As I start to host more and more services on my home server, my family and friends are interested in using some of the services I host as well. Up to now, all of my services have been internal-only, and my wife and I just use Tailscale to access everything. Getting others set up with tailscale isn’t an issue, but I can only have up to 4 other users before I have to pay to add more, and I have more than 4 people I would like to have access to some of the things I host.

Right now I’m using cloudflare tunnels to make some services available externally. I’m behind CGNAT, so I’m forced to use something like tunnels or similar. I’ve always read that if you are going to open things up externally to use a reverse proxy (which I use internally), but does this still apply with cloudflare tunnels? What else should I be looking at to make sure I have everything secured properly?

  • WASTECH@lemmy.worldOP
    link
    fedilink
    English
    arrow-up
    2
    ·
    21 hours ago

    Thanks for the warning. My Plex server is currently behind a Cloudflare tunnel, so I probably need to look at moving that.

    I mistook pangolin for netbird, so thanks for the clarification!

    • Vittelius@feddit.org
      link
      fedilink
      English
      arrow-up
      2
      ·
      20 hours ago

      Happy to help. One further point of clarification: Netbird traditionally was a VPN solution that required client software on the end user device, that’s what you were thinking of presumably. However they recently-ish expanded into offering reverse proxy services as well: https://docs.netbird.io/manage/reverse-proxy

      So if you are looking for a cloudflare tunnels alternative and don’t want to go the fully selfhosted route, then Netbird can do that. I can’t speak to it’s reliability though, because I run a selfhosted Pangolin for my setup, and Netbird themselves mention that the feature is currently still in beta.