Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Larvitz
Larvitz
@Larvitz@mastodon.bsd.cafe  ·  activity timestamp 2 months ago

Made my FreeBSD server at Netcup ready to host multiple isolated applications with automatic https via Let's Encrypt.

Internet → Server → PF firewall → Caddy jail (reverse proxy) → Individual application jails

Each app gets its own isolated jail for security, while Caddy handles all the routing and https. PF keeps the front door locked.

All of course with IPv6 first, where every Jail has it's own public IP address and using NAT for legacy IPv4.

Love how FreeBSD jails make this kind of segmentation so elegant.

#FreeBSD #Jails #SelfHosting #Caddy #ipv4

Traffic flow diagram
Traffic flow diagram
Traffic flow diagram
  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.40 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct