User avatar
Niko @niko@gts.niko.lgbt
8mo
i am once again going to put this PSA out because i've just seen yet another case of a fedi instance doing this (and especially if you're hosting at home you should do this)

if you are using a reverse proxy to hide your origin IP, you should proxy
ALL outbound requests through the same proxy server
if you don't do this all it takes to expose your origin IP is spinning up a fedi instance and getting a inbound request from your instance

GoToSocial natively supports this with the HTTP_PROXY environment variable, this instance uses
github.com/cfal/shoes as its outbound proxy and it works great for the load i get
other fedi software likely supports similar
1
2
3
0
User avatar
walnut 🌱 @walnut@thesoftestpaws.net
8mo
@niko
Did you happen to be looking at the logs and see this or did you set up an automatic alert if it notices that pattern?
1
0
0
0

User avatar
Niko @niko@gts.niko.lgbt
8mo
@walnut i was looking at logs
1
0
0
0
User avatar
Niko @niko@gts.niko.lgbt
8mo
@walnut gts automatically logs inbound request IP addresses
0
0
0
0