this post was submitted on 30 Dec 2025
28 points (96.7% liked)

Selfhosted

54376 readers
287 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

  7. No low-effort posts. This is subjective and will largely be determined by the community member reports.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I have Pangolin set up as a reverse proxy in my VPS and Cloudflare as a DNS provider with its free tier.

I want to migrate out of Cloudflare for my setup, however I lack the requisite network knowledge to safely transition my VPS and domain to better alternatives and don't know where to start its research from.

There are two features I intend my setup to have after the transition:

  • DDoS protection: I was considering using Crowdsec as there is a guide to incorporate it into Pangolin, but I do not know if it will be sufficient or not. I saw a post earlier listing some alternative DDoS protection solutions, but I am wary of their limited free tier options compared to that of Cloudflare and I don't wish to pay for them as my homelab is mostly going to be used by me and a handful of friends.

  • Wildcard Certificate Generation: My domain provider has a poor DNS service and is not listed under LEGO's supporter DNS providers for enabling wildcard certificate generation and the Cloudflare one does not seem to work for some reason. I don't know of any other compatible DNS provider I could shift to unless it is provided within the other DDoS protection services as mentioned above.

Again, I don't have much knowledge in this field but I'm willing to learn and make an informed decision. Please let me know any suitable alternatives for the above, the pros and cons for the migrations, or some guide on performing such transition from Cloudflare as you seem fit.

you are viewing a single comment's thread
view the rest of the comments
[–] stratself 14 points 1 week ago

For the DNS provider I recommend https://desec.io/. It's a nonprofit running worldwide DNS servers, supports DNSSEC, and has a plugin for Lego. If your registrar supports DNSSEC as well, I'd recommend enabling it to protect from DNS forgery.

For the DDoS protection I don't have a recommendation as they're all "just another SaaS", but maybe you could limit many more selfhosted things behind auth as to not expose more surface to potential scrapers.