this post was submitted on 26 Feb 2024
106 points (96.5% liked)

Selfhosted

39980 readers
780 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 55 points 8 months ago (2 children)

The only externally accessible service is my wireguard vpn. For anything else, if you are not on my lan or VPN back into my lan, it’s not accessible.

[–] [email protected] 2 points 8 months ago (4 children)

Can I ask your setup? I'd like to get this for myself as well.

[–] [email protected] 1 points 8 months ago

Sorry, haven't logged on in a bit. I use OPNSense on an old PC for my firewall with the wireguard packet installed.

Then use the wireguard client on my familys phones/laptops that is set to auto connect when NOT on my home wifi. That way media payback, adguard-home dns and everything acts as seamless as possible even when away while still keeping all ports blocked.

[–] [email protected] 3 points 8 months ago (1 children)

Not OP but… I have an old PC as a server, Wireguard in docker container, port-forward in the router and that’s it

[–] [email protected] 1 points 8 months ago (1 children)

Which image? I've seen a few wireguard options on docker hub

[–] [email protected] 3 points 8 months ago
[–] [email protected] 3 points 8 months ago

Try pivpn. It is meant to run on a raspberry pi, but it should work on most Ubuntu and Debian based distributions.

[–] [email protected] 1 points 8 months ago

Not OP, but I just use ZeroTier for this since it's dead simple to setup and free. I'm sure there's some 100% self-hosted solutions, but it's worked for me without issue.

[–] [email protected] 9 points 8 months ago (1 children)
[–] [email protected] 8 points 8 months ago (1 children)

Funnily enough it’s exactly the opposite way of where the corporate world is going, where the LAN is no longer seen as a fortress and most services are available publically but behind 2FA.

[–] [email protected] 9 points 8 months ago* (last edited 8 months ago) (1 children)

Corporate world, I still have to VPN in before much is accessible. Then there’s also 2FA.

Homelab, ehhh. Much smaller user base and within smackable reach.

[–] [email protected] 1 points 8 months ago

Oh right. The last three business I’ve worked in have all been fully public services; assume the intruder is already in the LAN, so don’t treat it like a barrier.