I want to expose my services publicly on my own domain name, how would you guys do that?

I have seen people using Cloudflare, but I don’t want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I’ve done some rough researching.

What do you guys do?

  • RanchBranch@anarchist.nexus
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    I recently switched to Netbird on a VPS (on Vultr). Their reverse proxy is super easy to set up / self host. They also offer a free version that works pretty good too, I just wanted to make it difficult for myself (thats the whole point of self hosting, right? )

    • /home/pineapplelover@lemmy.dbzer0.comOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      I have seen netbird pop around every now and again. I might try out their cloud free version first and if I like it I might try self hosting it.

      So you host netbird on a vps you rent and that is used for reverse proxy? So with that reverse proxy I can have my home server be publicly accessible and I can have friends log in to my jellyfin server without having to connect to my tailnet.

      My last concern is security. How is this set up good for making sure I don’t just get constantly botted and exploited?

      • InnocentZero@kbin.earth
        link
        fedilink
        arrow-up
        0
        ·
        2 months ago

        Opening jellyfin up publicly is kind of asking for trouble if you ask me. I haven’t done so myself, but seen enough on this community and elsewhere to know that it’s probably not a good idea.

        • ampersandrew@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          By all means correct me if you know more, but what I tend to see is one or two people here saying that Jellyfin devs don’t recommend exposing it publicly, only to be corrected by looking at the actual documentation. I suspect those cautioning against it are on outdated information and that Jellyfin carries much the same risk as exposing any other service.

          • irmadlad@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            but what I tend to see is one or two people here saying that Jellyfin devs don’t recommend exposing it publicly

            I think what the devs are saying is ‘don’t expose Jellyfin to the public in an unsafe manner’. I don’t run Jellyfin, but can confirm what you’ve read here. In that vein, don’t expose anything to the public in an unsafe manner.

              • irmadlad@lemmy.world
                link
                fedilink
                English
                arrow-up
                0
                ·
                2 months ago

                Again, I do not run Jellyfin, but what you’re saying seems contradictory to what the devs are implying: here and here. Since I lack the hands on experience, I will leave the issue with the experts.

                • frongt@lemmy.zip
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  2 months ago

                  That first page says exposing it to the Internet is “not recommended”. Putting a reverse proxy in front of it does not meaningfully change the security posture. A malicious request to http://jellyfin.homelab.com/exploitable-page will be sent to jellyfin in effectively the same way, whether through a reverse proxy or not. You would need a WAF set up specifically to look for relevant exploit attempts.

                  https://github.com/jellyfin/jellyfin/issues/5415

                  Those are some outstanding known vulnerabilities, most of them unfixed. They are not particularly severe, but it shows that thorough security is not a priority for the jellyfin devs.

      • RanchBranch@anarchist.nexus
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        Yup! They can either connect to your Netbird meshnet (ie, similar a tailnet) or you can reverse proxy it out to the internet (no tailnet needed)

        I saw a couple comments below concerned about security, one of the nice things about Netbird is that they have reverse proxy auth built in if you want. Some stuff (Navidrome or VoidAuth for instance) only has geolocation locked down (US only) but other things that I’m either more concerned about or don’t necessarily trust being open (Paperless or Komodo for instance) have Netbird Auth and VoidAuth as sign in options before it will let me open the page. Its worked flawlessly so far, and has kept my sanity intact because I wanted some stuff publically accessible without it being OPEN.

        As far as being hammer fucked, it has CrowdSec and Geolocation lockdowns so you can set it to only accept traffic from ONE location and the Crowdsec also catches everything.

      • InnocentZero@kbin.earth
        link
        fedilink
        arrow-up
        0
        ·
        2 months ago

        You’re probably misunderstanding what netbird does (unless I’m the one misunderstanding things?).

        Netbird subnet is equivalent to a tailscale tailnet (for all practical purposes; they even both use wireguard and hole-punching underneath). Netbird is not a reverse proxy (which I feel is what you think based on your comment).

  • ISolox@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    Reverse proxy is what you need. I would post instructions here but honestly they wouldnt be that good. Just search it up and follow along.

  • Dirtboy@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    I bought myself a Synology disk station and a domain.

    Yes I use Cloudflare for DNS so I can get a wildcard domain cert using ACME.

    I use the Synology supplied login portal as a web application firewall for every site I want to host with the wildcard SSL cert. Like bar.mydomain.com, mealie.mydomain.com, etc.

    The Synology routes the traffic to the services hosted on other services within my network.

    Anything else I don’t want open to the public web, I use the Synology supplied OpenVPN server to connect.

  • ArborNode@lemmy.shutes.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    For those of us behind double NAT (CGNAT) forwarding ports is not an option as we do not control forwarding on the second gateway. This will limit you to any of the solutions that include a device outside your network with a public port that tunnels traffic into your server.

      • ArborNode@lemmy.shutes.org
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        To some degree yes. I ran an experiment to see and found there is just too much of the existing internet infrastructure not implementing IPV6 for this to be reliable. For instance, you can’t use it for email intake because only 2 major players do IPV6.

        You still get dynamic assignments from the ISP and have to automate keeping your AAAA records up to date.

        The short answer is, it depends. For what OP is doing here, I expect it would work.

        If anyone else has messed with this, I’d love to here about it. Might be good as it’s own post.

  • galacticworm@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    If you have a UniFi gateway, you can enable region based firewall on your port forward ip. This then blocks most of the world (incoming) as a first step. Then like others suggest, a reverse proxy. I use Caddy built with the Maxmind geolocation plugin, and I also run fail2ban on my exposed service.

    I figure if you don’t need most of the world accessing your services, it is best to exclude them

  • myrmidex@belgae.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    I got off CloudFlare by using Pangolin. Ideal for my use-case, I didn’t use any of CF’s advanced features, so Pangolin is the ideal replacement for me.

    Publicly serves everything from static sites to forgejo (+the ssh endpoint for git pushes).

  • MagnificentSteiner@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    I can’t answer your question as I haven’t taken that step yet, everything is still confined to my LAN.

    Here’s a similar thread from last month that had a lot of replies. Hopefully will be some useful info there for you. Good luck!

  • lazylemons@lemmy.today
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    Recently set up caddy myself, very straightforward setup. You essentially just edit one config file and point your domain host to the right place and are good to go. Took me by surprise actually.

    • /home/pineapplelover@lemmy.dbzer0.comOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Yeah but my main concern is security. If I publicly have services like jellyfin or something then I would think I would have constant exploits and bot attacks

      • frongt@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        You will.

        Anything you expose should be designed for it (e.g. not jellyfin). You should have a WAF configured for the type of service you’re hosting. You can’t just drop one and have it magically protect you, they take configuration. Same with fail2ban.

        And you should have these services in a DMZ, so that a compromise in one doesn’t provide an entry point to other resources on your network.

  • Nibodhika@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    Why do you want to expose them? This might limit the solutions.

    The way I do this is in 2 different ways:

    1. Tailscale, my server connects to tailscale so all I have to do is connect to it from my phone and I can access things remotely easily. This is the best for most things, but has the downside that others can’t access it as easily

    2. I have a VPS (two actually at the moment as I’m switching providers from Vultr to IONOS) that also connects to tailscale so it can access my home server through it, then using Caddy I expose the services on a subdomain of the VPS. This is what I do for things that others might want to access, or things I don’t want to have to connect to tailscale to access.

    If you’re going down the second route do consider that you will need to:

    • Add something like fail2ban or crowdsec to the VPS as attacks will happen.
    • Same reason you should add a dedicated authentication on front of most things. While I don’t expect the auth on services to be weak, it might be more vulnerable than a dedicated authentication service. You should look into Authelia, Authentik, or similar to put on front of your services so any attacker would first have to pass that to even get to your services.
  • Karna@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    Make it publicly available to the world or just for you (and people you know)?

  • paydequeso@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    Netbird reverse proxy: https://docs.netbird.io/manage/reverse-proxy

    It’s like Tailscale, but Open Source. You can self-host the components, if you want. I just use the cloud offering. I have a domain name that resolves to my server. There’s different ways you can do auth. I just hard coded an allow list of IPs. Otherwise, devices in my Netbird network can use the private IP.