this post was submitted on 06 Aug 2026
79 points (97.6% liked)

Selfhosted

61454 readers
547 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

I want to expose my services publicly on my own domain name, how would you guys do that?

I have seen people using Cloudflare, but I don't want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I've done some rough researching.

What do you guys do?

top 50 comments
sorted by: hot top controversial new old
[–] kossa@feddit.org 1 points 2 days ago

What I do: VPS with reverse proxy and ssh reverse tunnels from the homelab.

OG would be to understand IPv6 and use that directly. Depending on the services you plan to expose that could be a good way. Tried it some years ago, was hit and miss and I still don't get my head around how v6 work...but that would be the most independent, standalone way.

[–] spork@pawb.social 33 points 1 week ago* (last edited 1 week ago) (3 children)

I rent a cheap VPS with iptables routing ports through a wireguard tunnel to a peer on the local network that acts as a firewall and reverse proxy, this gives you a static IP with a local control plane and no ddns.

[–] pineapplelover@lemmy.dbzer0.com 9 points 1 week ago (5 children)

What's a cheap vps you recommend?

I use a cheap racknerd vps via low end box. $12/yr.

[–] pineapplelover@lemmy.dbzer0.com 6 points 1 week ago (2 children)

That's crazy cheap price. Does it really have enough bandwidth to stream jellyfin?

[–] MangoPenguin@piefed.social 4 points 1 week ago (10 children)

Most VPS are on 1Gbps connections, but even if it only has 100Mbps that's plenty.

load more comments (10 replies)

Yes. (Depending on load) I run a server with 10 users, probably 2-3 active at any given time. Works fine.

[–] spork@pawb.social 9 points 1 week ago (1 children)

I hop around a lot. I’ve used Akamai (fka linode), Vultr, DigitalOcean, AWS EC2, and GCP Compute Engine. I wouldn’t recommend the last 2 anymore because fuck big tech. A lot of people will mention Oracle’s free tier, but I don’t trust anyone that looks like Larry Ellison to own a machine with a direct connection into my local network.

I resonate with you as well, so what kind of set up do you use now?

[–] TheRedSpade@lemmy.world 4 points 1 week ago (1 children)

Linode has a $5/month option.

[–] Andres4NY@social.ridetrans.it 10 points 1 week ago

@TheRedSpade @pineapplelover Linode got acquired by Akamai and their service (or at least, *my* VPS) has really gone downhill over the past few years.

Oracle has a free tier where I run my Wireguard.

load more comments (1 replies)
[–] HelloRoot@lemy.lol 5 points 1 week ago* (last edited 1 week ago) (1 children)

Same but nftables and also crowdsec.

Also I had some trouble with the wireguard tunnel dropping lots of packets, which resulted in my services not loading 50% of the time. I did a lot of suggestions at the same time so I'm not sure which one fixed it but here is a list in case anybody has similar troubles:

  • lowering MTU
  • routing ipv6 through the tunnel as well
  • rewriting nftables rule order
  • ...

(will update after work, notes are at home)

[–] hirihit640@sh.itjust.works 2 points 2 days ago (1 children)

I'm running into similar issues, do you mind expanding on your solutions?

[–] HelloRoot@lemy.lol 1 points 2 days ago* (last edited 2 days ago)

I'm still having trouble with it and I'm currently traveling. My analysis so far points to my vps provider being at fault.

I tried doing long term diagnostics, which effectively pinged through the tunnel every 5s and that make it work constantly and perfectly. So maybe some energy saving sleep stuff, which ends up breaking the tunnel?

[–] halcyoncmdr@piefed.social 4 points 1 week ago* (last edited 1 week ago) (2 children)

Similar here. Just a Digital Ocean droplet running Pangolin. Functions basically the same as the cloudflare tunnel it replaced.

Can expose the service directly if needed, or from behind a login page.

load more comments (2 replies)
[–] fozid@lem.radiantfig.fyi 24 points 1 week ago* (last edited 1 week ago) (1 children)

A reverse proxy is the traditional safe route. Use a web server like Apache, nginx or caddy, and setup to reverse proxy all your services through port 443, and use let's encrypt and certbot to generate and manage TLS certificates.

I host around 15 public facing web services this way using nginx.

Just be aware, this is very public facing so server security and hardening is important. Things like strong passwords, disabled root, use ssh keys instead of passwords, setup fail2ban, setup crowdsec etc.

The more modern safer way is not to truly expose to full public and use things like tailscale or cloudflare tunnels. But this relies on 3rd party servers and I'm not a fan of that, but it does bring benefits.

[–] lyralycan@sh.itjust.works 3 points 1 week ago* (last edited 1 week ago) (2 children)

A lot of folk decry Cloudflare as a terrible corp (and their AI push now involves the login page shunted to the side while 70% of the screen is a relatively blank section with some sentence about using their AI), but what is the non-3rd party alternative? Does one rely on sharing the IP instead? It is impossible to have public (non-family) traffic without a Cloudflare/Google DNS resolver right?

Being on a standard ISP I cannot use a higher-level rDNS.

[–] fozid@lem.radiantfig.fyi 6 points 1 week ago

im on a basic uk isp, with no fancy router, just the isp provided one. i have a fully exposed web server, im even hosting a lemmy server. Thats my domain, radiantfig.fyi, totally public, has been for nearly 2 years now. From that you can get my servers IP address. My IP is dynamic, changes roughly every 6 weeks. I have a ddns script that updates my server IP address to my domain name provider automatically. I have certbot running updating my TLS certs with lets encrypt, and if a cert dies or fails or is compromised, my server will refuse to serve. Everything is behind an nginx reverse proxy through port 443. I also have an ssh port open on a random port. Have fail2ban setup fairly aggressively to prevent brute force attacks, and have crowdsec which also kind of does the same but in a slightly different way. the internet requires ip addresses. to protect your ip address you have to give somebody elses. that somebody is a 3rd party you have no control or say on the decisions they make. i must have over 20 individual services that are public facing. 3 fully federated, lemmy, forgejo and matrix. Im as secure as any other website. nothing is unhackable, no matter how far down the rabbit hole you go. its all just layers of difficulty.

The important thing is dont listen to random internet people about security. dont listen to me. dont listen to anybody who tells you they know best. do your own research, understand the options, the risks, the compromises. only then do you put anything up. but if you are going to anxious or worried about your server and data, no amount of security guarantees you safety, so be warned.

[–] MangoPenguin@piefed.social 2 points 1 week ago

It costs a little but a VPS running Pangolin and Crowdsec is a decent replacement for cloudflare for hiding your IP and having some extra protection.

[–] myrmidex@belgae.social 9 points 1 week ago* (last edited 1 week ago)

I got off CloudFlare by using Pangolin. Ideal for my use-case, I didn't use any of CF's advanced features, so Pangolin is the ideal replacement for me.

Publicly serves everything from static sites to forgejo (+the ssh endpoint for git pushes).

[–] ISolox@lemmy.world 7 points 1 week ago

Reverse proxy is what you need. I would post instructions here but honestly they wouldnt be that good. Just search it up and follow along.

[–] AllYourSmurf@lemmy.world 6 points 1 week ago (1 children)

Authentication & single sign-on service

Plugged into Reverse proxy, routing to each service by name

With a wild card cert so there are no name leaks.

Make your urls unexpected. If your domain is example.com, don’t put your jellyfin server at jellyfin.example.com. Instead, use watch.example.com or telly.example.com. Anything that’s memorable to you about what the service is without using a specific brand name.

With a wildcard dns record to point all names to your IP, and a wildcard certificate that works for all names loaded on your load balancer, it becomes hard for a hacker to know what name to use to get the load balancer to send them to the service they want to hack.

If you then use a sso tool like traefik’s ForwardAuth middleware, you won’t even get to the service until you’ve first authenticated.

[–] helix@feddit.org 5 points 1 week ago* (last edited 1 week ago) (3 children)

If you use TLS like you should, your domains will be on the internet in the certificate transparency log. Yes, you should use a wildcard cert if you want this security by obscurity, but it's still security by obscurity.

[–] Jason2357@lemmy.ca 2 points 2 hours ago

Security by obscurity is when the design or archetecture of the system is obscure enough to supposedly styme attackers (it doesnt), and as soon as people understand the design, your security is broken.

A hard to guess unpublished subdomain is a transparent and standard archetecture - nothing obscure about it and publishing that you use such a scheme doesnt break the security.

The subdomain is a bearer token that serves as an access control and just like a key or passphrase, has a security value proportional to the bits of information an attacker has to guess.

The real limitation is that browsers and humans are not great at not leaking domain names, so its very possible it will get leaked eventually and hard to rotate. Thats the reason they are weak. Still, they can be usefull to stop scanners just trolling for unpatched services.

[–] AllYourSmurf@lemmy.world 3 points 1 week ago

Of course. The goal here is to not advertise. Make it hard for the bots to find you. With these steps, they can try your IP, but there’s nothing directly on your IP.

You still need proper security. Authentication is a good start, and it has the extra effect of adding an extra layer to prevent the bots from going further if they get lucky and guess a host name.

load more comments (1 replies)
[–] RanchBranch@anarchist.nexus 5 points 1 week ago (1 children)

I recently switched to Netbird on a VPS (on Vultr). Their reverse proxy is super easy to set up / self host. They also offer a free version that works pretty good too, I just wanted to make it difficult for myself (thats the whole point of self hosting, right? )

[–] pineapplelover@lemmy.dbzer0.com 3 points 1 week ago (7 children)

I have seen netbird pop around every now and again. I might try out their cloud free version first and if I like it I might try self hosting it.

So you host netbird on a vps you rent and that is used for reverse proxy? So with that reverse proxy I can have my home server be publicly accessible and I can have friends log in to my jellyfin server without having to connect to my tailnet.

My last concern is security. How is this set up good for making sure I don't just get constantly botted and exploited?

[–] RanchBranch@anarchist.nexus 3 points 1 week ago

Yup! They can either connect to your Netbird meshnet (ie, similar a tailnet) or you can reverse proxy it out to the internet (no tailnet needed)

I saw a couple comments below concerned about security, one of the nice things about Netbird is that they have reverse proxy auth built in if you want. Some stuff (Navidrome or VoidAuth for instance) only has geolocation locked down (US only) but other things that I'm either more concerned about or don't necessarily trust being open (Paperless or Komodo for instance) have Netbird Auth and VoidAuth as sign in options before it will let me open the page. Its worked flawlessly so far, and has kept my sanity intact because I wanted some stuff publically accessible without it being OPEN.

As far as being hammer fucked, it has CrowdSec and Geolocation lockdowns so you can set it to only accept traffic from ONE location and the Crowdsec also catches everything.

[–] innocentzero@kbin.earth 2 points 1 week ago (11 children)

Opening jellyfin up publicly is kind of asking for trouble if you ask me. I haven't done so myself, but seen enough on this community and elsewhere to know that it's probably not a good idea.

load more comments (11 replies)
load more comments (5 replies)
[–] Nibodhika@lemmy.world 5 points 1 week ago

Why do you want to expose them? This might limit the solutions.

The way I do this is in 2 different ways:

  1. Tailscale, my server connects to tailscale so all I have to do is connect to it from my phone and I can access things remotely easily. This is the best for most things, but has the downside that others can't access it as easily

  2. I have a VPS (two actually at the moment as I'm switching providers from Vultr to IONOS) that also connects to tailscale so it can access my home server through it, then using Caddy I expose the services on a subdomain of the VPS. This is what I do for things that others might want to access, or things I don't want to have to connect to tailscale to access.

If you're going down the second route do consider that you will need to:

  • Add something like fail2ban or crowdsec to the VPS as attacks will happen.
  • Same reason you should add a dedicated authentication on front of most things. While I don't expect the auth on services to be weak, it might be more vulnerable than a dedicated authentication service. You should look into Authelia, Authentik, or similar to put on front of your services so any attacker would first have to pass that to even get to your services.
[–] lime@feddit.nu 4 points 1 week ago

i configured dyndns in my router and have it forward all traffic to a gateway vm running nginx and fail2ban. every service is on a subdomain so any attempt to fetch things from the main name gets banned.

[–] uuj8za@piefed.social 4 points 1 week ago

Netbird reverse proxy: https://docs.netbird.io/manage/reverse-proxy

It's like Tailscale, but Open Source. You can self-host the components, if you want. I just use the cloud offering. I have a domain name that resolves to my server. There's different ways you can do auth. I just hard coded an allow list of IPs. Otherwise, devices in my Netbird network can use the private IP.

[–] DrunkAnRoot@sh.itjust.works 3 points 1 week ago

I personally use a vps for this stuff but my setup is standalone nginx as a reverse proxy and fail2ban and ufw

[–] lazylemons@lemmy.today 3 points 1 week ago (3 children)

Recently set up caddy myself, very straightforward setup. You essentially just edit one config file and point your domain host to the right place and are good to go. Took me by surprise actually.

load more comments (3 replies)
[–] WhatsHerBucket@lemmy.world 3 points 1 week ago

My router (gl-net) has a VPN server built in. I just use WireGuard client and freedns.

[–] KarnaSubarna@lemmy.ml 3 points 1 week ago (1 children)

Make it publicly available to the world or just for you (and people you know)?

load more comments (1 replies)
[–] Dirtboy@lemmy.world 2 points 1 week ago (1 children)

I bought myself a Synology disk station and a domain.

Yes I use Cloudflare for DNS so I can get a wildcard domain cert using ACME.

I use the Synology supplied login portal as a web application firewall for every site I want to host with the wildcard SSL cert. Like bar.mydomain.com, mealie.mydomain.com, etc.

The Synology routes the traffic to the services hosted on other services within my network.

Anything else I don’t want open to the public web, I use the Synology supplied OpenVPN server to connect.

load more comments (1 replies)
[–] ArborNode@lemmy.shutes.org 2 points 1 week ago (2 children)

For those of us behind double NAT (CGNAT) forwarding ports is not an option as we do not control forwarding on the second gateway. This will limit you to any of the solutions that include a device outside your network with a public port that tunnels traffic into your server.

load more comments (2 replies)
[–] MangoPenguin@piefed.social 2 points 1 week ago

Just a reverse proxy, I was using Caddy, moved to Pangolin because it's neat.

load more comments
view more: next ›