Self-hosted S3-compatible object storage for backups: MinIO behind an Nginx proxy, with an rclone-based backup agent and versioned buckets. Your offsite backups without a cloud bill.
Self-hosted S3-compatible object storage for backups: MinIO behind an Nginx proxy, with an rclone-based backup agent and versioned buckets. Your offsite backups without a cloud bill.
The front door pattern: Nginx terminating TLS with automated Let's Encrypt renewal via Certbot, hardened by CrowdSec WAF/IPS with the nginx bouncer, kept fresh by Watchtower. One compose file in front of every other stack on this site.
A deployment guide with working examples — not a downloadable product. Everything below is the actual configuration I use, abridged to the parts that matter.
services:
nginx:
image: nginx:${NGINX_VERSION:-1.27-alpine}
container_name: ssl-nginx
restart: unless-stopped
ports:
- ${HTTP_PORT:-80}:80
- ${HTTPS_PORT:-443}:443
volumes:
- ./config/nginx.conf:/etc/nginx/nginx.conf:ro
- ./config/conf.d:/etc/nginx/conf.d:ro
- certbot-www:/var/www/certbot
- certbot-certs:/etc/letsencrypt
- ${LOG_DIR:-./logs}:/var/log/nginx
depends_on:
certbot:
condition: service_completed_successfully
networks:
- proxy
healthcheck:
test:
- CMD
- nginx
- -t
interval: 30s
timeout: 5s
retries: 3
crowdsec:
image: crowdsecurity/crowdsec:${CROWDSEC_VERSION:-v1.6.8}
container_name: ssl-crowdsec
restart: unless-stopped
environment:
- COLLECTIONS=crowdsecurity/nginx
- GID=${PGID:-1000}
- UID=${PUID:-1000}
volumes:
- crowdsec-db:/var/lib/crowdsec/data
- crowdsec-config:/etc/crowdsec
- ${LOG_DIR:-./logs}:/var/log/nginx:ro
networks:
- proxy
Excerpt — nginx, crowdsec from the compose file. The remaining services (proxies, init jobs, exporters) follow the same pattern and mount their configuration from a config/ directory.
Copy .env.example to .env and at minimum set:
HTTP_PORT=80
HTTPS_PORT=443
NGINX_VERSION=1.27-alpine
LOG_DIR=./logs
PROXY_NETWORK=ssl-reverse-proxy
CERTBOT_VERSION=latest
CROWDSEC_API_KEY (use openssl rand -base64 32)./logs//etc/letsencrypt/ (SSL certs).env for production deploymentsA guide, not a product. This page is deployment documentation with working examples — there is no zip, no download, no support contract. You adapt the patterns to your own environment, and you own the result.
Want this running production-grade in your infrastructure instead? Edge security like this is part of my infrastructure consulting — details on the consulting page: €1,000/day, remote or on-site, invoice as usual.