For Riccardo · From Giuseppe · Droplet 206.189.197.6
Want to harden the WAHA droplet: install Caddy for HTTPS, rotate the API key, install fail2ban. About 90 minutes of work with roughly 5 minutes of WAHA downtime. Need your green light before touching anything. Can we schedule it for tomorrow off-hours?
There are active news reports of public WAHA instances being exploited by scammers. They push spam from the connected number, then WhatsApp permanently bans the number. I audited our setup and found three real risks worth closing before it becomes our story.
waha.signalstaff.ai to the dropletlocalhost:3000. Port 3000 stops being exposed to the internet..env. Redeploy Sophie. Old key dies.Free memory right now is around 350 MB. Caddy idles around 25 MB, fail2ban around 15 MB. Post-install we are looking at about 310 MB free. Works, but tight. Worth bumping the droplet to 2 GB at $12 per month at some point. Already noted in your TODO.