• One Identity Provider for Everything merox merox #homelab#authentik#sso#docker#security#cloudflare#kubernetes

    Replacing scattered logins with Authentik on Oracle Cloud. Google login everywhere, proxy auth for Guacamole, OAuth2 for Portainer, and a K8s outpost for cluster services.

  • The Axios Supply Chain Attack merox merox #security#npm#supply-chain#javascript#nodejs

    A compromised maintainer pushed poisoned axios versions containing a cross-platform RAT.

  • SSH Hardening - Securing Your Linux Servers merox merox #security#ssh#linux

    Practical SSH hardening for production Linux servers — key-based auth, sshd_config, 2FA, host-based auth, fail2ban, and log monitoring.

  • SMB Authentication with AD on Linux merox merox #security#smb#linux#active-directory

    How to integrate Linux SMB file servers with Active Directory using SSSD, Samba, Kerberos, and realmd — tested on RHEL 8 and OpenSUSE 15.6.

  • Tailscale site-to-site pfSense - Linux merox merox #security#vpn#tailscale#pfsense

    How to set up a Tailscale site-to-site L3 connection between a pfSense homelab subnet and a Linux cloud VM subnet.