Author
Moreno De Zorzi

Manage every Docker host from one Portainer using the agent, and why the management layer stays on the LAN instead of ever facing the internet.

Stop exposing services one by one. Set up WireGuard on a UniFi gateway so you reach every LAN-only service from anywhere through a single private door, with nothing else exposed.

A public service gets scanned within minutes. Here's how I put CrowdSec in front of my reverse proxy to detect attacks from the logs and ban the offenders automatically.

The full path from a container on your LAN to a public https site: DNS, port forwarding, and a reverse proxy with a Let's Encrypt certificate, using this Ghost blog as the example.

A lightweight alternative to a full Prometheus and Grafana stack: deploy Beszel as a Portainer stack, monitor multiple hosts, and keep the dashboard off the public internet.