Yes this is very important.
For spending, calculate your daily spend limit (monthly income divided by 31) and try not to spend anything more than that any given day. If you need to spend more then you have to save that money from thee day before. Do not lend money from future days. Only accumulate from money not spent in the past. For example your monthly income 3100, then your daily spend limit is 100. You cannot spend 150 and hope that tomorrow you will only spend 50. Do it I. Reverse. Today spend 50. If you manage it, tomorrow spend 100. Only if necessary that you can spend 100 + the 50 you saved the day before.
Also try getting rid of the pets. I can't believe you pay insurance for the pet. We do have people that have no insurance even for themselves. I know you love them, but it times are hard. Maybe be give them to someone you know so you can get them back once you are doing better.
You haven't spoken much about food but you have cook your own food and snacks. Do not eat out. Do not but snacks. Your health and pocket will thank you. You can have snacks for really cheap. Just find inspiration in the internet or your relatives.
It is good you have solved you initial issue. However, as you say, your rules are too permissive. You should not publish ports from containers to the host. Your container ports should only be accessible over reverse-proxy network. Said otherwise :3000 should not resolve to anything.
This can be simply acheive by not publishing any port on your service containers.
Here is an example of my VPS:
Exposed ports:
$ ss -ntlp
State Recv-Q Send-Q Local Address:Port Peer Address:Port Process
LISTEN 0 128* users:(("sshd",pid=4084094,fd=3))
LISTEN 0 4096* users:(("conmon",pid=3436659,fd=6))
LISTEN 0 4096* users:(("systemd-resolve",pid=723,fd=11))
LISTEN 0 4096* users:(("conmon",pid=3436659,fd=5))
LISTEN 0 4096* users:(("systemd-resolve",pid=723,fd=19))
LISTEN 0 4096* users:(("systemd-resolve",pid=723,fd=17))
Redacted list of containers:
$ podman container ls
[...] node ./streaming 2 months ago Up 2 months (healthy) social_streaming keydb-server /etc... 2 months ago Up 2 months (healthy) cloud_cache
localhost/podman-pause:4.4.1-1111111111 2 months ago Up 2 months>80/tcp,>443/tcp 1111111111-infra traefik 2 months ago Up 2 months>80/tcp,>443/tcp traefik nginx -g daemon o... 3 weeks ago Up 3 weeks cloud_web nginx -g daemon o... 3 weeks ago Up 3 weeks social_front
@noclue I guess the dress is just three hundred fifty five dollars.
I guess they say $335,000 with a coma si it is just three hunder thirty five dollars while the interest rate is 6.95% with a dot so it is almost a seven?
Why should the drives be sneakily deposited. If he trusts his relative or friend he may just tell them to keep it safe until new gets out.
However the bigger challenge would be to read the files using newer technology since those drive connectors might get obsolete. Maybe you need to store technology you can read it with. For example an external disk drive with USB 3 cables and Somme USB C adapters. If using internal drives this gets a bit complicated since you would need also some cables and motherboards. So external hard drives would be easier.
Maybe you could delete Reddit. But you can self-host your own lemmy instance in addition to you website. It does not hurt to have your own website in addition to social media.
However, you cannot host a lemmy on github pages.
The only two important columns are "Local address: port" and "process". The later is what process is listening whille the former is the interface that process is listening on and the port.
So you see that I don't have any process listening on any port other than 80 and 443 iin the host and the regular ones.
That said, you containers will still listen on the ports you want but only on a virtual network interface.
Basically you only need to publish ports 80 amd 443 on the container or pod you have your reverse proxy on. Other containers need to only be attached to the same network as you already did.