• 2 Posts
  • 33 Comments
Joined 2 years ago
cake
Cake day: July 20th, 2023

help-circle


  • Ehmmmm I still don’t grasp what you mean.

    In any case, mandos has a possibility to do it automatically via rsa encryption, so you have the possibility of totally unattended restart.

    Because the server is (ideally) in a different location, if one of yiur systems is stolen / compromised then you only delete / revoked the certificates ID and then that machine would not be able to decrypt its own luks system.

    I never deployed this system on my own, but I know a few guys who did it

    Regards









  • Yes, it is possible, but you need a domain (example.com) that I guess you want to be resolved from internet and a public face ip.

    After that, yep, if the reverse proxy can resolve tailscale names (basically it has tailscale installed in the same machine) and the service is reachable via tailscale, then it is perfect.

    In fact in my setup I have a public domain name that is translated into a private domain name in the reverse proxy (exactly what you want with the addition of tailscale)