

1·
9 hours agoAdding the security basics, since nobody listed them yet:
- A firewall with default deny, then open only what you need. A simple one such as ufw is fine.
- Install CrowdSec or fail2ban early. Within a day you will see how much junk hits any public server.
- Reach SSH and admin pages over a private network (Tailscale or WireGuard) instead of exposing them.
- Read your reverse proxy access log for a week. It teaches you more about how the internet really behaves than most courses.
None of it has to be perfect on day one, but it is much easier to build in from the start.
Since your records are DNS-only, these requests hit your origin directly, so you can deal with them there no matter who is behind the Worker. A Lemmy host has no WordPress, so anything asking for /wp-login.php, /wp-content/ or /xmlrpc.php is junk. Two cheap fixes: have your reverse proxy reject those paths outright, or use CrowdSec with its WordPress/http-probing scenarios, which bans the source after a few hits.