.

  • The Axios Supply Chain Attack #security#javascript

    A compromised maintainer pushed poisoned axios versions containing a cross-platform RAT.

  • SSH Hardening - Securing Your Linux Servers #security#ssh#linux

    Practical SSH hardening for production Linux servers — key-based auth, sshd_config, 2FA, host-based auth, fail2ban, and log monitoring.

  • SMB Authentication with AD on Linux #security#linux

    How to integrate Linux SMB file servers with Active Directory using SSSD, Samba, Kerberos, and realmd — tested on RHEL 8 and OpenSUSE 15.6.

  • Tailscale site-to-site pfSense - Linux #security#networking

    How to set up a Tailscale site-to-site L3 connection between a pfSense homelab subnet and a Linux cloud VM subnet.