this post was submitted on 20 Sep 2026
12 points (100.0% liked)
Self Hosted - Self-hosting your services.
21095 readers
44 users here now
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules
- No harassment
- crossposts from c/Open Source & c/docker & related may be allowed, depending on context
- Video Promoting is allowed if is within the topic.
- No spamming.
- Stay friendly.
- Follow the lemmy.ml instance rules.
- Tag your post. (Read under)
Important
- Lemmy doesn't have tags yet, so mark it with [Question], [Help], [Project], [Other], [Promoting] or other you may think is appropriate. This is strongly encouraged!
Cross-posting
- !everything_git@lemmy.ml is allowed!
- !docker@lemmy.ml is allowed!
- !portainer@lemmy.ml is allowed!
- !fediverse@lemmy.ml is allowed if topic has to do with selfhosting.
- !selfhosted@lemmy.ml is allowed!
If you see a rule-breaker please DM the mods!
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Depending on how you set it up.
Normally, you run the reverse proxy on the same machine as your NextCloud.
The job of the reverse proxy is do TLS termination, ie. encrypt your communications. It can also do other things - like virtual hosts (self-host your NextCloud and .. er, whatever else like Standard Notes on the same machine, distinguish them by FQDN: https://cloud.sem.com/ vs https://notes.sem.com/).
On the topic of transferring 500GB files to your self-hosted storage - it really depends on where you connect from. Home WiFi? It'll take the direct path, and likely be faster. Home, but on the mobile network? You'll make a hop through the nearest cell tower, inflating your internet usage. A VPS, however, is not in this picture at all.
Now, could you add a VPS? Sure, but you'd need to have a specific reason/goal in mind. Your residential IP address is already exposed to the internet (evidently, as you're posting here). Instead of a VPS-as-a-reverse-proxy, set up a Wireguard split tunnel with https://github.com/wgtunnel/android if you want your whole deployment be hidden/private.
The security aspect I've heard is that knowing your IP is one thing, but the more services you have running on your IP the more security holes there are likely to be. That was the idea for having public dns point to a VPS for nextcloud, so it is still reachable by the public, but not exposing the home network to any holes nextcloud may have.
But I'm not sure that is a great solutiin either.
Nextcloud probably has security holes :) but then use Wireguard to hide it from the interwebs. TLS termination should still be done in localhost.