I want to expose my services publicly on my own domain name, how would you guys do that?
I have seen people using Cloudflare, but I don’t want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I’ve done some rough researching.
What do you guys do?
Reverse proxy is what you need. I would post instructions here but honestly they wouldnt be that good. Just search it up and follow along.
Authentication & single sign-on service
Plugged into Reverse proxy, routing to each service by name
With a wild card cert so there are no name leaks.
Make your urls unexpected. If your domain is example.com, don’t put your jellyfin server at jellyfin.example.com. Instead, use watch.example.com or telly.example.com. Anything that’s memorable to you about what the service is without using a specific brand name.
With a wildcard dns record to point all names to your IP, and a wildcard certificate that works for all names loaded on your load balancer, it becomes hard for a hacker to know what name to use to get the load balancer to send them to the service they want to hack.
If you then use a sso tool like traefik’s ForwardAuth middleware, you won’t even get to the service until you’ve first authenticated.
My router (gl-net) has a VPN server built in. I just use WireGuard client and freedns.
Why do you want to expose them? This might limit the solutions.
The way I do this is in 2 different ways:
-
Tailscale, my server connects to tailscale so all I have to do is connect to it from my phone and I can access things remotely easily. This is the best for most things, but has the downside that others can’t access it as easily
-
I have a VPS (two actually at the moment as I’m switching providers from Vultr to IONOS) that also connects to tailscale so it can access my home server through it, then using Caddy I expose the services on a subdomain of the VPS. This is what I do for things that others might want to access, or things I don’t want to have to connect to tailscale to access.
If you’re going down the second route do consider that you will need to:
- Add something like fail2ban or crowdsec to the VPS as attacks will happen.
- Same reason you should add a dedicated authentication on front of most things. While I don’t expect the auth on services to be weak, it might be more vulnerable than a dedicated authentication service. You should look into Authelia, Authentik, or similar to put on front of your services so any attacker would first have to pass that to even get to your services.
-
I personally use a vps for this stuff but my setup is standalone nginx as a reverse proxy and fail2ban and ufw
Make it publicly available to the world or just for you (and people you know)?
Publicly to the world. For example, I wanted to self host temporary file sharing and temporary link shortener to the world. Stuff like jellyfin I would have that public but only specific users would have the credentials to log in.
I bought myself a Synology disk station and a domain.
Yes I use Cloudflare for DNS so I can get a wildcard domain cert using ACME.
I use the Synology supplied login portal as a web application firewall for every site I want to host with the wildcard SSL cert. Like bar.mydomain.com, mealie.mydomain.com, etc.
The Synology routes the traffic to the services hosted on other services within my network.
Anything else I don’t want open to the public web, I use the Synology supplied OpenVPN server to connect.
I also have a synology but my old gaming laptop does video transcoding better so I have it on debian right now and am figuring out the best set up to access it and self host services to access publicly
Is the server at your house? Or VPS?
My server is at home
The way that I handled this, was to get a $5 VPS, and have it proxy all my traffic over wireguard. Your DNS records (and SSL cert) all point to the VPS public IP address. IPtables rules route all relevant traffic.
I use traefik combined with crowdsec, there is a plugin for that. There is some pretty good tutorial (in german) on goneuland.de
Netbird has a reverseproxy that’s super easy to setup to point to one of your netbird nodes.
I have a Flint 2 with a vanilla install of openWRT, that hosts wireguard. I have 2 static IPs, because I thought hey running my own mail and smtp services cannot be that hard (turns out yes it is hard and not worth the time to deal). Any who I have Wireguard running on my firewall and Caddy running on one of my pi’s, it gets TLS from lets encrypt.
I have a couple of domains that Caddy uses to point things out to the world or my LAN/vLANs/VPNs. Very few of the things go out to the whole world, but if I wanted to share say a Jellyfin server with someone I could wip up a VPN that only allows Jellyfin through and points DNS to my piholes. Why do I mention my ad blocker? I mention pihole because that what hosts the A records to my domain names that Caddy can serve up, I do not remember why I set it up like this, I would have to look through my notes but pihole points “service”.domain1or2.xyz to caddy which than points to the right service.
Edit: went and looked A records are hosted on pihole for my LAN/vLANs/VPNs to prevent things needing to go out and come back just to tell devices where on my LAN services are.




