this post was submitted on 06 Aug 2026
63 points (100.0% liked)

Selfhosted

62187 readers
636 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

I want to expose my services publicly on my own domain name, how would you guys do that?

I have seen people using Cloudflare, but I don't want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I've done some rough researching.

What do you guys do?

you are viewing a single comment's thread
view the rest of the comments
[–] spork@pawb.social 15 points 1 month ago* (last edited 1 month ago) (3 children)

I rent a cheap VPS with iptables routing ports through a wireguard tunnel to a peer on the local network that acts as a firewall and reverse proxy, this gives you a static IP with a local control plane and no ddns.

[–] pineapplelover@lemmy.dbzer0.com 6 points 1 month ago (5 children)

What's a cheap vps you recommend?

I use a cheap racknerd vps via low end box. $12/yr.

[–] pineapplelover@lemmy.dbzer0.com 5 points 1 month ago (2 children)

That's crazy cheap price. Does it really have enough bandwidth to stream jellyfin?

[–] MangoPenguin@piefed.social 4 points 1 month ago (1 children)

Most VPS are on 1Gbps connections, but even if it only has 100Mbps that's plenty.

[–] pineapplelover@lemmy.dbzer0.com 1 points 1 month ago (2 children)

Is there a data cap? I'm concerned like they only allow me to pass through like a TB or so of data passing through it within a month. If you have users watching your jellyfin server every day that can surpass your limit.

[–] MangoPenguin@piefed.social 1 points 1 month ago

Yes generally around 1TB on cheap plans. That's a ton of data though for streaming media, if youre moving more than that getting a higher tier VPS would make sense.

[–] Jason2357@lemmy.ca 0 points 1 month ago (1 children)

Keep in mind that you wouldn't route local traffic through it, so everything watched at home would be direct and not count.

I have a $5/mo VPS with OVH and they allow unlimited bandwidth within reason. Unless you have multiple households streaming from your server all the time, likely totally fine. If you do end up with one relative streaming 24x7, then I would look at installing the tailscale app on their TV and configuring things to connect that one user direct to your home server.

A VPS takes some learning, but IMHO, it is the "correct" answer and worthile learning.

[–] pineapplelover@lemmy.dbzer0.com 0 points 1 month ago (1 children)

How do you set up security on your server with the constant attacks that come with having the server public?

[–] Jason2357@lemmy.ca 1 points 1 month ago (1 children)

There are constant scanners on any site and scrapers on websites, but it is far less of a problem than you would imagine unless you have a big wiki or software forge with hundreds of nested commit history pages for them to spider into.

I also run private servers on hidden subdomains (with wildcard certs and DNS entries), so the low effort scanners never bother them.

DDOS attacks take money, so they aren't typically going to go after some random homelabber. If it did happen, I would either just shut it off for a while or change the VPs IP. Ovh also has some of its own ddos protection.

[–] pineapplelover@lemmy.dbzer0.com 1 points 1 month ago (1 children)

That sounds perfect, I might go with ovh, how do you like them? The $4.54/mo plan looks cool

[–] Jason2357@lemmy.ca 1 points 1 month ago (1 children)

Their admin interface is slow and awkward, but otherwise happy. Their deals are always changing and I currently have good specs for the money. EU company and my machine is in Montreal, so I was happy with non-American hosting and green electricity.

[–] pineapplelover@lemmy.dbzer0.com 0 points 1 month ago (1 children)

Epic. You probably don't use the admin interface too much right? Probably just configure your reverse proxy a leave it. Gonna rent a vps here in the states.

[–] Jason2357@lemmy.ca 2 points 1 month ago (1 children)

Indeed, I log in pretty rarely.

[–] pineapplelover@lemmy.dbzer0.com 1 points 1 month ago

I keep thinking to myself whether $5/mo or buying a firewall and attempting to achieve the same thing is a better idea

Yes. (Depending on load) I run a server with 10 users, probably 2-3 active at any given time. Works fine.

[–] spork@pawb.social 5 points 1 month ago (1 children)

I hop around a lot. I’ve used Akamai (fka linode), Vultr, DigitalOcean, AWS EC2, and GCP Compute Engine. I wouldn’t recommend the last 2 anymore because fuck big tech. A lot of people will mention Oracle’s free tier, but I don’t trust anyone that looks like Larry Ellison to own a machine with a direct connection into my local network.

[–] pineapplelover@lemmy.dbzer0.com 1 points 1 month ago

I resonate with you as well, so what kind of set up do you use now?

Oracle has a free tier where I run my Wireguard.

[–] TheRedSpade@lemmy.world 3 points 1 month ago (1 children)

Linode has a $5/month option.

[–] Andres4NY@social.ridetrans.it 5 points 1 month ago

@TheRedSpade @pineapplelover Linode got acquired by Akamai and their service (or at least, *my* VPS) has really gone downhill over the past few years.

[–] shadshack@feddit.online 0 points 1 month ago

Look into Oracle cloud's Always Free tier of cloud instances. I have a few of those and they're decent for free.

[–] halcyoncmdr@piefed.social 3 points 1 month ago* (last edited 1 month ago)

Similar here. Just a Digital Ocean droplet running Pangolin. Functions basically the same as the cloudflare tunnel it replaced.

Can expose the service directly if needed, or from behind a login page.

[–] HelloRoot@lemy.lol 1 points 1 month ago* (last edited 1 month ago) (1 children)

Same but nftables and also crowdsec.

Also I had some trouble with the wireguard tunnel dropping lots of packets, which resulted in my services not loading 50% of the time. I did a lot of suggestions at the same time so I'm not sure which one fixed it but here is a list in case anybody has similar troubles:

  • lowering MTU
  • routing ipv6 through the tunnel as well
  • rewriting nftables rule order
  • ...

(will update after work, notes are at home)

[–] hirihit640@sh.itjust.works 0 points 1 month ago (1 children)

I'm running into similar issues, do you mind expanding on your solutions?

[–] HelloRoot@lemy.lol 1 points 1 month ago* (last edited 1 month ago)

I'm still having trouble with it and I'm currently traveling. My analysis so far points to my vps provider being at fault.

I tried doing long term diagnostics, which effectively pinged through the tunnel every 5s and that make it work constantly and perfectly. So maybe some energy saving sleep stuff, which ends up breaking the tunnel?