As I start to host more and more services on my home server, my family and friends are interested in using some of the services I host as well. Up to now, all of my services have been internal-only, and my wife and I just use Tailscale to access everything. Getting others set up with tailscale isn’t an issue, but I can only have up to 4 other users before I have to pay to add more, and I have more than 4 people I would like to have access to some of the things I host.

Right now I’m using cloudflare tunnels to make some services available externally. I’m behind CGNAT, so I’m forced to use something like tunnels or similar. I’ve always read that if you are going to open things up externally to use a reverse proxy (which I use internally), but does this still apply with cloudflare tunnels? What else should I be looking at to make sure I have everything secured properly?

  • frongt@lemmy.zip
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    1
    ·
    22 days ago

    A reverse proxy is just for convenice of stuff like hostnames and ssl termination. It’s not a security layer.

    The proper way to do it would be to have your public stuff in a DMZ , if untrusted users (i.e. could have malware on their device) are going to access it.

    Personally I use Netbird and host a tiny server in the cloud, which a local node connects to, to avoid NAT or firewall rules. Since it’s self-hosted, there is no user limit.

  • vividspecter@aussie.zone
    link
    fedilink
    English
    arrow-up
    7
    ·
    22 days ago

    For tailscale, unless you need different ACLs for every user, you could instead have additional friends share a single user and then you’re only limited by the quite high device cap. Or self-host headscale on a VPS and then there are no user limits.

  • poundyourdrum@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    5
    ·
    22 days ago

    if you want more users you can host headscale instead of using tailscale, users can still connect with the regular tailscale clients

    additionally you can use forward auth on your reverse proxy using something like authentik so that users have to be logged in before they can even see the service itself. personally I trust authentik more than I trust all of the individual services which might not have the same level of scrutiny applied to their security. it also has the added bonus of letting your users use SSO if your services support it.

      • the_q@piefed.social
        link
        fedilink
        English
        arrow-up
        5
        ·
        22 days ago

        I think this is a similar approach to Cloudflare tunneling just self hosted. I personally miss reverse proxy with my own domain, but my apartment complex forced an ISP on us that killed that.

        • paris@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          2
          ·
          22 days ago

          I rent a free tier oracle vm that does nothing more than tunnel traffic using GOST. Ports 80/443/25 and a control port that my homelab can connect to to establish the tunnel. No ports open at my house, public IP is the cloud VM, and the raw encrypted tcp traffic is tunneled through whatever NAT shenanigans my ISP might have and straight into Caddy within a docker (podman) network. I’m pretty happy with it and it works well!

          It’s a single binary and can parse a config file or command line parameters. If I ever switch public VM providers, it’s a single binary download and a systemd service file. Switch my DNS records to the new VM and I’m completely done. And since my homelab establishes the connection to the VM’s port, I don’t have to reconfigure anything if I move buildings, switch providers, get stuck behind NAT, or can’t open ports.

            • paris@lemmy.blahaj.zone
              link
              fedilink
              English
              arrow-up
              2
              ·
              21 days ago

              Not sure if this is meant to be sarcastic, but I’m not particularly smart on this matter, just persistent in trying to get things to work. I used to use rathole but came around to GOST as a replacement for several reasons. I don’t think Pangolin was around yet when I made the switch.

                • paris@lemmy.blahaj.zone
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  19 days ago

                  We all are until we aren’t. Good documentation goes a long way and gost has extensive documentation and examples for every option it has. It helped a lot in figuring out how to use the tool and I was very excited when I finally got it working!

      • myrmidex@slrpnk.net
        link
        fedilink
        English
        arrow-up
        2
        ·
        22 days ago

        Pangolin seconded! Been using it for over a year, not a single hiccup. Switched the moment I heard CF does not like media streams via their tunnels.

      • WASTECH@lemmy.worldOP
        link
        fedilink
        English
        arrow-up
        2
        ·
        22 days ago

        I would like to avoid paying for a VPS. I probably should have clarified in my post too that I am specifically looking for advise on securing public facing services. While I certainly could make everyone use a tailscale-like service, at this point I think securing an external service would be easier. Especially since most of these people would not be tech savvy and I don’t particularly want to play tech support for their VPN.

        • moonpiedumplings@programming.dev
          link
          fedilink
          English
          arrow-up
          2
          ·
          22 days ago

          EDIT no wait, this post is about secure, not hosting/tunneling in general. This comment is off topic ig.

          I would like to avoid paying for a VPS

          Oracle cloud free tier, but it does have a history of randomly killing the VPS’s created.

          Public ipv4 addresses are scarce, and becoming more expensive now. You are probably going to have to shell out some cash if you don’t already get one as part of your internet plan.

          • WASTECH@lemmy.worldOP
            link
            fedilink
            English
            arrow-up
            1
            ·
            22 days ago

            My ISP is charging $20/mo for static IP’s, so almost any other solution would be cheaper.

            I hate Oracle with the passion of a thousand suns, so I don’t want to touch them with a 10ft pole. I would happily pay anyone else to avoid using anything affiliated with Oracle.

        • linux_supremacist@lemmy.nazibeater.fyi
          link
          fedilink
          English
          arrow-up
          2
          ·
          22 days ago

          ngrok allows up to 1 gigabyte out. it is not a good deal compared to cloudflare tunnels. the vps with pangolin is the best option on the table if I’m going to be honest

  • mxdcodes@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    22 days ago

    Tunnel is fine security wise. Keep the reverse proxy anyway and let the tunnel point at it. Routing, logs, etc. stay in one place this way.

    Zero Trust with Google etc. is the way for family. Tailscale or Wireguard means installing a VPN client and making sure it keeps running, that’s too much for most people who just want to click a link.

    • iamthetot@piefed.ca
      link
      fedilink
      English
      arrow-up
      2
      ·
      21 days ago

      If people want to use a service you’re putting in the effort (and money) hosting, they can put in the effort to learn how to access it, however you choose. Otherwise they can kick rocks.

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    13 days ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    CGNAT Carrier-Grade NAT
    DNS Domain Name Service/System
    ISP Internet Service Provider
    NAT Network Address Translation
    Plex Brand of media server package
    SSO Single Sign-On
    VPN Virtual Private Network
    VPS Virtual Private Server (opposed to shared hosting)

    8 acronyms in this thread; the most compressed thread commented on today has 12 acronyms.

    [Thread #103 for this comm, first seen 13th Sep 2026, 06:00] [FAQ] [Full list] [Contact] [Source code]

  • WingedObsidian@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    1
    ·
    13 days ago

    Consider pangolin(I use this) or netbird on a cheap VPS from racknerd. With pangolin can share secure links without exposing services to whole internet. I add crowdsec to it and it works wonders. If you go this route secure you ssh port 22 with crowdsec and in ssh config.

  • GreenKnight23@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    20 days ago

    if you’re going to expose a reverse proxy, you might as well use a WAF instead.

    think of a WAF as a smart reverse proxy with logging intelligence.

    might also help to have blocklists on your firewall that block any IP outside of your country.

  • lemmyvore@feddit.nl
    link
    fedilink
    English
    arrow-up
    1
    ·
    21 days ago

    They don’t need to be actual users. When they’re trying to start Tailscale on a new device have them pass the authorization link to you and open it on your account. This way their devices are registered as devices for your user. You can tag the devices and write ACLs for them to determine what they can access.