I want to expose my services publicly on my own domain name, how would you guys do that?

I have seen people using Cloudflare, but I don’t want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I’ve done some rough researching.

What do you guys do?

  • spork@pawb.social
    link
    fedilink
    English
    arrow-up
    32
    ·
    edit-2
    3 days ago

    I rent a cheap VPS with iptables routing ports through a wireguard tunnel to a peer on the local network that acts as a firewall and reverse proxy, this gives you a static IP with a local control plane and no ddns.

      • spork@pawb.social
        link
        fedilink
        English
        arrow-up
        8
        ·
        2 days ago

        I hop around a lot. I’ve used Akamai (fka linode), Vultr, DigitalOcean, AWS EC2, and GCP Compute Engine. I wouldn’t recommend the last 2 anymore because fuck big tech. A lot of people will mention Oracle’s free tier, but I don’t trust anyone that looks like Larry Ellison to own a machine with a direct connection into my local network.

            • /home/pineapplelover@lemmy.dbzer0.comOP
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 day ago

              Is there a data cap? I’m concerned like they only allow me to pass through like a TB or so of data passing through it within a month. If you have users watching your jellyfin server every day that can surpass your limit.

              • Taasz/Woof@piefed.social
                link
                fedilink
                English
                arrow-up
                1
                ·
                1 day ago

                Yes generally around 1TB on cheap plans. That’s a ton of data though for streaming media, if youre moving more than that getting a higher tier VPS would make sense.

              • Jason2357@lemmy.ca
                link
                fedilink
                English
                arrow-up
                0
                ·
                1 day ago

                Keep in mind that you wouldn’t route local traffic through it, so everything watched at home would be direct and not count.

                I have a $5/mo VPS with OVH and they allow unlimited bandwidth within reason. Unless you have multiple households streaming from your server all the time, likely totally fine. If you do end up with one relative streaming 24x7, then I would look at installing the tailscale app on their TV and configuring things to connect that one user direct to your home server.

                A VPS takes some learning, but IMHO, it is the “correct” answer and worthile learning.

                  • Jason2357@lemmy.ca
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    7 hours ago

                    There are constant scanners on any site and scrapers on websites, but it is far less of a problem than you would imagine unless you have a big wiki or software forge with hundreds of nested commit history pages for them to spider into.

                    I also run private servers on hidden subdomains (with wildcard certs and DNS entries), so the low effort scanners never bother them.

                    DDOS attacks take money, so they aren’t typically going to go after some random homelabber. If it did happen, I would either just shut it off for a while or change the VPs IP. Ovh also has some of its own ddos protection.

      • shadshack@feddit.online
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        2 days ago

        Look into Oracle cloud’s Always Free tier of cloud instances. I have a few of those and they’re decent for free.

    • HelloRoot@lemy.lol
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      edit-2
      3 days ago

      Same but nftables and also crowdsec.

      Also I had some trouble with the wireguard tunnel dropping lots of packets, which resulted in my services not loading 50% of the time. I did a lot of suggestions at the same time so I’m not sure which one fixed it but here is a list in case anybody has similar troubles:

      • lowering MTU
      • routing ipv6 through the tunnel as well
      • rewriting nftables rule order

      (will update after work, notes are at home)

    • halcyoncmdr@piefed.social
      link
      fedilink
      English
      arrow-up
      4
      ·
      edit-2
      3 days ago

      Similar here. Just a Digital Ocean droplet running Pangolin. Functions basically the same as the cloudflare tunnel it replaced.

      Can expose the service directly if needed, or from behind a login page.