Why I stopped exposing services directly

Saturday, 2 May 2026

Opening a port for each service felt simple until the logs filled with login attempts within hours of the first one going live. The internet scans everything, constantly, the moment it can reach you.

Everything now sits behind a single reverse proxy with real certificates, and the few things that need outside access sit behind a login page rather than a bare public port.

The attack surface went from a dozen doors to one, and that one gets the attention it deserves. The logs are quiet again.