Right now I'm using NetBird's Reverse Proxy/Expose feature for my public-facing services, and I'm wondering if there are better options.
My current setup is:
- NetBird
- Nginx Proxy Manager
- Pi-hole
- My own domain
- Dynamic public IP
I currently use Nginx Proxy Manager and Pi-hole for local DNS, HTTPS, and certificates. NPM isn't exposed to the internet.
For public access, I'm currently exposing these through NetBird:
- Jellyfin
- Seerr
- Home Assistant
- Audiobookshelf
- Vikunja
- LubeLogger
Some of the services have NetBird's PIN protection enabled. However, Home Assistant, Jellyfin, and Audiobookshelf are currently relying on their own username/password authentication.
I've considered just exposing Nginx Proxy Manager with ports 80/443 forwarded from my router, but I'm not sure how comfortable I am with opening ports directly to my network, especially since I have a dynamic public IP.
I've also tried Cloudflare Zero Trust/Tunnels in the past, but that was about two years ago. At the time I found the authentication setup more complicated than I wanted, although I'd be willing to revisit it if it's a better solution now.
My main requirement is that some services need to be accessible to friends/family without requiring them to install NetBird or create a NetBird account. I also want to continue using my own domain/subdomains.
Would you recommend sticking with NetBird Reverse Proxy/Expose, going back to Cloudflare Tunnel, or exposing NPM directly over 80/443? Or is there another solution I should be looking into?
I'm mainly looking for something that's secure, reasonably simple to maintain, and works well for services that need to be publicly accessible.
What are you all using for this?
Clarification: I use NetBird as my VPN for accessing my home network remotely, but I’m also using NetBird’s Reverse Proxy/Expose feature to make the services listed above publicly accessible. So users accessing those services currently don’t need to be connected to my NetBird VPN.
Source: r/homelab · by /u/signalloss443