As I start to host more and more services on my home server, my family and friends are interested in using some of the services I host as well. Up to now, all of my services have been internal-only, and my wife and I just use Tailscale to access everything. Getting others set up with tailscale isn’t an issue, but I can only have up to 4 other users before I have to pay to add more, and I have more than 4 people I would like to have access to some of the things I host.

Right now I’m using cloudflare tunnels to make some services available externally. I’m behind CGNAT, so I’m forced to use something like tunnels or similar. I’ve always read that if you are going to open things up externally to use a reverse proxy (which I use internally), but does this still apply with cloudflare tunnels? What else should I be looking at to make sure I have everything secured properly?

  • vividspecter@aussie.zone
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    3 hours ago

    For tailscale, unless you need different ACLs for every user, you could instead have additional friends share a single user and then you’re only limited by the quite high device cap. Or self-host headscale on a VPS and then there are no user limits.

  • frongt@lemmy.zip
    link
    fedilink
    English
    arrow-up
    10
    ·
    6 hours ago

    A reverse proxy is just for convenice of stuff like hostnames and ssl termination. It’s not a security layer.

    The proper way to do it would be to have your public stuff in a DMZ , if untrusted users (i.e. could have malware on their device) are going to access it.

    Personally I use Netbird and host a tiny server in the cloud, which a local node connects to, to avoid NAT or firewall rules. Since it’s self-hosted, there is no user limit.

      • WASTECH@lemmy.worldOP
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        I would like to avoid paying for a VPS. I probably should have clarified in my post too that I am specifically looking for advise on securing public facing services. While I certainly could make everyone use a tailscale-like service, at this point I think securing an external service would be easier. Especially since most of these people would not be tech savvy and I don’t particularly want to play tech support for their VPN.

        • linux_supremacist@lemmy.nazibeater.fyi
          link
          fedilink
          English
          arrow-up
          1
          ·
          57 minutes ago

          ngrok allows up to 1 gigabyte out. it is not a good deal compared to cloudflare tunnels. the vps with pangolin is the best option on the table if I’m going to be honest

      • the_q@piefed.social
        link
        fedilink
        English
        arrow-up
        2
        ·
        3 hours ago

        I think this is a similar approach to Cloudflare tunneling just self hosted. I personally miss reverse proxy with my own domain, but my apartment complex forced an ISP on us that killed that.

    • WASTECH@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 hours ago

      I use NPM internally for SSL. DuckDNS won’t work for me since I am behind CGNAT. I also already own a domain.