A Linux Server Hardening Baseline

The concrete, non-negotiable set of changes to make on every Linux server before it goes anywhere near the internet -- SSH, firewall, updates, and fail2ban, done right.

Beginner 1 h Free

Network Scanning with nmap and Trivy

See your homelab the way an attacker would: what ports are actually open, and which of your container images have known vulnerabilities -- on your own network, with permission.

Intermediate 1.3 h Free

Single Sign-On for the Homelab with Authentik

One login for every self-hosted service, with real MFA -- instead of a different password (or no password at all) guarding each one.

Intermediate 2 h Free