Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
view the rest of the comments
I encrypt everything.
I have a repository set up with all my keys for all my encrypted drives. The keys get rar'd with a strong, known, 50 character password, and the filenames encrypted so no one can just open the rar file and gaze at the keys.
These get backed up in a 3,2,1 schema, and also to thumb drives stored in secure places. I also rotate the passwords on a regular basis, so the process starts all over again.
sudo cryptsetup luksDump /dev/sdXsudo cryptsetup luksAddKey /dev/sdXsudo cryptsetup luksRemoveKey /dev/sdXsudo cryptsetup luksDump /dev/sdXThe headers are not secret. Anyone with physical, read access to the device can run
luksDump. It reveals algorithm, key derivation parameters, number of keys, but not the passphrase or master key.As far as 'best practice', that will be determined by subsequent replies to your post. LOL That's just how I do it.
You can dettach your headers with
--header.I've started putting the header and key on my boot partition on a USB key. Without the usb, the hard drives appear to be filled only with random data (plausible deniability). After booting, the USB can be removed to prepare for a panic shutdown.
I did not know this. That would seem, abiding by your system, to be more secure. I will have to investigate.
Thanks for sharing.