home-lab/machines/reverse-proxy
Geir Okkenhaug Jerstad 304e868e09 Add reverse-proxy configuration with DMZ-specific security
- Create reverse-proxy machine configuration for VPS edge server
- Configure SSH access only via Tailscale (100.96.189.104)
- Implement strict DMZ firewall rules (HTTP/HTTPS only externally)
- Add enhanced fail2ban settings for DMZ environment
- Include sma user with SSH key management
- Configure Nginx reverse proxy with Let's Encrypt SSL
- Add reverse-proxy to flake.nix nixosConfigurations

Security features:
- SSH only accessible through Tailscale interface
- Aggressive fail2ban settings (24h ban, 3 max retries)
- Firewall rejects all non-essential traffic
- No common network config to avoid security conflicts
2025-06-05 16:47:52 +02:00
..
About.org docs: add content to reverse-proxy About.org 2025-06-04 16:36:44 +02:00
configuration.nix Add reverse-proxy configuration with DMZ-specific security 2025-06-05 16:47:52 +02:00
gandicloud.nix Add reverse-proxy configuration with DMZ-specific security 2025-06-05 16:47:52 +02:00