I want to expose my services publicly on my own domain name, how would you guys do that?
I have seen people using Cloudflare, but I don’t want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I’ve done some rough researching.
What do you guys do?


I rent a cheap VPS with iptables routing ports through a wireguard tunnel to a peer on the local network that acts as a firewall and reverse proxy, this gives you a static IP with a local control plane and no ddns.
What’s a cheap vps you recommend?
I hop around a lot. I’ve used Akamai (fka linode), Vultr, DigitalOcean, AWS EC2, and GCP Compute Engine. I wouldn’t recommend the last 2 anymore because fuck big tech. A lot of people will mention Oracle’s free tier, but I don’t trust anyone that looks like Larry Ellison to own a machine with a direct connection into my local network.
I resonate with you as well, so what kind of set up do you use now?
I use a cheap racknerd vps via low end box. $12/yr.
That’s crazy cheap price. Does it really have enough bandwidth to stream jellyfin?
Most VPS are on 1Gbps connections, but even if it only has 100Mbps that’s plenty.
Is there a data cap? I’m concerned like they only allow me to pass through like a TB or so of data passing through it within a month. If you have users watching your jellyfin server every day that can surpass your limit.
Yes generally around 1TB on cheap plans. That’s a ton of data though for streaming media, if youre moving more than that getting a higher tier VPS would make sense.
Keep in mind that you wouldn’t route local traffic through it, so everything watched at home would be direct and not count.
I have a $5/mo VPS with OVH and they allow unlimited bandwidth within reason. Unless you have multiple households streaming from your server all the time, likely totally fine. If you do end up with one relative streaming 24x7, then I would look at installing the tailscale app on their TV and configuring things to connect that one user direct to your home server.
A VPS takes some learning, but IMHO, it is the “correct” answer and worthile learning.
How do you set up security on your server with the constant attacks that come with having the server public?
There are constant scanners on any site and scrapers on websites, but it is far less of a problem than you would imagine unless you have a big wiki or software forge with hundreds of nested commit history pages for them to spider into.
I also run private servers on hidden subdomains (with wildcard certs and DNS entries), so the low effort scanners never bother them.
DDOS attacks take money, so they aren’t typically going to go after some random homelabber. If it did happen, I would either just shut it off for a while or change the VPs IP. Ovh also has some of its own ddos protection.
Yes. (Depending on load) I run a server with 10 users, probably 2-3 active at any given time. Works fine.
Linode has a $5/month option.
@TheRedSpade @pineapplelover Linode got acquired by Akamai and their service (or at least, *my* VPS) has really gone downhill over the past few years.
Oracle has a free tier where I run my Wireguard.
Look into Oracle cloud’s Always Free tier of cloud instances. I have a few of those and they’re decent for free.
Same but nftables and also crowdsec.
Also I had some trouble with the wireguard tunnel dropping lots of packets, which resulted in my services not loading 50% of the time. I did a lot of suggestions at the same time so I’m not sure which one fixed it but here is a list in case anybody has similar troubles:
(will update after work, notes are at home)
Similar here. Just a Digital Ocean droplet running Pangolin. Functions basically the same as the cloudflare tunnel it replaced.
Can expose the service directly if needed, or from behind a login page.
The basic 4 dolars one? Or something extra?