Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

Niclas

@niclas@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

#sysadmin #devops #devsecops #cybersecurity #honeypot #privacy #homelab #firewall #monitoring #selfhosting #logs #metrics #securityengineering

0 Followers
0 Following
14 Posts
Joined July 29, 2025
GitLab:
https://gitlab.com/niclasheinz
GitHub:
https://github.com/niclasheinz
Website:
https://nheinz.eu
Open post
Niclas @niclas@infosec.exchange
· 5mo ago

After quite some time, I finally have all the pieces in place. Over the last 30 minutes, I’ve set up one of my servers from scratch. Here are some key changes:
- Reverse Proxy: Nginx with Modsecurity (WAF)
- Container Isolation: Every container runs in a seperate linux user
- Podman Quadlet: I rewrote all my compose stacks into quadlet files - now all containers are starting probably after reboot 🥳
- Grafana: Grafana's configuration is no managed by Opentofu which provitions at the moment the datasources (Grafana Loki and Prometheus) as well as the dashboards.
- Server hardening: Improved ssh configuration, firewall, permissions in general on this host
- Ansible: Everything is powered by ansible
- Certbot: Use wildcard certificates for my domains / subdomains for easier renew process
- Backups: All those services have proper backups configured which are timed with systemd timer and are replicated into my local homelab.
- Services that are running at the moment
- Grafana
- Prometheus
- Grafana Loki
- Grafana Alloy
- GitLab Runner
- some other services that I wanna migrate to this server

#homelab #sysadmin #linux #ansible #automation #devsecops #selfhosting #declarative #gitops #monitoring

7
0
2
0
Open post
Niclas @niclas@infosec.exchange
· 1mo ago
Since March 2026, I have been running honeypots on the internet to collect data and analyze attack patterns. The amount of data stored in the log database has steadily increased over the past few months and has now reached 70 GB of raw logs. I may need to consider a better archiving strategy, especially since I am thinking about adding a T-Pot instance, which would significantly increase the load on the current database setup. #honeypot #postgresql #sysadmin #cybersecurity #blueteam
1
0
1
0
Open post
Niclas @niclas@infosec.exchange
· 5mo ago

Now I get notified when my certificates are expiring before everything breaks.

#monitoring #observability #certificates #grafana #selfhosting #sysadmin

4
0
1
0
Open post
Niclas @niclas@infosec.exchange
· 2mo ago
What are you using as a Web Application Firewall in Kubernetes Environments with a traefik ingress controller? #kubernetes #traefik #selfhost #homelab #waf #webapplicationfirewall
1
0
0
0
Open post
Niclas @niclas@infosec.exchange
· 3mo ago

I’ve been running honeypots on the internet for about four months. I’ve looked in detail at the mdrfckr botnet (Outlaw) and written a blog post about it.

https://nheinz.dev/blog/2026/06/mdrfckr---a-almost-decade-old-botnet/

#honeypot #botnet #cybersecurity #threathunting #threatintel

1
0
1
0
Open post
Niclas @niclas@infosec.exchange
· 5mo ago

Decided to switch from VMware Workstation 17 to QEMU + Virtual Machine Manager today and spent two hours debugging networking. Turned out the VM couldn't reach the internet and my host couldn't ping the VM due to two conflicting routes for the same subnet. Removed the old VM network route and everything started working - finally 🥳 .

#networking #sysadmin #dumb #qemu #vmware

2
0
0
0
Open post
Niclas @niclas@infosec.exchange
· 4mo ago

Does anyone know if there's an equivalent to "GitLab Components" in Forgejo?

#forgejo #Gitlab #CICD #Devops #Devsecops

1
0
0
0
Open post
Niclas @niclas@infosec.exchange
· 6mo ago

The most interesting supply chain attack I've ever seen: #trivy

The attack is really bizarre. I learned a lot about GitHub Actions and how the attack was performed.

- https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/
- https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation
- https://ramimac.me/trivy-teampcp/#timeline
- https://snyk.io/articles/trivy-github-actions-supply-chain-compromise/

#cybersecurity #supplychain #github #glassworm #githubactions #attack #TeamPCP #c2

1
0
3
0
Open post
Niclas @niclas@infosec.exchange
· 7mo ago

With this structure, the variables in “host_vars” and “group_vars” are not loaded. This is because the inventory file is not in the root directory. Is there a way to have the inventory file in an inventory folder?

#ansible #sysadmin #devops #gitops #automation

1
0
1
0
Open post
Niclas @niclas@infosec.exchange
· 2mo ago

Has anyone tested Coraza as a WAF in Kubernetes? I switched to the traefik-modsecurity-plugin because roughly 50–75% of all HTTP/2 traffic was returning HTTP 500.

#Kubernetes #k8s #k3s #traefik #waf #coraza #modsecurity

0
0
0
0
Open post
Niclas @niclas@infosec.exchange
· 5mo ago

@nwcs@mastodon.social

That does sound interesting. Especially for those who are currently in the process of moving away from VMware Workstation and don't want to have to rebuild and reconfigure all their VMs. Migrating from VMware to Qemu gives me the chance to sort through my roughly 40 VMs and figure out which ones I actually still need (I'll probably delete 30 of them). And I can quickly rebuild the rest using backups and Ansible and get them back up and running.

0
0
0
0
Open post
Niclas @niclas@infosec.exchange
· 7mo ago

Please give me a reason, why #ec2 on #aws has less than 5GB tmp and 0 SWAP space? Sooner or later, you'll run into problems😞 .

#sysadmin #linux #cloud

0
0
0
0
Open post
Niclas @niclas@infosec.exchange
· 2w ago
A new blog post from me: https://nheinz.eu/blog/2026/08/redtails-long-runner/ #cybersecurity #honeypot #c2 #redtail #botnet
0
0
0
0
Open post
Niclas @niclas@infosec.exchange
· 7mo ago
Replying to @appsinet@phpc.social

@appsinet@phpc.social Interesting. Are your playbooks also located in a subfolder and not in the inventoryfolder? Because for me, those vars are not loaded when executing the playbook with ansible-playbook -i inventory/inventory.yml playbooks/infra.yml

0
4
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 14:34:19 UTC