this post was submitted on 11 Sep 2026
35 points (97.3% liked)

Selfhosted

62068 readers
633 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

As I start to host more and more services on my home server, my family and friends are interested in using some of the services I host as well. Up to now, all of my services have been internal-only, and my wife and I just use Tailscale to access everything. Getting others set up with tailscale isn’t an issue, but I can only have up to 4 other users before I have to pay to add more, and I have more than 4 people I would like to have access to some of the things I host.

Right now I’m using cloudflare tunnels to make some services available externally. I’m behind CGNAT, so I’m forced to use something like tunnels or similar. I’ve always read that if you are going to open things up externally to use a reverse proxy (which I use internally), but does this still apply with cloudflare tunnels? What else should I be looking at to make sure I have everything secured properly?

you are viewing a single comment's thread
view the rest of the comments
[–] Vittelius@feddit.org 5 points 17 hours ago (1 children)

That's what pangolin is. Your users don't need to use anything special. The VPN is used internally to connect your server and the VPS. It's not actually public facing. For the enduser it's the same as if you used cloudflare tunnels.

One word of warning if you choose to go with Cloudflare: Using their tunnels for streaming video is technically against their TOS. It's not really enforced most of the time, but you might run into problems, if you plan on really high usage.

An alternative service is Netbird. Open Source, based in Germany and as far as I know they don't have this limitation

[–] WASTECH@lemmy.world 1 points 3 hours ago (1 children)

Thanks for the warning. My Plex server is currently behind a Cloudflare tunnel, so I probably need to look at moving that.

I mistook pangolin for netbird, so thanks for the clarification!

[–] Vittelius@feddit.org 1 points 3 hours ago

Happy to help. One further point of clarification: Netbird traditionally was a VPN solution that required client software on the end user device, that's what you were thinking of presumably. However they recently-ish expanded into offering reverse proxy services as well: https://docs.netbird.io/manage/reverse-proxy

So if you are looking for a cloudflare tunnels alternative and don't want to go the fully selfhosted route, then Netbird can do that. I can't speak to it's reliability though, because I run a selfhosted Pangolin for my setup, and Netbird themselves mention that the feature is currently still in beta.