this post was submitted on 11 Sep 2026
35 points (97.3% liked)

Selfhosted

62068 readers
633 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

As I start to host more and more services on my home server, my family and friends are interested in using some of the services I host as well. Up to now, all of my services have been internal-only, and my wife and I just use Tailscale to access everything. Getting others set up with tailscale isn’t an issue, but I can only have up to 4 other users before I have to pay to add more, and I have more than 4 people I would like to have access to some of the things I host.

Right now I’m using cloudflare tunnels to make some services available externally. I’m behind CGNAT, so I’m forced to use something like tunnels or similar. I’ve always read that if you are going to open things up externally to use a reverse proxy (which I use internally), but does this still apply with cloudflare tunnels? What else should I be looking at to make sure I have everything secured properly?

top 24 comments
sorted by: hot top controversial new old
[–] poundyourdrum@lemmy.dbzer0.com 5 points 13 hours ago

if you want more users you can host headscale instead of using tailscale, users can still connect with the regular tailscale clients

additionally you can use forward auth on your reverse proxy using something like authentik so that users have to be logged in before they can even see the service itself. personally I trust authentik more than I trust all of the individual services which might not have the same level of scrutiny applied to their security. it also has the added bonus of letting your users use SSO if your services support it.

[–] mxdcodes@lemmy.world 3 points 13 hours ago

Tunnel is fine security wise. Keep the reverse proxy anyway and let the tunnel point at it. Routing, logs, etc. stay in one place this way.

Zero Trust with Google etc. is the way for family. Tailscale or Wireguard means installing a VPN client and making sure it keeps running, that's too much for most people who just want to click a link.

[–] Augmented1207@feddit.org 2 points 13 hours ago (1 children)

So my setup rigjt now:

  • vps with headscale
  • all devices connect to it
  • in my home lab a vm running a tailscale client and a reverse proxy with a Wildcard cert
  • all other services run as their own VMS and the proxy routes to them
  • i have a dmz (not yet public) running a proxy with tailscale again for a different domain
  • dmz runs a authentik vm which i use for access controll and user management
  • backup Server connects to tailscale as well and proxmox pushes zfs snapshots every day

My long term goal is to move to pangolin as a reverse proxy on the vps and tailscale alternative and remove tailscale, as i find its very battery inefficient on Android (no subnet Router etc).

So i just give people access to the VPN and send them an authentik invite and thats it. With pangolin i dont even have to give them a VPN access anymore, it can be done via authentik i think.

A vps is 3-6€ and the tailscale standard is 10€ so its even cheaper, but a bit more setup to maintain. But it allows a ton of users :) so i guess this would be the smallest change with the highest impact

Authentik is nice to have but a pain to set up as the oicd stuff can be tricky. Immich was super ez, nextcloud was OK, docspell was a pain and ocis does not work with authentik becsuse they use different architectures for sso. (Ocis and authentik are a bit dumb here)

[–] WASTECH@lemmy.world 1 points 3 hours ago

I have just recently started messing with Authentik. And I can confirm OIDC claims and whatnot are an absolute nightmare. I have some experience setting up SAML stuff from my work, but I only do that if our main guy is out and I always struggle with it there too.

Your setup sounds the most like what I am doing now, minus the DMZ. But all of my containers are rootless. I am running everything on TrueNAS right now.

I think I will lean more on Authentik, as the provisioning of users and giving them access to services through that is very easy. I will probably stick with Cloudflare for the time being, but I will look more into Pangolin.

[–] vividspecter@aussie.zone 6 points 20 hours ago* (last edited 20 hours ago)

For tailscale, unless you need different ACLs for every user, you could instead have additional friends share a single user and then you're only limited by the quite high device cap. Or self-host headscale on a VPS and then there are no user limits.

[–] frongt@lemmy.zip 14 points 1 day ago

A reverse proxy is just for convenice of stuff like hostnames and ssl termination. It's not a security layer.

The proper way to do it would be to have your public stuff in a DMZ , if untrusted users (i.e. could have malware on their device) are going to access it.

Personally I use Netbird and host a tiny server in the cloud, which a local node connects to, to avoid NAT or firewall rules. Since it's self-hosted, there is no user limit.

[–] the_q@piefed.social 3 points 23 hours ago (1 children)

With being behind a CGNAT tunnels is your only option.

[–] linux_supremacist@lemmy.nazibeater.fyi 7 points 23 hours ago (4 children)

https://pangolin.net/

What about this? Pangolin is probably fine if they rent a vps.

[–] pleksi@sopuli.xyz 2 points 4 hours ago

Pangolin + pocketid has been rock solid!

[–] myrmidex@slrpnk.net 2 points 16 hours ago

Pangolin seconded! Been using it for over a year, not a single hiccup. Switched the moment I heard CF does not like media streams via their tunnels.

[–] the_q@piefed.social 4 points 20 hours ago (2 children)

I think this is a similar approach to Cloudflare tunneling just self hosted. I personally miss reverse proxy with my own domain, but my apartment complex forced an ISP on us that killed that.

[–] paris@lemmy.blahaj.zone 2 points 15 hours ago (1 children)

I rent a free tier oracle vm that does nothing more than tunnel traffic using GOST. Ports 80/443/25 and a control port that my homelab can connect to to establish the tunnel. No ports open at my house, public IP is the cloud VM, and the raw encrypted tcp traffic is tunneled through whatever NAT shenanigans my ISP might have and straight into Caddy within a docker (podman) network. I'm pretty happy with it and it works well!

It's a single binary and can parse a config file or command line parameters. If I ever switch public VM providers, it's a single binary download and a systemd service file. Switch my DNS records to the new VM and I'm completely done. And since my homelab establishes the connection to the VM's port, I don't have to reconfigure anything if I move buildings, switch providers, get stuck behind NAT, or can't open ports.

[–] the_q@piefed.social 1 points 12 hours ago

Oh to be as smart as you.

it literally is self hosting cloudflare tunnels :)

[–] WASTECH@lemmy.world 2 points 20 hours ago (3 children)

I would like to avoid paying for a VPS. I probably should have clarified in my post too that I am specifically looking for advise on securing public facing services. While I certainly could make everyone use a tailscale-like service, at this point I think securing an external service would be easier. Especially since most of these people would not be tech savvy and I don’t particularly want to play tech support for their VPN.

[–] Vittelius@feddit.org 5 points 17 hours ago (1 children)

That's what pangolin is. Your users don't need to use anything special. The VPN is used internally to connect your server and the VPS. It's not actually public facing. For the enduser it's the same as if you used cloudflare tunnels.

One word of warning if you choose to go with Cloudflare: Using their tunnels for streaming video is technically against their TOS. It's not really enforced most of the time, but you might run into problems, if you plan on really high usage.

An alternative service is Netbird. Open Source, based in Germany and as far as I know they don't have this limitation

[–] WASTECH@lemmy.world 1 points 3 hours ago (1 children)

Thanks for the warning. My Plex server is currently behind a Cloudflare tunnel, so I probably need to look at moving that.

I mistook pangolin for netbird, so thanks for the clarification!

[–] Vittelius@feddit.org 1 points 3 hours ago

Happy to help. One further point of clarification: Netbird traditionally was a VPN solution that required client software on the end user device, that's what you were thinking of presumably. However they recently-ish expanded into offering reverse proxy services as well: https://docs.netbird.io/manage/reverse-proxy

So if you are looking for a cloudflare tunnels alternative and don't want to go the fully selfhosted route, then Netbird can do that. I can't speak to it's reliability though, because I run a selfhosted Pangolin for my setup, and Netbird themselves mention that the feature is currently still in beta.

[–] moonpiedumplings@programming.dev 2 points 17 hours ago* (last edited 17 hours ago) (1 children)

EDIT no wait, this post is about secure, not hosting/tunneling in general. This comment is off topic ig.

I would like to avoid paying for a VPS

Oracle cloud free tier, but it does have a history of randomly killing the VPS's created.

Public ipv4 addresses are scarce, and becoming more expensive now. You are probably going to have to shell out some cash if you don't already get one as part of your internet plan.

[–] WASTECH@lemmy.world 1 points 3 hours ago

My ISP is charging $20/mo for static IP’s, so almost any other solution would be cheaper.

I hate Oracle with the passion of a thousand suns, so I don’t want to touch them with a 10ft pole. I would happily pay anyone else to avoid using anything affiliated with Oracle.

ngrok allows up to 1 gigabyte out. it is not a good deal compared to cloudflare tunnels. the vps with pangolin is the best option on the table if I'm going to be honest

[–] Kirk@startrek.website 2 points 23 hours ago (1 children)

Look into NGINX Proxy manager and DuckDNS

[–] WASTECH@lemmy.world 2 points 19 hours ago (1 children)

I use NPM internally for SSL. DuckDNS won’t work for me since I am behind CGNAT. I also already own a domain.

[–] Kirk@startrek.website 1 points 10 hours ago

You know more than me