Publishing garage telemetry to the internet invites scanning. Lock down who can read feeds, rate-limit public endpoints, and never expose the Arduino JSON port directly without understanding the risk.
Hardening checklist
- HTTPS only on public URLs; HSTS at the reverse proxy.
- Optional API keys or signed tokens for non-browser clients.
- Firewall the Arduino to LAN-only; only the relay reaches it.
- No secrets in firmware source committed to public repos.
Dashboard integration
Users paste HTTPS feed URLs in temperature feed settings. The site stores URLs per account: pair with Supabase auth so feeds are not world-editable.
Compare stacks
Node and Next patterns for APIs: Node Express API patterns. This project uses Astro fetch routes: Astro SSR.
FAQ
Do ESP32 freeze probes need a public IP?
No for push ingest: the board POSTs outbound HTTPS to ProbeHarbor. Pull feeds need a reachable HTTPS JSON URL if you use that path.
How should I harden a DIY JSON relay?
Terminate TLS, restrict source IPs when possible, and avoid embedding ingest keys in public repos. Prefer ProbeHarbor push keys from Dashboard → Devices.