I want to expose my services publicly on my own domain name, how would you guys do that?

I have seen people using Cloudflare, but I don’t want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I’ve done some rough researching.

What do you guys do?

  • kossa@feddit.org
    link
    fedilink
    English
    arrow-up
    1
    ·
    16 days ago

    What I do: VPS with reverse proxy and ssh reverse tunnels from the homelab.

    OG would be to understand IPv6 and use that directly. Depending on the services you plan to expose that could be a good way. Tried it some years ago, was hit and miss and I still don’t get my head around how v6 work…but that would be the most independent, standalone way.

  • fozid@lem.radiantfig.fyi
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    24 days ago

    A reverse proxy is the traditional safe route. Use a web server like Apache, nginx or caddy, and setup to reverse proxy all your services through port 443, and use let’s encrypt and certbot to generate and manage TLS certificates.

    I host around 15 public facing web services this way using nginx.

    Just be aware, this is very public facing so server security and hardening is important. Things like strong passwords, disabled root, use ssh keys instead of passwords, setup fail2ban, setup crowdsec etc.

    The more modern safer way is not to truly expose to full public and use things like tailscale or cloudflare tunnels. But this relies on 3rd party servers and I’m not a fan of that, but it does bring benefits.

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    13 days ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    CA (SSL) Certificate Authority
    CSAM Child Sexual Abuse Material
    DNS Domain Name Service/System
    Git Popular version control system, primarily for code
    ISP Internet Service Provider
    SSD Solid State Drive mass storage
    TLS Transport Layer Security, supersedes SSL
    VPN Virtual Private Network
    VPS Virtual Private Server (opposed to shared hosting)
    nginx Popular HTTP server

    10 acronyms in this thread; the most compressed thread commented on today has 24 acronyms.

    [Thread #74 for this comm, first seen 6th Aug 2026, 09:00] [FAQ] [Full list] [Contact] [Source code]

  • spork@pawb.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    24 days ago

    I rent a cheap VPS with iptables routing ports through a wireguard tunnel to a peer on the local network that acts as a firewall and reverse proxy, this gives you a static IP with a local control plane and no ddns.

    • halcyoncmdr@piefed.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      24 days ago

      Similar here. Just a Digital Ocean droplet running Pangolin. Functions basically the same as the cloudflare tunnel it replaced.

      Can expose the service directly if needed, or from behind a login page.

        • halcyoncmdr@piefed.social
          link
          fedilink
          English
          arrow-up
          1
          ·
          19 days ago

          Pangolin officially says on their site :

          Pangolin generally requires minimal resources to run effectively. A basic VPS with 1 vCPU, 2GB RAM, and 8GB SSD is sufficient for most deployments.

          If you choose a VPS with only 1GB RAM, you may need to create swap space to avoid memory pressure during installation, updates, or periods of higher traffic.

          I’ve got a 1 vCPU, 1GB RAM, 25GB Disk droplet for $6/mo and have no issues for my limited home use. Updates don’t really take a noticeably long time or anything, it takes maybe 45 seconds to fully bring up the docker container again after an update. But it runs just fine.

    • HelloRoot@lemy.lol
      link
      fedilink
      English
      arrow-up
      0
      ·
      24 days ago

      Same but nftables and also crowdsec.

      Also I had some trouble with the wireguard tunnel dropping lots of packets, which resulted in my services not loading 50% of the time. I did a lot of suggestions at the same time so I’m not sure which one fixed it but here is a list in case anybody has similar troubles:

      • lowering MTU
      • routing ipv6 through the tunnel as well
      • rewriting nftables rule order

      (will update after work, notes are at home)

        • HelloRoot@lemy.lol
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          16 days ago

          I’m still having trouble with it and I’m currently traveling. My analysis so far points to my vps provider being at fault.

          I tried doing long term diagnostics, which effectively pinged through the tunnel every 5s and that make it work constantly and perfectly. So maybe some energy saving sleep stuff, which ends up breaking the tunnel?

      • spork@pawb.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        24 days ago

        I hop around a lot. I’ve used Akamai (fka linode), Vultr, DigitalOcean, AWS EC2, and GCP Compute Engine. I wouldn’t recommend the last 2 anymore because fuck big tech. A lot of people will mention Oracle’s free tier, but I don’t trust anyone that looks like Larry Ellison to own a machine with a direct connection into my local network.

            • /home/pineapplelover@lemmy.dbzer0.comOP
              link
              fedilink
              English
              arrow-up
              0
              ·
              23 days ago

              Is there a data cap? I’m concerned like they only allow me to pass through like a TB or so of data passing through it within a month. If you have users watching your jellyfin server every day that can surpass your limit.

              • Taasz/Woof@piefed.social
                link
                fedilink
                English
                arrow-up
                1
                ·
                23 days ago

                Yes generally around 1TB on cheap plans. That’s a ton of data though for streaming media, if youre moving more than that getting a higher tier VPS would make sense.

              • Jason2357@lemmy.ca
                link
                fedilink
                English
                arrow-up
                0
                ·
                22 days ago

                Keep in mind that you wouldn’t route local traffic through it, so everything watched at home would be direct and not count.

                I have a $5/mo VPS with OVH and they allow unlimited bandwidth within reason. Unless you have multiple households streaming from your server all the time, likely totally fine. If you do end up with one relative streaming 24x7, then I would look at installing the tailscale app on their TV and configuring things to connect that one user direct to your home server.

                A VPS takes some learning, but IMHO, it is the “correct” answer and worthile learning.

  • AllYourSmurf@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    24 days ago

    Authentication & single sign-on service

    Plugged into Reverse proxy, routing to each service by name

    With a wild card cert so there are no name leaks.

    Make your urls unexpected. If your domain is example.com, don’t put your jellyfin server at jellyfin.example.com. Instead, use watch.example.com or telly.example.com. Anything that’s memorable to you about what the service is without using a specific brand name.

    With a wildcard dns record to point all names to your IP, and a wildcard certificate that works for all names loaded on your load balancer, it becomes hard for a hacker to know what name to use to get the load balancer to send them to the service they want to hack.

    If you then use a sso tool like traefik’s ForwardAuth middleware, you won’t even get to the service until you’ve first authenticated.

    • Helix 🧬@feddit.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      24 days ago

      If you use TLS like you should, your domains will be on the internet in the certificate transparency log. Yes, you should use a wildcard cert if you want this security by obscurity, but it’s still security by obscurity.

      • Jason2357@lemmy.ca
        link
        fedilink
        English
        arrow-up
        2
        ·
        13 days ago

        Security by obscurity is when the design or archetecture of the system is obscure enough to supposedly styme attackers (it doesnt), and as soon as people understand the design, your security is broken.

        A hard to guess unpublished subdomain is a transparent and standard archetecture - nothing obscure about it and publishing that you use such a scheme doesnt break the security.

        The subdomain is a bearer token that serves as an access control and just like a key or passphrase, has a security value proportional to the bits of information an attacker has to guess.

        The real limitation is that browsers and humans are not great at not leaking domain names, so its very possible it will get leaked eventually and hard to rotate. Thats the reason they are weak. Still, they can be usefull to stop scanners just trolling for unpatched services.