One thing I enjoy about runing a home server is that there are so many levels of “hygeine.” These levels range from “running everything as root with no SSH hardening and asking to get hacked” to “locked down with 97% of the security measures of a large tech company” and everything in between. Here are a few levels I have traversed:
Dedicated users for each service (or a dedicated kubernetes user if you go that route) SSH and firewall hardening to do things like forbid password-based authentication, only allow connections from specific IP addresses or interfaces, forcing the use of modern cryptographic algorithms and key-exchange mechanisms, even forcing all outbound traffic to go through a proxy that enforces rules/standards. BACKUPS. Regular and tested. Locked down file permissions with group membership or ACLs mediating much of the access control. Quarterly security audits of installed packages, registered users, permissions, etc. (rootless) containerization with limited and deliberately mounted directories/files from the host to limit the blast radius of compromised services Auditable and reproducible infrastructure as code (how long would it take you to reconfigure your server from a fresh OS install?) TLS/SSL to prevent/practice preventing man-in-the-middle attacks in web services. I have learned that good security is layered (defense in depth ) and even if one layer is compromised, there are other layers still acting as defense. A good barometer of a well-secured home server is “if some web service I run is compromised, could an attacker exfiltrate my family photos or important documents?) And learning/understanding these layers is a journey. You start at one level to get off the ground and as long as you use a tool like Ansible, you can effectively reflect on the security-convenience-simplicity tradeoffs made and make things more secure over time. There really is something to be said for “just starting” and iteratively improving. There really is no single “here is the initial checklist of security measures from which you can expand” because everyone starts from a different place. And it is difficult for an individual who has been paid lots of money as a software engineer to understand production-grade linux server environments to appreciate exactly how difficult it is for someone without mentors, an “infosec” team, and hours every day to spend on this nonsense how difficult this really is. Even something simple like “forbid password-based SSH authentication” is difficult because one should only take this measure when one truly understands how asymmetric cryptography works and the exact kinds of attacks it prevents.
...