Ways to Expose Services Publicly
from pineapplelover@lemmy.dbzer0.com to selfhosted@lemmy.world on 06 Aug 03:32
https://lemmy.dbzer0.com/post/73497592

I want to expose my services publicly on my own domain name, how would you guys do that?

I have seen people using Cloudflare, but I don’t want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I’ve done some rough researching.

What do you guys do?

#selfhosted

threaded - newest

ISolox@lemmy.world on 06 Aug 03:35 next collapse

Reverse proxy is what you need. I would post instructions here but honestly they wouldnt be that good. Just search it up and follow along.

lazylemons@lemmy.today on 06 Aug 03:45 next collapse

Recently set up caddy myself, very straightforward setup. You essentially just edit one config file and point your domain host to the right place and are good to go. Took me by surprise actually.

pineapplelover@lemmy.dbzer0.com on 06 Aug 04:06 collapse

Yeah but my main concern is security. If I publicly have services like jellyfin or something then I would think I would have constant exploits and bot attacks

frongt@lemmy.zip on 06 Aug 04:15 next collapse

You will.

Anything you expose should be designed for it (e.g. not jellyfin). You should have a WAF configured for the type of service you’re hosting. You can’t just drop one and have it magically protect you, they take configuration. Same with fail2ban.

And you should have these services in a DMZ, so that a compromise in one doesn’t provide an entry point to other resources on your network.

lazylemons@lemmy.today on 06 Aug 10:54 collapse

Oh for sure. I would only do so if you have a proper firewall running, a DMZ set up. Among other precautions.

electric_nan@lemmy.ml on 06 Aug 04:00 next collapse

Is the server at your house? Or VPS?

pineapplelover@lemmy.dbzer0.com on 06 Aug 04:05 collapse

My server is at home

electric_nan@lemmy.ml on 06 Aug 08:08 collapse

The way that I handled this, was to get a $5 VPS, and have it proxy all my traffic over wireguard. Your DNS records (and SSL cert) all point to the VPS public IP address. IPtables rules route all relevant traffic.

spork@pawb.social on 06 Aug 04:02 next collapse

I rent a cheap VPS with iptables routing ports through a wireguard tunnel to a peer on the local network that acts as a firewall and reverse proxy, this gives you a static IP with a local control plane and no ddns.

pineapplelover@lemmy.dbzer0.com on 06 Aug 04:06 next collapse

What’s a cheap vps you recommend?

TheRedSpade@lemmy.world on 06 Aug 04:38 next collapse

Linode has a $5/month option.

Andres4NY@social.ridetrans.it on 06 Aug 05:23 collapse

@TheRedSpade @pineapplelover Linode got acquired by Akamai and their service (or at least, *my* VPS) has really gone downhill over the past few years.

state_electrician@discuss.tchncs.de on 06 Aug 04:49 next collapse

Oracle has a free tier where I run my Wireguard.

sulfidedisburseangledafternoontipper@piefed.blahaj.zone on 06 Aug 08:59 next collapse

I use a cheap racknerd vps via low end box. $12/yr.

pineapplelover@lemmy.dbzer0.com on 06 Aug 13:58 collapse

That’s crazy cheap price. Does it really have enough bandwidth to stream jellyfin?

MangoPenguin@piefed.social on 07 Aug 14:21 collapse

Most VPS are on 1Gbps connections, but even if it only has 100Mbps that’s plenty.

pineapplelover@lemmy.dbzer0.com on 07 Aug 15:13 collapse

Is there a data cap? I’m concerned like they only allow me to pass through like a TB or so of data passing through it within a month. If you have users watching your jellyfin server every day that can surpass your limit.

MangoPenguin@piefed.social on 07 Aug 17:20 next collapse

Yes generally around 1TB on cheap plans. That’s a ton of data though for streaming media, if youre moving more than that getting a higher tier VPS would make sense.

Jason2357@lemmy.ca on 07 Aug 20:07 collapse

Keep in mind that you wouldn’t route local traffic through it, so everything watched at home would be direct and not count.

I have a $5/mo VPS with OVH and they allow unlimited bandwidth within reason. Unless you have multiple households streaming from your server all the time, likely totally fine. If you do end up with one relative streaming 24x7, then I would look at installing the tailscale app on their TV and configuring things to connect that one user direct to your home server.

A VPS takes some learning, but IMHO, it is the “correct” answer and worthile learning.

pineapplelover@lemmy.dbzer0.com on 08 Aug 14:01 collapse

How do you set up security on your server with the constant attacks that come with having the server public?

Jason2357@lemmy.ca on 08 Aug 17:31 collapse

There are constant scanners on any site and scrapers on websites, but it is far less of a problem than you would imagine unless you have a big wiki or software forge with hundreds of nested commit history pages for them to spider into.

I also run private servers on hidden subdomains (with wildcard certs and DNS entries), so the low effort scanners never bother them.

DDOS attacks take money, so they aren’t typically going to go after some random homelabber. If it did happen, I would either just shut it off for a while or change the VPs IP. Ovh also has some of its own ddos protection.

pineapplelover@lemmy.dbzer0.com on 08 Aug 19:47 collapse

That sounds perfect, I might go with ovh, how do you like them? The $4.54/mo plan looks cool

Jason2357@lemmy.ca on 08 Aug 19:58 collapse

Their admin interface is slow and awkward, but otherwise happy. Their deals are always changing and I currently have good specs for the money. EU company and my machine is in Montreal, so I was happy with non-American hosting and green electricity.

pineapplelover@lemmy.dbzer0.com on 08 Aug 20:17 collapse

Epic. You probably don’t use the admin interface too much right? Probably just configure your reverse proxy a leave it. Gonna rent a vps here in the states.

Jason2357@lemmy.ca on 09 Aug 16:55 collapse

Indeed, I log in pretty rarely.

pineapplelover@lemmy.dbzer0.com on 11 Aug 04:48 collapse

I keep thinking to myself whether $5/mo or buying a firewall and attempting to achieve the same thing is a better idea

shadshack@feddit.online on 06 Aug 13:39 next collapse

Look into Oracle cloud’s Always Free tier of cloud instances. I have a few of those and they’re decent for free.

spork@pawb.social on 06 Aug 14:24 collapse

I hop around a lot. I’ve used Akamai (fka linode), Vultr, DigitalOcean, AWS EC2, and GCP Compute Engine. I wouldn’t recommend the last 2 anymore because fuck big tech. A lot of people will mention Oracle’s free tier, but I don’t trust anyone that looks like Larry Ellison to own a machine with a direct connection into my local network.

pineapplelover@lemmy.dbzer0.com on 06 Aug 15:32 collapse

I resonate with you as well, so what kind of set up do you use now?

HelloRoot@lemy.lol on 06 Aug 09:23 next collapse

Same but nftables and also crowdsec.

Also I had some trouble with the wireguard tunnel dropping lots of packets, which resulted in my services not loading 50% of the time. I did a lot of suggestions at the same time so I’m not sure which one fixed it but here is a list in case anybody has similar troubles:

  • lowering MTU
  • routing ipv6 through the tunnel as well
  • rewriting nftables rule order (will update after work, notes are at home)
hirihit640@sh.itjust.works on 14 Aug 08:49 collapse

I’m running into similar issues, do you mind expanding on your solutions?

HelloRoot@lemy.lol on 14 Aug 12:09 collapse

I’m still having trouble with it and I’m currently traveling. My analysis so far points to my vps provider being at fault.

I tried doing long term diagnostics, which effectively pinged through the tunnel every 5s and that make it work constantly and perfectly. So maybe some energy saving sleep stuff, which ends up breaking the tunnel?

halcyoncmdr@piefed.social on 06 Aug 10:26 collapse

Similar here. Just a Digital Ocean droplet running Pangolin. Functions basically the same as the cloudflare tunnel it replaced.

Can expose the service directly if needed, or from behind a login page.

Railcar8095@lemmy.world on 06 Aug 21:55 collapse

The basic 4 dolars one? Or something extra?

halcyoncmdr@piefed.social on 11 Aug 04:59 collapse

Pangolin officially says on their site :

Pangolin generally requires minimal resources to run effectively. A basic VPS with 1 vCPU, 2GB RAM, and 8GB SSD is sufficient for most deployments.

If you choose a VPS with only 1GB RAM, you may need to create swap space to avoid memory pressure during installation, updates, or periods of higher traffic.

I’ve got a 1 vCPU, 1GB RAM, 25GB Disk droplet for $6/mo and have no issues for my limited home use. Updates don’t really take a noticeably long time or anything, it takes maybe 45 seconds to fully bring up the docker container again after an update. But it runs just fine.

WhatsHerBucket@lemmy.world on 06 Aug 04:12 next collapse

My router (gl-net) has a VPN server built in. I just use WireGuard client and freedns.

AllYourSmurf@lemmy.world on 06 Aug 04:14 next collapse

Authentication & single sign-on service

Plugged into Reverse proxy, routing to each service by name

With a wild card cert so there are no name leaks.

Make your urls unexpected. If your domain is example.com, don’t put your jellyfin server at jellyfin.example.com. Instead, use watch.example.com or telly.example.com. Anything that’s memorable to you about what the service is without using a specific brand name.

With a wildcard dns record to point all names to your IP, and a wildcard certificate that works for all names loaded on your load balancer, it becomes hard for a hacker to know what name to use to get the load balancer to send them to the service they want to hack.

If you then use a sso tool like traefik’s ForwardAuth middleware, you won’t even get to the service until you’ve first authenticated.

helix@feddit.org on 06 Aug 05:41 collapse

If you use TLS like you should, your domains will be on the internet in the certificate transparency log. Yes, you should use a wildcard cert if you want this security by obscurity, but it’s still security by obscurity.

AllYourSmurf@lemmy.world on 06 Aug 11:54 next collapse

Of course. The goal here is to not advertise. Make it hard for the bots to find you. With these steps, they can try your IP, but there’s nothing directly on your IP.

You still need proper security. Authentication is a good start, and it has the extra effect of adding an extra layer to prevent the bots from going further if they get lucky and guess a host name.

frongt@lemmy.zip on 06 Aug 19:39 next collapse

Or run an internal CA, if you’re the only one accessing the services.

Jason2357@lemmy.ca on 17 Aug 03:53 collapse

Security by obscurity is when the design or archetecture of the system is obscure enough to supposedly styme attackers (it doesnt), and as soon as people understand the design, your security is broken.

A hard to guess unpublished subdomain is a transparent and standard archetecture - nothing obscure about it and publishing that you use such a scheme doesnt break the security.

The subdomain is a bearer token that serves as an access control and just like a key or passphrase, has a security value proportional to the bits of information an attacker has to guess.

The real limitation is that browsers and humans are not great at not leaking domain names, so its very possible it will get leaked eventually and hard to rotate. Thats the reason they are weak. Still, they can be usefull to stop scanners just trolling for unpatched services.

RanchBranch@anarchist.nexus on 06 Aug 04:15 next collapse

I recently switched to Netbird on a VPS (on Vultr). Their reverse proxy is super easy to set up / self host. They also offer a free version that works pretty good too, I just wanted to make it difficult for myself (thats the whole point of self hosting, right? )

pineapplelover@lemmy.dbzer0.com on 06 Aug 04:42 collapse

I have seen netbird pop around every now and again. I might try out their cloud free version first and if I like it I might try self hosting it.

So you host netbird on a vps you rent and that is used for reverse proxy? So with that reverse proxy I can have my home server be publicly accessible and I can have friends log in to my jellyfin server without having to connect to my tailnet.

My last concern is security. How is this set up good for making sure I don’t just get constantly botted and exploited?

innocentzero@kbin.earth on 06 Aug 04:47 next collapse

Opening jellyfin up publicly is kind of asking for trouble if you ask me. I haven't done so myself, but seen enough on this community and elsewhere to know that it's probably not a good idea.

ampersandrew@lemmy.world on 06 Aug 14:45 collapse

By all means correct me if you know more, but what I tend to see is one or two people here saying that Jellyfin devs don’t recommend exposing it publicly, only to be corrected by looking at the actual documentation. I suspect those cautioning against it are on outdated information and that Jellyfin carries much the same risk as exposing any other service.

irmadlad@lemmy.world on 06 Aug 16:41 collapse

but what I tend to see is one or two people here saying that Jellyfin devs don’t recommend exposing it publicly

I think what the devs are saying is ‘don’t expose Jellyfin to the public in an unsafe manner’. I don’t run Jellyfin, but can confirm what you’ve read here. In that vein, don’t expose anything to the public in an unsafe manner.

frongt@lemmy.zip on 06 Aug 19:40 collapse

There is no safe manner of exposing jellyfin.

irmadlad@lemmy.world on 06 Aug 21:18 collapse

Again, I do not run Jellyfin, but what you’re saying seems contradictory to what the devs are implying: here and here. Since I lack the hands on experience, I will leave the issue with the experts.

frongt@lemmy.zip on 06 Aug 22:08 collapse

That first page says exposing it to the Internet is “not recommended”. Putting a reverse proxy in front of it does not meaningfully change the security posture. A malicious request to http://jellyfin.homelab.com/exploitable-page will be sent to jellyfin in effectively the same way, whether through a reverse proxy or not. You would need a WAF set up specifically to look for relevant exploit attempts.

github.com/jellyfin/jellyfin/issues/5415

Those are some outstanding known vulnerabilities, most of them unfixed. They are not particularly severe, but it shows that thorough security is not a priority for the jellyfin devs.

ampersandrew@lemmy.world on 07 Aug 13:10 collapse

It says exposing a port directly to the internet is not recommended; do you know of any project that would recommend directly exposing a port? What is meaningfully different here?

frongt@lemmy.zip on 07 Aug 13:20 collapse

Sure, any project designed to be exposed to the Internet. Web servers would be the most obvious.

ampersandrew@lemmy.world on 07 Aug 13:24 collapse

Probably the number one recommendation I see in self hosting communities is to not open ports directly (other than for a reverse proxy). It seems like a common recommendation no matter the service. To be clear: I am a beginner. I know very little about this, but I’ve spent months learning. I can’t say you’re wrong, but I don’t think you’ve made a convincing argument for me to actually understand why Jellyfin is unsafe to expose to the internet compared to any other service.

frongt@lemmy.zip on 07 Aug 13:56 collapse

You are welcome to expose it at your own risk. Assess you own tolerance for compromise (personal data compromise, becoming part of a botnet, becoming a host for spam or CSAM) and proceed accordingly.

ampersandrew@lemmy.world on 07 Aug 13:59 collapse

Yes, that’s exactly what I’ve done. You still haven’t shown me why it’s unsafe. If you can’t, that’s fine. At some threshold or another, nothing is secure. The one thing I know for sure is that that first page, that says it doesn’t recommend exposing a port, does not say what you said it does.

frongt@lemmy.zip on 07 Aug 14:49 collapse

It sounds to me like you just have a higher risk tolerance, and if you accept that, that’s okay.

innocentzero@kbin.earth on 06 Aug 04:49 next collapse

You're probably misunderstanding what netbird does (unless I'm the one misunderstanding things?).

Netbird subnet is equivalent to a tailscale tailnet (for all practical purposes; they even both use wireguard and hole-punching underneath). Netbird is not a reverse proxy (which I feel is what you think based on your comment).

diecknet@discuss.tchncs.de on 06 Aug 09:50 collapse

While Netbird is generally just one of the many alternatives to Tailscale, they also do have a Reverse Proxy feature that allows access without a Netbird client. Haven’t tested it yet, seems to be in beta.

docs.netbird.io/manage/reverse-proxy

RanchBranch@anarchist.nexus on 06 Aug 13:04 collapse

The reverse Proxy is exactly what I use (in addition to the VPN, but I’m the only one that uses that in my group of cohorts)

Its been in Beta for a but now, but its worked perfectly for me the entire time

TrippinMallard@lemmy.ml on 06 Aug 21:31 collapse

same

stratself@lemdro.id on 06 Aug 06:11 next collapse

I do this albeit with Tailscale. Netbird/Tailscale would act as a node of your VPN and you can configure reverse proxy routes (via tailscale serve or Netbird’s equivalent) from the VPS edge to the homelab. You can even do SNI passthrough and have TLS terminated at your home, if you want, though this can be a bit slower

Alternatively you can even expose stuff via their servers. Tailscale Inc calls this service Funnels, and Netbird should have similar offerings. It’s kinda like Tunnels but you gotta use their domains, so a VPS acts greater as a dedicated entrypoint.

Lastly yes you’d be exposing the service to the general public internet, so some basic security is needed. Netbird has a Crowdsec module integration, might wanna look at that one and set up rules/detections. Consider putting extra auth in front of Jellyfin, use Authelia or something with an auth screen. And only expose the stuff you need, not your internal dashboard or whatever admin UI.

RanchBranch@anarchist.nexus on 06 Aug 13:02 collapse

Yup! They can either connect to your Netbird meshnet (ie, similar a tailnet) or you can reverse proxy it out to the internet (no tailnet needed)

I saw a couple comments below concerned about security, one of the nice things about Netbird is that they have reverse proxy auth built in if you want. Some stuff (Navidrome or VoidAuth for instance) only has geolocation locked down (US only) but other things that I’m either more concerned about or don’t necessarily trust being open (Paperless or Komodo for instance) have Netbird Auth and VoidAuth as sign in options before it will let me open the page. Its worked flawlessly so far, and has kept my sanity intact because I wanted some stuff publically accessible without it being OPEN.

As far as being hammer fucked, it has CrowdSec and Geolocation lockdowns so you can set it to only accept traffic from ONE location and the Crowdsec also catches everything.

lime@feddit.nu on 06 Aug 05:39 next collapse

i configured dyndns in my router and have it forward all traffic to a gateway vm running nginx and fail2ban. every service is on a subdomain so any attempt to fetch things from the main name gets banned.

Nibodhika@lemmy.world on 06 Aug 06:12 next collapse

Why do you want to expose them? This might limit the solutions.

The way I do this is in 2 different ways:

  1. Tailscale, my server connects to tailscale so all I have to do is connect to it from my phone and I can access things remotely easily. This is the best for most things, but has the downside that others can’t access it as easily

  2. I have a VPS (two actually at the moment as I’m switching providers from Vultr to IONOS) that also connects to tailscale so it can access my home server through it, then using Caddy I expose the services on a subdomain of the VPS. This is what I do for things that others might want to access, or things I don’t want to have to connect to tailscale to access.

If you’re going down the second route do consider that you will need to:

  • Add something like fail2ban or crowdsec to the VPS as attacks will happen.
  • Same reason you should add a dedicated authentication on front of most things. While I don’t expect the auth on services to be weak, it might be more vulnerable than a dedicated authentication service. You should look into Authelia, Authentik, or similar to put on front of your services so any attacker would first have to pass that to even get to your services.
KarnaSubarna@lemmy.ml on 06 Aug 06:17 next collapse

Make it publicly available to the world or just for you (and people you know)?

pineapplelover@lemmy.dbzer0.com on 06 Aug 12:54 collapse

Publicly to the world. For example, I wanted to self host temporary file sharing and temporary link shortener to the world. Stuff like jellyfin I would have that public but only specific users would have the credentials to log in.

fozid@lem.radiantfig.fyi on 06 Aug 07:06 next collapse

A reverse proxy is the traditional safe route. Use a web server like Apache, nginx or caddy, and setup to reverse proxy all your services through port 443, and use let’s encrypt and certbot to generate and manage TLS certificates.

I host around 15 public facing web services this way using nginx.

Just be aware, this is very public facing so server security and hardening is important. Things like strong passwords, disabled root, use ssh keys instead of passwords, setup fail2ban, setup crowdsec etc.

The more modern safer way is not to truly expose to full public and use things like tailscale or cloudflare tunnels. But this relies on 3rd party servers and I’m not a fan of that, but it does bring benefits.

lyralycan@sh.itjust.works on 06 Aug 15:44 collapse

A lot of folk decry Cloudflare as a terrible corp (and their AI push now involves the login page shunted to the side while 70% of the screen is a relatively blank section with some sentence about using their AI), but what is the non-3rd party alternative? Does one rely on sharing the IP instead? It is impossible to have public (non-family) traffic without a Cloudflare/Google DNS resolver right?

Being on a standard ISP I cannot use a higher-level rDNS.

fozid@lem.radiantfig.fyi on 06 Aug 21:06 next collapse

im on a basic uk isp, with no fancy router, just the isp provided one. i have a fully exposed web server, im even hosting a lemmy server. Thats my domain, radiantfig.fyi, totally public, has been for nearly 2 years now. From that you can get my servers IP address. My IP is dynamic, changes roughly every 6 weeks. I have a ddns script that updates my server IP address to my domain name provider automatically. I have certbot running updating my TLS certs with lets encrypt, and if a cert dies or fails or is compromised, my server will refuse to serve. Everything is behind an nginx reverse proxy through port 443. I also have an ssh port open on a random port. Have fail2ban setup fairly aggressively to prevent brute force attacks, and have crowdsec which also kind of does the same but in a slightly different way. the internet requires ip addresses. to protect your ip address you have to give somebody elses. that somebody is a 3rd party you have no control or say on the decisions they make. i must have over 20 individual services that are public facing. 3 fully federated, lemmy, forgejo and matrix. Im as secure as any other website. nothing is unhackable, no matter how far down the rabbit hole you go. its all just layers of difficulty.

The important thing is dont listen to random internet people about security. dont listen to me. dont listen to anybody who tells you they know best. do your own research, understand the options, the risks, the compromises. only then do you put anything up. but if you are going to anxious or worried about your server and data, no amount of security guarantees you safety, so be warned.

MangoPenguin@piefed.social on 07 Aug 14:22 collapse

It costs a little but a VPS running Pangolin and Crowdsec is a decent replacement for cloudflare for hiding your IP and having some extra protection.

MagnificentSteiner@lemmy.zip on 06 Aug 07:33 next collapse

I can’t answer your question as I haven’t taken that step yet, everything is still confined to my LAN.

Here’s a similar thread from last month that had a lot of replies. Hopefully will be some useful info there for you. Good luck!

myrmidex@belgae.social on 06 Aug 08:15 next collapse

I got off CloudFlare by using Pangolin. Ideal for my use-case, I didn’t use any of CF’s advanced features, so Pangolin is the ideal replacement for me.

Publicly serves everything from static sites to forgejo (+the ssh endpoint for git pushes).

Decronym@lemmy.decronym.xyz on 06 Aug 09:00 next collapse

Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

Fewer Letters More Letters
CA (SSL) Certificate Authority
CSAM Child Sexual Abuse Material
DNS Domain Name Service/System
Git Popular version control system, primarily for code
ISP Internet Service Provider
SSD Solid State Drive mass storage
TLS Transport Layer Security, supersedes SSL
VPN Virtual Private Network
VPS Virtual Private Server (opposed to shared hosting)
nginx Popular HTTP server

10 acronyms in this thread; the most compressed thread commented on today has 24 acronyms.

[Thread #74 for this comm, first seen 6th Aug 2026, 09:00] [FAQ] [Full list] [Contact] [Source code]

benoegen@discuss.tchncs.de on 06 Aug 10:55 next collapse

I use traefik combined with crowdsec, there is a plugin for that. There is some pretty good tutorial (in german) on goneuland.de

uuj8za@piefed.social on 06 Aug 12:38 next collapse

Netbird reverse proxy: https://docs.netbird.io/manage/reverse-proxy

It’s like Tailscale, but Open Source. You can self-host the components, if you want. I just use the cloud offering. I have a domain name that resolves to my server. There’s different ways you can do auth. I just hard coded an allow list of IPs. Otherwise, devices in my Netbird network can use the private IP.

Reannlegge@lemmy.ca on 06 Aug 15:59 next collapse

I have a Flint 2 with a vanilla install of openWRT, that hosts wireguard. I have 2 static IPs, because I thought hey running my own mail and smtp services cannot be that hard (turns out yes it is hard and not worth the time to deal). Any who I have Wireguard running on my firewall and Caddy running on one of my pi’s, it gets TLS from lets encrypt.

I have a couple of domains that Caddy uses to point things out to the world or my LAN/vLANs/VPNs. Very few of the things go out to the whole world, but if I wanted to share say a Jellyfin server with someone I could wip up a VPN that only allows Jellyfin through and points DNS to my piholes. Why do I mention my ad blocker? I mention pihole because that what hosts the A records to my domain names that Caddy can serve up, I do not remember why I set it up like this, I would have to look through my notes but pihole points “service”.domain1or2.xyz to caddy which than points to the right service.

Edit: went and looked A records are hosted on pihole for my LAN/vLANs/VPNs to prevent things needing to go out and come back just to tell devices where on my LAN services are.

MangoPenguin@piefed.social on 06 Aug 17:56 next collapse

Just a reverse proxy, I was using Caddy, moved to Pangolin because it’s neat.

galacticworm@piefed.social on 06 Aug 19:38 next collapse

If you have a UniFi gateway, you can enable region based firewall on your port forward ip. This then blocks most of the world (incoming) as a first step. Then like others suggest, a reverse proxy. I use Caddy built with the Maxmind geolocation plugin, and I also run fail2ban on my exposed service.

I figure if you don’t need most of the world accessing your services, it is best to exclude them

TrippinMallard@lemmy.ml on 06 Aug 21:30 next collapse

Netbird has a reverseproxy that’s super easy to setup to point to one of your netbird nodes.

ArborNode@lemmy.shutes.org on 06 Aug 21:39 next collapse

For those of us behind double NAT (CGNAT) forwarding ports is not an option as we do not control forwarding on the second gateway. This will limit you to any of the solutions that include a device outside your network with a public port that tunnels traffic into your server.

matron1049@lemmy.dbzer0.com on 07 Aug 18:37 collapse

I’m not behind CGNAT/double NAT but I’m curious, can you use IPv6 to bypass that?

ArborNode@lemmy.shutes.org on 07 Aug 20:25 collapse

To some degree yes. I ran an experiment to see and found there is just too much of the existing internet infrastructure not implementing IPV6 for this to be reliable. For instance, you can’t use it for email intake because only 2 major players do IPV6.

You still get dynamic assignments from the ISP and have to automate keeping your AAAA records up to date.

The short answer is, it depends. For what OP is doing here, I expect it would work.

If anyone else has messed with this, I’d love to here about it. Might be good as it’s own post.

DrunkAnRoot@sh.itjust.works on 06 Aug 22:50 next collapse

I personally use a vps for this stuff but my setup is standalone nginx as a reverse proxy and fail2ban and ufw

The_Zen_Cow_Says_Mu@infosec.pub on 07 Aug 17:48 next collapse

You may also want to consider a hardened single sign-on solution, as that can enable 2FA for all your services, even those that don’t have them built-in. I use Authentik.

Dirtboy@lemmy.world on 07 Aug 19:24 next collapse

I bought myself a Synology disk station and a domain.

Yes I use Cloudflare for DNS so I can get a wildcard domain cert using ACME.

I use the Synology supplied login portal as a web application firewall for every site I want to host with the wildcard SSL cert. Like bar.mydomain.com, mealie.mydomain.com, etc.

The Synology routes the traffic to the services hosted on other services within my network.

Anything else I don’t want open to the public web, I use the Synology supplied OpenVPN server to connect.

pineapplelover@lemmy.dbzer0.com on 08 Aug 04:59 collapse

I also have a synology but my old gaming laptop does video transcoding better so I have it on debian right now and am figuring out the best set up to access it and self host services to access publicly

kossa@feddit.org on 14 Aug 08:33 collapse

What I do: VPS with reverse proxy and ssh reverse tunnels from the homelab.

OG would be to understand IPv6 and use that directly. Depending on the services you plan to expose that could be a good way. Tried it some years ago, was hit and miss and I still don’t get my head around how v6 work…but that would be the most independent, standalone way.