▲ | dizhn 4 days ago | |||||||
Don't you use Keycloak for SSO? The ports needed for that needs to be accessible so services can talk to it. If there's a dedicated port for management you can still use it with software like pangolin. Run the management service on only a local port and access using this software or wireguad. I use authentik and as far as I know the management is on the same web port so I have to allow some paths to be accessible to the world. | ||||||||
▲ | djlameche 4 days ago | parent [-] | |||||||
I'm not using anything YET. I am thinking about hosting a pepper variety database I am developing on a VPS for public use. I want to use Keycloak for authentication and also some other services alongside (eg. a headless CMS for writing some of the content). The thing is, I don't have any prior experience with hosting at all. So I am wondering if I can reduce attack surface by making "management" services (Keycloak admin console, the headless CMS admin interface etc.) accessible only to me... | ||||||||
|