I had a discourse forum which got ddos’d to hell last month (it’s basically a community about news, and what got me ddos’d was the posting of news about ecuadorean protests a month ago. Real eyeopener too). Anyway, this is basically a “hobby” of mine and I don’t really have the money to pay for expert help or expensive servers. It’s just a rather cheap standard vps dedicated exclusively to discourse.
So, what are some good tips you could give me to harden the security of my dirscourse?
This is the one good use case for Cloudflare. But you have to be unbelievably careful that you don’t leak the IP address because if you do it is game over.
That means using cloudflare for “everything” in the forum, so to speak?.
I have cloudlfare in almost standard configuration and works fine. However some posts here recommend “enable this, disable that”, shich makes me fear exactly that: leaking ip.
I disabled “rocket” something and “minification” on cloudflare, that’s basically it. Am I ok?