
Void
560 posts




You should never ever expose a VPS to the entire internet Always firewall it to subnets If you host a website you should only allow port 443 (HTTPS) inbound from Cloudflare's IP range / subnets Port 22 (SSH) only from your Tailscale subnet range That means you create a "tunnel" from Cloudflare and Tailscale (your laptop) to your server's door You still need your SSH key to open the door btw If you don't, ANYONE in the entire world can connect to your VPS and if there's just one security vulnerability and you didn't upgrade your VPS you can get hacked If you do have it firewalled with Tailscale subnet only, it means only if they hack your laptop they could get in via your Tailscale there Another thing is ask OpenClaw or Claude Code to enable unattended upgrades with auto reboot

@levelsio @nfcodes I created a redis instance on hetzner with public port open for few minutes and someone was running a cryptominer the next moment taking 50% CPU 💀 After that I always use @Tailscale 👌


Footage shows a massive fire raging at the Shahran oil depot on the outskirts of northern Tehran after an Israeli attack late Saturday. The Israeli military says it struck fuel storage and related sites it alleges are linked to the Iranian armed forces.

Tehran’s Shahran oil depot is completely consumed by a massive blaze after Israeli airstrikes hit the facility tonight.













Started wearing Kolhapuris to office lately. No laces, no sweat, no morning friction. Just walk in and start working. Perfect for Indian weather. Funny how formal shoes built for colder boardrooms became the default here while footwear designed for our climate stayed informal





















