<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Selfhosting on JermaNoiD</title>
    <link>https://jermanoid.com/tags/selfhosting/</link>
    <description>Recent content in Selfhosting on JermaNoiD</description>
    <image>
      <title>JermaNoiD</title>
      <url>https://jermanoid.com/papermod-cover.png</url>
      <link>https://jermanoid.com/papermod-cover.png</link>
    </image>
    <generator>Hugo -- 0.155.3</generator>
    <language>en</language>
    <lastBuildDate>Mon, 14 Sep 2026 21:28:15 +0000</lastBuildDate>
    <atom:link href="https://jermanoid.com/tags/selfhosting/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Running a WAF on services I expose on the internet</title>
      <link>https://jermanoid.com/posts/crowdsec/</link>
      <pubDate>Mon, 14 Sep 2026 21:28:15 +0000</pubDate>
      <guid>https://jermanoid.com/posts/crowdsec/</guid>
      <description>&lt;h1 id=&#34;running-a-waf-on-services-i-expose-to-the-internet&#34;&gt;Running a WAF on services I expose to the internet&lt;/h1&gt;
&lt;p&gt;I have a handful of services that anyone on the internet can reach. Most of them are small, but &amp;ldquo;small&amp;rdquo; doesn&amp;rsquo;t mean &amp;ldquo;uninteresting to a scanner.&amp;rdquo; Within an hour of pointing a domain at a box, it gets probed. Not by a human, by a bot. And the probes get creative in ways you don&amp;rsquo;t expect.&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s what pushed me to put a web application firewall in front of my public endpoints. I went with CrowdSec, and this is why, and how.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
