this post was submitted on 10 Dec 2025
430 points (99.5% liked)

Selfhosted

59939 readers
607 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam.

  3. Posts here are to be centered around self-hosting. Please ensure it is clear in your post how it relates to self-hosting.

  4. Don't duplicate the full text of your blog or git here. Just post the link for folks to click.

  5. Submission headline should match the article title.

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

By 'Git instances' they mean Gogs instances that allow open registration. I know most of the community moved from Gogs to Gitea, and then to Forgejo, but thought this was still worth noting.

you are viewing a single comment's thread
view the rest of the comments
[–] ITGuyLevi@programming.dev 2 points 6 months ago (2 children)

I keep mine accessible from the internet, its just more useful to me like that. I do have registration disabled though and SSO is handled by Authentik so it could be worse (my personal goal has just been to not be the easiest target, perfect security is a myth in my mind).

[–] Jason2357@lemmy.ca 2 points 6 months ago

Theres a HUGE difference between hosting it essentially read-only to the world, vs allowing account creation, uploading, and processing unknown files by the server.

I have thought of blocking access to the commit history pages at the reverse proxy to cut off 99% of the traffic from bots. If anyone wants to look at the history, its just a git clone away.

[–] possiblylinux127@lemmy.zip 1 points 6 months ago* (last edited 6 months ago) (1 children)

You could also throw it behind mTLS

[–] ITGuyLevi@programming.dev 1 points 6 months ago

I could, but then I would have issues getting to it from work; from the bit I've read about mTLS, it's not really indended for my use case, I think I'll just stick with TLS.