Back openDesk Edu for a sovereign, open-source education — every vote counts.
Vote nowSave products you love by clicking the heart icon.
Hochwertiger Reverse-Proxy mit automatischer SSL-Zertifikatsverwaltung, CrowdSec WAF/IPS und automatischen Updates ohne Ausfallzeiten.
No payment required
The information, code snippets, configuration files, and instructions provided in this product are shared for educational and informational purposes only. While every effort has been made to ensure accuracy, you are solely responsible for reviewing, testing, and adapting any code or configurations to your own environment before using them in production.
No liability: The author(s) shall not be held liable for any damages, data loss, system outages, security breaches, or other issues arising from the use, misuse, or inability to use the code, configurations, or instructions provided in this product. By downloading or using this product, you acknowledge that you understand and accept these terms.
Production-ready self-hosted AI inference stack with Ollama, Open WebUI, and LiteLLM — unified API gateway, GPU-accelerated inference, and a ChatGPT-compatible chat interface.
Get all 5 production-ready infrastructure stacks (SSL Reverse Proxy, Database Foundation, MinIO S3 Backup, n8n Production, Observability) plus the DevOps Cheatsheets Bundle at 20% off. Save €9.95!
Production-ready PostgreSQL + Redis with automated daily backups, 30-day retention, and optional S3 off-site sync.
Diese Lösung verwandelt einen einfachen Docker-Host in einen sicheren Eingangspunkt. Alle Ihre Dienste – Webanwendungen, APIs, Datenbanken – werden hinter einem abgesicherten Nginx-Reverse-Proxy mit automatischer TLS-Terminierung bereitgestellt.
Enthalten: Nginx, Certbot, CrowdSec + bouncer, Watchtower
| Aspekt | Naive selbstsignierte Zertifikate | Diese Lösung |
|---|---|---|
| SSL-Verlängerung | Manuell alle 90 Tage | Automatisch, 12-Stunden-Checkzyklus |
| WAF-Schutz | Keiner | CrowdSec basiert auf Verhaltensmustern (SQLi, XSS, Brute-Force) |
| Rate Limiting | Manuelle iptables-Regeln | Nginx-integriert + CrowdSec-Ban-Entscheidungen |
| Sicherheitsheader | Oft fehlen | CSP, HSTS, X-Frame-Options vorab konfiguriert |
| Updates | Vernachlässigt | Watchtower führt automatische Updates aller Container durch |
DOMAIN=example.com und EMAIL=you@example.com in .env.docker compose up -d aus.CrowdSec verwendet einen verhaltensbasierten Erkennungsmechanismus – es lernt, wie normaler Verkehr aussieht, und markiert Anomalien, ohne sich ausschließlich auf Signaturdatenbanken zu verlassen. Der Nginx-Bouncer wendet CrowdSec-Ban-Entscheidungen auf der Reverse-Proxy-Ebene an, bevor Anfragen Ihre Upstream-Dienste erreichen.
Für alle, die selbstgehostete Dienste betreiben, die einen sicheren öffentlichen Eingangspunkt benötigen. Besonders wertvoll, wenn Sie bereits Docker-Dienste betreiben und diese hinter einem einzigen, TLS-terminierten Eingangspunkt mit minimalem Konfigurationsaufwand konsolidieren möchten.