Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
view the rest of the comments
They won’t do that because it’s expensive and free software generally doesn’t have the budget to do this
I don’t know why you think the “just works” is any different from tunneling with a service. Your server is still opened to the internet through upnp with direct connections and through a tunnel to plex.tv when a direct connection is not possible. In fact plex is inherently less secure because their infra is both the encryption endpoint (as opposed to your client with Jellyfin and Tailscale or whatever) and their infra has been vulnerable in the past (like the massive breach in 2022).
Jellyfin with something like nginx and a vpn is open to the internet, yes, but a service that tunnels (like wireguard, Tailscale) bypasses this issue and it’s up to you to set it up as to your level of comfort
Plex is just easier but as with all things tech (especially those infected with VC dollars) “ease” translates to less secure and far more likely to exploit your data
I came up with a funny strategy I use to lock it down a bit. What's exposed to the internet for me is Apache2 reverse proxy. The proxy is locked down to reject all connections EXCEPT for the ones coming from a special subdomain which is something like a 64-character long random string. This prevents pretty any unwanted connections. Obviously the special subdomain must remain as secret as a shared password among the Jellyfin users. It works for trusted users.
What I want ideally is an "authenticated firewall." OpenWrt rejecting all connections on the open port except for an allowlist of IPs. Then there must be a system where users can authenticate and their IP is added to the allowlist. I haven't found an off-the-shelf solution like this but I'll make it some day. Too bad I figured this random string subdomain trick cause it seems good enough for now. :D
A semi-automated whitelist solution would be nice. I've settled for Crowdsec with very strict automatic banning behavior.
How is your DNS set up for that subdomain? Is it on a wildcard DNS record?
Do you mean the SSL cert? Yes, that's wildcard on *.mydomain.com. Then the subdomain is kvtn4ftxfreurdcw7qtr21mcywxaqqm.mydomain.com.
In this case I mean the DNS entry for the random string. The thing pointing that subdomain at your IP/proxy.
It's just an A record pointing to my IP. IP's updated from my router via the DNS provider API.
If that A record isn’t a wildcard, anyone can see it, is what I’m getting at.
Hm. As far as I know that can only be done if AXFR is enabled (it's not), if the domain has entered some search engine that has remembered it, or through brute force lookup. Am I missing something?
Give it a look on https://dnsdumpster.com/ or similar. Your dns records are inherently public, so anyone that works out the domain can work out the subdomain. In fact there are plenty of tools that just scan every domain/subdomain they can find.
Thanks for the pointer. Checked, tried a couple others - they don't know about it. They have some other non-random DNS records. AFAIK they can absolutely find it if they scan for all domains, but it'll take forever if the name is randomly-generated and sufficiently long. Someone has to be determined to spend the resources. This doesn't guard against that but against bots trying to fuck with the service at the port. I could move it to a wildcard though. There's an overlap with another subdomain (they're actually sub-subdomains and the first sub is common) but I could move that.