Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
view the rest of the comments
With being behind a CGNAT tunnels is your only option.
https://pangolin.net/
What about this? Pangolin is probably fine if they rent a vps.
Pangolin seconded! Been using it for over a year, not a single hiccup. Switched the moment I heard CF does not like media streams via their tunnels.
I think this is a similar approach to Cloudflare tunneling just self hosted. I personally miss reverse proxy with my own domain, but my apartment complex forced an ISP on us that killed that.
I rent a free tier oracle vm that does nothing more than tunnel traffic using GOST. Ports 80/443/25 and a control port that my homelab can connect to to establish the tunnel. No ports open at my house, public IP is the cloud VM, and the raw encrypted tcp traffic is tunneled through whatever NAT shenanigans my ISP might have and straight into Caddy within a docker (podman) network. I'm pretty happy with it and it works well!
It's a single binary and can parse a config file or command line parameters. If I ever switch public VM providers, it's a single binary download and a systemd service file. Switch my DNS records to the new VM and I'm completely done. And since my homelab establishes the connection to the VM's port, I don't have to reconfigure anything if I move buildings, switch providers, get stuck behind NAT, or can't open ports.
Oh to be as smart as you.
it literally is self hosting cloudflare tunnels :)
I would like to avoid paying for a VPS. I probably should have clarified in my post too that I am specifically looking for advise on securing public facing services. While I certainly could make everyone use a tailscale-like service, at this point I think securing an external service would be easier. Especially since most of these people would not be tech savvy and I don’t particularly want to play tech support for their VPN.
That's what pangolin is. Your users don't need to use anything special. The VPN is used internally to connect your server and the VPS. It's not actually public facing. For the enduser it's the same as if you used cloudflare tunnels.
One word of warning if you choose to go with Cloudflare: Using their tunnels for streaming video is technically against their TOS. It's not really enforced most of the time, but you might run into problems, if you plan on really high usage.
An alternative service is Netbird. Open Source, based in Germany and as far as I know they don't have this limitation
EDIT no wait, this post is about secure, not hosting/tunneling in general. This comment is off topic ig.
Oracle cloud free tier, but it does have a history of randomly killing the VPS's created.
Public ipv4 addresses are scarce, and becoming more expensive now. You are probably going to have to shell out some cash if you don't already get one as part of your internet plan.
ngrok allows up to 1 gigabyte out. it is not a good deal compared to cloudflare tunnels. the vps with pangolin is the best option on the table if I'm going to be honest