Replying to @⁨pineapplelover@lemmy.dbzer0.com⁩

You will.

Anything you expose should be designed for it (e.g. not jellyfin). You should have a WAF configured for the type of service you’re hosting. You can’t just drop one and have it magically protect you, they take configuration. Same with fail2ban.

And you should have these services in a DMZ, so that a compromise in one doesn’t provide an entry point to other resources on your network.

en