Skip to content
DnsLister Forum

Where domain hunters compare notes

How do you expose services to the public, and what do you think is best practice?

Recently started my first homelab, and I've got the basics setup on my lan (also took this as a chance to learn nixos, which has been it's own headache, but that's offtopic) but I am a little worried about opening up ports to the wider world. I do want to provide some services to non-technical friends and family, mostly immich and jellyfin, so I have been searching for a way to do that without just opening up ports.

I started with a reverse proxy (caddy) with a dns challenge for https to my cloudflare domain. Figuring I was already using cloudflare, I also setup a cloudflare tunnel so that I could provide services without a vpn client on a client device, at a domain url and not an IP, and my favorite part, with familiar SSO authentication for people in my life who aren't actively running from google. This works great for services when accessed in a browser (yes, I know that serving video is a grey area, I do have cdn caching off, and it won't be a ton of traffic anyways) but anything on an app won't connect because the SSO is now in the way. Which brings me here: how do you guys provide services to friends and family? do you just require them to use tailscale or wireguard? do you port forward at your router and harden your own network? I want this to be as easy as possible for others to use, without sacrificing my own network's security.

Source: r/homelab · by /u/ritz_are_the_shitz

Leave a Reply

Your email address will not be published. Required fields are marked *