3 ms·
> I just rent a VPS and run it on that. I don't want anything I don't own initiating connections to anything on my home network in any way. I do this for my p
by cloudbonsai 5y ago
> I just rent a VPS and run it on that. I don't want anything I don't own initiating connections to anything on my home network in any way.
I do this for my personal web server, but also set up the network rule so that its SSH port is only reachable from my VPN.
IMO, this is super convenient. I can keep my public servers out of my home network (so clear separation of private/public networks), but still a VPN connection is required to log into any of my servers.
- inportb 5y agoWhat do you do if your VPN goes down and you need access to your server to debug it? Is physical access required or do you have other contingency plans?
- cloudbonsai 5y ago> What do you do if your VPN goes down and you need access to your server to debug it Here is exactly what I would do: 1. Sign in to AWS console (with my Yubikey). 2. Click "Lightsail > instances > <my-server>" 3. Click "Networking > Allow Lightsail browser SSH/RDP" 4. Click "Connect using SSH". 5. Do debugging! In short, you can use cloud providers' web interface as an escape hatch. This just works as long as you manage the firewall using your cloud provider's network filter, such as Security Group, rather than, say, iptables.
- qw3rty01 5y agoSome providers like digitalocean use a serial connection for the terminal, so it works even when the network configuration is completely broken somehow (totally not because you set the input policy to drop without making an accept rule first)
- yolovoe 5y agoEC2 has this too: https://aws.amazon.com/about-aws/whats-new/2021/03/introducing-ec2-serial-console/ https://aws.amazon.com/about-aws/whats-new/2021/03/introduci... Works even if you mess up the boot process somehow Disclaimer: I work here