this post was submitted on 21 Jul 2025
107 points (97.3% liked)

Selfhosted

49689 readers
396 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

Hello,

Some time ago, I started self-hosting applications, but only on my local network. So far, it's working fine, but I can't access them as soon as I go outside (which is completely normal).

For the past few days I've been looking for a relatively secure way of accessing my applications from outside.

I don't need anyone but myself to have access to my applications, so from what I've understood, it's not necessarily useful to set up a reverse-proxy in that case and it would be simpler to set up a VPN.

From what I've seen, Wireguard seems to be a good option. At first glance, I'd have to install it on the machine containing my applications, port-forward the Wireguard listening port and configure my other devices to access this machine through Wireguard

However, I don't have enough hindsight to know whether this is a sufficient layer of security to at least prevent bots from accessing my data or compromising my machine.

I've also seen Wireguard-based solutions like Tailscale or Netbird that seem to make configuration easier, but I have a hard time knowing if it would really be useful in my case (and I don't really get what else they are doing despite simplifying the setup).

Do you have any opinions on this? Are there any obvious security holes in what I've said? Is setting up a VPN really the solution in my case?

Thanks in advance for your answers!

you are viewing a single comment's thread
view the rest of the comments
[–] Ptsf@lemmy.world 6 points 1 day ago (2 children)

Zero tier. I went tailscale originally, and they're good, but their mdns support doesn't exist and several services rely on it. (For me, the showstopper was time machine backups)

[–] maxwellfire@lemmy.world 2 points 1 day ago* (last edited 1 day ago) (1 children)

I like zerotier over wireguard because it's one layer lower. So anything that uses Ethernet frames can be routed over it like it was a network switch plugged into your computer. This is probably why mdns works.

[–] skankhunt42@lemmy.ca 1 points 1 day ago* (last edited 1 day ago) (1 children)

Do you test public WiFi with ZeroTier at all?

I ask because there's a few public networks where WG won't connect and I'm trying to find ways around it. I could always use cell data but this is more fun to me.

[–] maxwellfire@lemmy.world 2 points 1 day ago

Yeah it's worked everywhere I've tested. But that's only really been airport WiFi, so I'm not sure it's indicative of it working in general. It's easy enough to setup for testing that it's probably worth a shot

huh. I knew there was a reason for me to go back to ZT. mdns, you say? Nice to know!