this post was submitted on 06 Aug 2026
27 points (100.0% liked)

Selfhosted

61207 readers
300 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

I want to expose my services publicly on my own domain name, how would you guys do that?

I have seen people using Cloudflare, but I don't want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I've done some rough researching.

What do you guys do?

top 30 comments
sorted by: hot top controversial new old
[–] benoegen@discuss.tchncs.de 1 points 1 hour ago

I use traefik combined with crowdsec, there is a plugin for that. There is some pretty good tutorial (in german) on goneuland.de

[–] fozid@lem.radiantfig.fyi 8 points 5 hours ago* (last edited 5 hours ago)

A reverse proxy is the traditional safe route. Use a web server like Apache, nginx or caddy, and setup to reverse proxy all your services through port 443, and use let's encrypt and certbot to generate and manage TLS certificates.

I host around 15 public facing web services this way using nginx.

Just be aware, this is very public facing so server security and hardening is important. Things like strong passwords, disabled root, use ssh keys instead of passwords, setup fail2ban, setup crowdsec etc.

The more modern safer way is not to truly expose to full public and use things like tailscale or cloudflare tunnels. But this relies on 3rd party servers and I'm not a fan of that, but it does bring benefits.

[–] myrmidex@belgae.social 3 points 4 hours ago* (last edited 4 hours ago)

I got off CloudFlare by using Pangolin. Ideal for my use-case, I didn't use any of CF's advanced features, so Pangolin is the ideal replacement for me.

Publicly serves everything from static sites to forgejo (+git).

[–] Decronym@lemmy.decronym.xyz 0 points 3 hours ago* (last edited 1 hour ago)

Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:

Fewer Letters More Letters
DNS Domain Name Service/System
Git Popular version control system, primarily for code
TLS Transport Layer Security, supersedes SSL
VPN Virtual Private Network
VPS Virtual Private Server (opposed to shared hosting)
nginx Popular HTTP server

6 acronyms in this thread; the most compressed thread commented on today has 13 acronyms.

[Thread #74 for this comm, first seen 6th Aug 2026, 09:00] [FAQ] [Full list] [Contact] [Source code]

[–] spork@pawb.social 7 points 8 hours ago* (last edited 8 hours ago) (3 children)

I rent a cheap VPS with iptables routing ports through a wireguard tunnel to a peer on the local network that acts as a firewall and reverse proxy, this gives you a static IP with a local control plane and no ddns.

[–] halcyoncmdr@piefed.social 1 points 1 hour ago* (last edited 1 hour ago)

Similar here. Just a Digital Ocean droplet running Pangolin. Functions basically the same as the cloudflare tunnel it replaced.

Can expose the service directly if needed, or from behind a login page.

[–] HelloRoot@lemy.lol 1 points 3 hours ago* (last edited 3 hours ago)

Same but nftables and also crowdsec.

Also I had some trouble with the wireguard tunnel dropping lots of packets, which resulted in my services not loading 50% of the time. I did a lot of suggestions at the same time so I'm not sure which one fixed it but here is a list in case anybody has similar troubles:

  • lowering MTU
  • routing ipv6 through the tunnel as well
  • rewriting nftables rule order
  • ...

(will update after work, notes are at home)

[–] pineapplelover@lemmy.dbzer0.com 3 points 8 hours ago (3 children)

What's a cheap vps you recommend?

I use a cheap racknerd vps via low end box. $12/yr.

Oracle has a free tier where I run my Wireguard.

[–] TheRedSpade@lemmy.world 2 points 7 hours ago (1 children)

Linode has a $5/month option.

[–] Andres4NY@social.ridetrans.it 1 points 7 hours ago

@TheRedSpade @pineapplelover Linode got acquired by Akamai and their service (or at least, *my* VPS) has really gone downhill over the past few years.

[–] Nibodhika@lemmy.world 2 points 6 hours ago

Why do you want to expose them? This might limit the solutions.

The way I do this is in 2 different ways:

  1. Tailscale, my server connects to tailscale so all I have to do is connect to it from my phone and I can access things remotely easily. This is the best for most things, but has the downside that others can't access it as easily

  2. I have a VPS (two actually at the moment as I'm switching providers from Vultr to IONOS) that also connects to tailscale so it can access my home server through it, then using Caddy I expose the services on a subdomain of the VPS. This is what I do for things that others might want to access, or things I don't want to have to connect to tailscale to access.

If you're going down the second route do consider that you will need to:

  • Add something like fail2ban or crowdsec to the VPS as attacks will happen.
  • Same reason you should add a dedicated authentication on front of most things. While I don't expect the auth on services to be weak, it might be more vulnerable than a dedicated authentication service. You should look into Authelia, Authentik, or similar to put on front of your services so any attacker would first have to pass that to even get to your services.
[–] KarnaSubarna@lemmy.ml 1 points 6 hours ago

Make it publicly available to the world or just for you (and people you know)?

[–] AllYourSmurf@lemmy.world 3 points 8 hours ago (1 children)

Authentication & single sign-on service

Plugged into Reverse proxy, routing to each service by name

With a wild card cert so there are no name leaks.

Make your urls unexpected. If your domain is example.com, don’t put your jellyfin server at jellyfin.example.com. Instead, use watch.example.com or telly.example.com. Anything that’s memorable to you about what the service is without using a specific brand name.

With a wildcard dns record to point all names to your IP, and a wildcard certificate that works for all names loaded on your load balancer, it becomes hard for a hacker to know what name to use to get the load balancer to send them to the service they want to hack.

If you then use a sso tool like traefik’s ForwardAuth middleware, you won’t even get to the service until you’ve first authenticated.

[–] helix@feddit.org 4 points 6 hours ago* (last edited 6 hours ago) (1 children)

If you use TLS like you should, your domains will be on the internet in the certificate transparency log. Yes, you should use a wildcard cert if you want this security by obscurity, but it's still security by obscurity.

[–] AllYourSmurf@lemmy.world 1 points 29 minutes ago

Of course. The goal here is to not advertise. Make it hard for the bots to find you. With these steps, they can try your IP, but there’s nothing directly on your IP.

You still need proper security. Authentication is a good start, and it has the extra effect of adding an extra layer to prevent the bots from going further if they get lucky and guess a host name.

[–] ISolox@lemmy.world 3 points 8 hours ago

Reverse proxy is what you need. I would post instructions here but honestly they wouldnt be that good. Just search it up and follow along.

[–] RanchBranch@anarchist.nexus 1 points 8 hours ago (1 children)

I recently switched to Netbird on a VPS (on Vultr). Their reverse proxy is super easy to set up / self host. They also offer a free version that works pretty good too, I just wanted to make it difficult for myself (thats the whole point of self hosting, right? )

[–] pineapplelover@lemmy.dbzer0.com 1 points 7 hours ago (3 children)

I have seen netbird pop around every now and again. I might try out their cloud free version first and if I like it I might try self hosting it.

So you host netbird on a vps you rent and that is used for reverse proxy? So with that reverse proxy I can have my home server be publicly accessible and I can have friends log in to my jellyfin server without having to connect to my tailnet.

My last concern is security. How is this set up good for making sure I don't just get constantly botted and exploited?

[–] stratself 1 points 6 hours ago* (last edited 6 hours ago)

I do this albeit with Tailscale. Netbird/Tailscale would act as a node of your VPN and you can configure reverse proxy routes (via tailscale serve or Netbird's equivalent) from the VPS edge to the homelab. You can even do SNI passthrough and have TLS terminated at your home, if you want, though this can be a bit slower

Alternatively you can even expose stuff via their servers. Tailscale Inc calls this service Funnels, and Netbird should have similar offerings. It's kinda like Tunnels but you gotta use their domains, so a VPS acts greater as a dedicated entrypoint.

Lastly yes you'd be exposing the service to the general public internet, so some basic security is needed. Netbird has a Crowdsec module integration, might wanna look at that one and set up rules/detections. Consider putting extra auth in front of Jellyfin, use Authelia or something with an auth screen. And only expose the stuff you need, not your internal dashboard or whatever admin UI.

[–] innocentzero@kbin.earth 1 points 7 hours ago

Opening jellyfin up publicly is kind of asking for trouble if you ask me. I haven't done so myself, but seen enough on this community and elsewhere to know that it's probably not a good idea.

[–] innocentzero@kbin.earth 0 points 7 hours ago (1 children)

You're probably misunderstanding what netbird does (unless I'm the one misunderstanding things?).

Netbird subnet is equivalent to a tailscale tailnet (for all practical purposes; they even both use wireguard and hole-punching underneath). Netbird is not a reverse proxy (which I feel is what you think based on your comment).

[–] diecknet@discuss.tchncs.de 1 points 2 hours ago

While Netbird is generally just one of the many alternatives to Tailscale, they also do have a Reverse Proxy feature that allows access without a Netbird client. Haven't tested it yet, seems to be in beta.

https://docs.netbird.io/manage/reverse-proxy

[–] lime@feddit.nu 0 points 6 hours ago

i configured dyndns in my router and have it forward all traffic to a gateway vm running nginx and fail2ban. every service is on a subdomain so any attempt to fetch things from the main name gets banned.

[–] electric_nan@lemmy.ml 0 points 8 hours ago (1 children)

Is the server at your house? Or VPS?

[–] pineapplelover@lemmy.dbzer0.com 1 points 8 hours ago

My server is at home

[–] lazylemons@lemmy.today -1 points 8 hours ago (1 children)

Recently set up caddy myself, very straightforward setup. You essentially just edit one config file and point your domain host to the right place and are good to go. Took me by surprise actually.

[–] pineapplelover@lemmy.dbzer0.com 1 points 8 hours ago (1 children)

Yeah but my main concern is security. If I publicly have services like jellyfin or something then I would think I would have constant exploits and bot attacks

[–] frongt@lemmy.zip 1 points 8 hours ago

You will.

Anything you expose should be designed for it (e.g. not jellyfin). You should have a WAF configured for the type of service you're hosting. You can't just drop one and have it magically protect you, they take configuration. Same with fail2ban.

And you should have these services in a DMZ, so that a compromise in one doesn't provide an entry point to other resources on your network.