• tired_n_bored@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 hours ago

    I have 3 subnets. One for me, one for family members and one for the publicly accessible services I expose. Each process has limited access to the file system, no root shell and even in the case someone gains full control of it they can’t reach other subnets. I use fail2ban too.

    For the “me” part, I connect through a VPN. I’d like to run rootless docker services tho, or by using Podman