Hello. I’m pretty new here. I just managed to get my Raspberry Pi setup at home to selfhost a simple website that will act as my portfolio for some art I do.

I’m using WordPress to make the content of the website, meaning it runs on Apache, MariaDB and MySQL in the background. It’s connected via port 80 since I don’t want to pay for SSL certificates to setup https. There will be no accounts or transactions happening on my website. I don’t have anything to manage my dynamic IP but I’ll figure that out later. I’ve deleted the default Pi user on the RPi.

Are there security issues I should address preemptively? I’m worried for instance that I am exposing my home network, making it easier for someone to breach into whatever is connected there.

Any tips on making sure my setup is secure?

  • Shimitar
    link
    fedilink
    English
    232 days ago

    Go https, today there is no real reason not to and tons of good reasons to do it.

    Let’s encrypt is 100% free and using their certbot its also automated and easy to do.

    • PSoul•LemmyOP
      link
      English
      12 days ago

      Thanks, I’ll look into it. I didn’t know there were free SSL certs out there

      • @[email protected]
        link
        fedilink
        English
        12 days ago

        Yeah, afaik, you just need to install letsencrpyt and then run the command with sudo. It’ll scan your apache conf and generate you an ssl version. Just make sure to include your domain name in the ServerName directive