I want to expose my services publicly on my own domain name, how would you guys do that?

I have seen people using Cloudflare, but I don’t want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I’ve done some rough researching.

What do you guys do?

  • kossa@feddit.org
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 day ago

    What I do: VPS with reverse proxy and ssh reverse tunnels from the homelab.

    OG would be to understand IPv6 and use that directly. Depending on the services you plan to expose that could be a good way. Tried it some years ago, was hit and miss and I still don’t get my head around how v6 work…but that would be the most independent, standalone way.

  • spork@pawb.social
    link
    fedilink
    English
    arrow-up
    28
    ·
    10 days ago

    I rent a cheap VPS with iptables routing ports through a wireguard tunnel to a peer on the local network that acts as a firewall and reverse proxy, this gives you a static IP with a local control plane and no ddns.

            • /home/pineapplelover@lemmy.dbzer0.comOP
              link
              fedilink
              English
              arrow-up
              1
              ·
              8 days ago

              Is there a data cap? I’m concerned like they only allow me to pass through like a TB or so of data passing through it within a month. If you have users watching your jellyfin server every day that can surpass your limit.

              • Taasz/Woof@piefed.social
                link
                fedilink
                English
                arrow-up
                2
                ·
                8 days ago

                Yes generally around 1TB on cheap plans. That’s a ton of data though for streaming media, if youre moving more than that getting a higher tier VPS would make sense.

              • Jason2357@lemmy.ca
                link
                fedilink
                English
                arrow-up
                0
                ·
                8 days ago

                Keep in mind that you wouldn’t route local traffic through it, so everything watched at home would be direct and not count.

                I have a $5/mo VPS with OVH and they allow unlimited bandwidth within reason. Unless you have multiple households streaming from your server all the time, likely totally fine. If you do end up with one relative streaming 24x7, then I would look at installing the tailscale app on their TV and configuring things to connect that one user direct to your home server.

                A VPS takes some learning, but IMHO, it is the “correct” answer and worthile learning.

      • spork@pawb.social
        link
        fedilink
        English
        arrow-up
        9
        ·
        9 days ago

        I hop around a lot. I’ve used Akamai (fka linode), Vultr, DigitalOcean, AWS EC2, and GCP Compute Engine. I wouldn’t recommend the last 2 anymore because fuck big tech. A lot of people will mention Oracle’s free tier, but I don’t trust anyone that looks like Larry Ellison to own a machine with a direct connection into my local network.

      • shadshack@feddit.online
        link
        fedilink
        English
        arrow-up
        2
        ·
        9 days ago

        Look into Oracle cloud’s Always Free tier of cloud instances. I have a few of those and they’re decent for free.

    • halcyoncmdr@piefed.social
      link
      fedilink
      English
      arrow-up
      4
      ·
      9 days ago

      Similar here. Just a Digital Ocean droplet running Pangolin. Functions basically the same as the cloudflare tunnel it replaced.

      Can expose the service directly if needed, or from behind a login page.

        • halcyoncmdr@piefed.social
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 days ago

          Pangolin officially says on their site :

          Pangolin generally requires minimal resources to run effectively. A basic VPS with 1 vCPU, 2GB RAM, and 8GB SSD is sufficient for most deployments.

          If you choose a VPS with only 1GB RAM, you may need to create swap space to avoid memory pressure during installation, updates, or periods of higher traffic.

          I’ve got a 1 vCPU, 1GB RAM, 25GB Disk droplet for $6/mo and have no issues for my limited home use. Updates don’t really take a noticeably long time or anything, it takes maybe 45 seconds to fully bring up the docker container again after an update. But it runs just fine.

  • ISolox@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    10 days ago

    Reverse proxy is what you need. I would post instructions here but honestly they wouldnt be that good. Just search it up and follow along.

  • myrmidex@belgae.social
    link
    fedilink
    English
    arrow-up
    9
    ·
    10 days ago

    I got off CloudFlare by using Pangolin. Ideal for my use-case, I didn’t use any of CF’s advanced features, so Pangolin is the ideal replacement for me.

    Publicly serves everything from static sites to forgejo (+the ssh endpoint for git pushes).

  • AllYourSmurf@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    10 days ago

    Authentication & single sign-on service

    Plugged into Reverse proxy, routing to each service by name

    With a wild card cert so there are no name leaks.

    Make your urls unexpected. If your domain is example.com, don’t put your jellyfin server at jellyfin.example.com. Instead, use watch.example.com or telly.example.com. Anything that’s memorable to you about what the service is without using a specific brand name.

    With a wildcard dns record to point all names to your IP, and a wildcard certificate that works for all names loaded on your load balancer, it becomes hard for a hacker to know what name to use to get the load balancer to send them to the service they want to hack.

    If you then use a sso tool like traefik’s ForwardAuth middleware, you won’t even get to the service until you’ve first authenticated.

    • Helix 🧬@feddit.org
      link
      fedilink
      English
      arrow-up
      5
      ·
      10 days ago

      If you use TLS like you should, your domains will be on the internet in the certificate transparency log. Yes, you should use a wildcard cert if you want this security by obscurity, but it’s still security by obscurity.

      • AllYourSmurf@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        9 days ago

        Of course. The goal here is to not advertise. Make it hard for the bots to find you. With these steps, they can try your IP, but there’s nothing directly on your IP.

        You still need proper security. Authentication is a good start, and it has the extra effect of adding an extra layer to prevent the bots from going further if they get lucky and guess a host name.

      • frongt@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        ·
        9 days ago

        Or run an internal CA, if you’re the only one accessing the services.

  • Nibodhika@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    10 days ago

    Why do you want to expose them? This might limit the solutions.

    The way I do this is in 2 different ways:

    1. Tailscale, my server connects to tailscale so all I have to do is connect to it from my phone and I can access things remotely easily. This is the best for most things, but has the downside that others can’t access it as easily

    2. I have a VPS (two actually at the moment as I’m switching providers from Vultr to IONOS) that also connects to tailscale so it can access my home server through it, then using Caddy I expose the services on a subdomain of the VPS. This is what I do for things that others might want to access, or things I don’t want to have to connect to tailscale to access.

    If you’re going down the second route do consider that you will need to:

    • Add something like fail2ban or crowdsec to the VPS as attacks will happen.
    • Same reason you should add a dedicated authentication on front of most things. While I don’t expect the auth on services to be weak, it might be more vulnerable than a dedicated authentication service. You should look into Authelia, Authentik, or similar to put on front of your services so any attacker would first have to pass that to even get to your services.
  • uuj8za@piefed.social
    link
    fedilink
    English
    arrow-up
    3
    ·
    9 days ago

    Netbird reverse proxy: https://docs.netbird.io/manage/reverse-proxy

    It’s like Tailscale, but Open Source. You can self-host the components, if you want. I just use the cloud offering. I have a domain name that resolves to my server. There’s different ways you can do auth. I just hard coded an allow list of IPs. Otherwise, devices in my Netbird network can use the private IP.

  • lime!@feddit.nu
    link
    fedilink
    English
    arrow-up
    2
    ·
    10 days ago

    i configured dyndns in my router and have it forward all traffic to a gateway vm running nginx and fail2ban. every service is on a subdomain so any attempt to fetch things from the main name gets banned.

  • Dirtboy@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    8 days ago

    I bought myself a Synology disk station and a domain.

    Yes I use Cloudflare for DNS so I can get a wildcard domain cert using ACME.

    I use the Synology supplied login portal as a web application firewall for every site I want to host with the wildcard SSL cert. Like bar.mydomain.com, mealie.mydomain.com, etc.

    The Synology routes the traffic to the services hosted on other services within my network.

    Anything else I don’t want open to the public web, I use the Synology supplied OpenVPN server to connect.

    • /home/pineapplelover@lemmy.dbzer0.comOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      8 days ago

      I also have a synology but my old gaming laptop does video transcoding better so I have it on debian right now and am figuring out the best set up to access it and self host services to access publicly

  • Karna@lemmy.ml
    link
    fedilink
    English
    arrow-up
    2
    ·
    10 days ago

    Make it publicly available to the world or just for you (and people you know)?

    • /home/pineapplelover@lemmy.dbzer0.comOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      9 days ago

      Publicly to the world. For example, I wanted to self host temporary file sharing and temporary link shortener to the world. Stuff like jellyfin I would have that public but only specific users would have the credentials to log in.

  • galacticworm@piefed.social
    link
    fedilink
    English
    arrow-up
    2
    ·
    9 days ago

    If you have a UniFi gateway, you can enable region based firewall on your port forward ip. This then blocks most of the world (incoming) as a first step. Then like others suggest, a reverse proxy. I use Caddy built with the Maxmind geolocation plugin, and I also run fail2ban on my exposed service.

    I figure if you don’t need most of the world accessing your services, it is best to exclude them

  • lazylemons@lemmy.today
    link
    fedilink
    English
    arrow-up
    2
    ·
    10 days ago

    Recently set up caddy myself, very straightforward setup. You essentially just edit one config file and point your domain host to the right place and are good to go. Took me by surprise actually.

    • /home/pineapplelover@lemmy.dbzer0.comOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      10 days ago

      Yeah but my main concern is security. If I publicly have services like jellyfin or something then I would think I would have constant exploits and bot attacks

      • frongt@lemmy.zip
        link
        fedilink
        English
        arrow-up
        4
        ·
        10 days ago

        You will.

        Anything you expose should be designed for it (e.g. not jellyfin). You should have a WAF configured for the type of service you’re hosting. You can’t just drop one and have it magically protect you, they take configuration. Same with fail2ban.

        And you should have these services in a DMZ, so that a compromise in one doesn’t provide an entry point to other resources on your network.

      • lazylemons@lemmy.today
        link
        fedilink
        English
        arrow-up
        1
        ·
        9 days ago

        Oh for sure. I would only do so if you have a proper firewall running, a DMZ set up. Among other precautions.