hi everyone,

I was just about to self-host a Ghost blog but then was warned that my ISP might change my external IP address at any time, so I would need to pay for a static IP address.

Is that true?

(I'd not seen much about that in stuff I've looked up so far about self hosting)

you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 1 year ago* (last edited 1 year ago) (21 children)

I could make this quick: Is your internet access behind a CG-NAT? If yes: you're gonna need a static IP.

  • source
  • hideshow 21 child comments
  • [–] 6 points 1 year ago (5 children)

    Not necessarily, Cloudflare tunnels, headscale/tailscale will sort that issue out amongst several other ways

  • source
  • parent
  • hideshow 5 child comments
  • [–] [S] 1 point 1 year ago (1 child)

    I was going to use Cloudflare to sort this, but I'm uncomfortable how big they are getting / lack of competition in that part of the market. So we looked at Pangolin as an alternative, but it's a faff to self host.

    Hence why we're back at exposing it straight out the back of Nginx Proxy Manager.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 1 year ago (2 children)

    But how will a tailnet help for a blog? At some point, the https port needs to be open.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 1 year ago

    tailscale will tunnel through and you can set it to pass through https. Lots of different ways to achieve this, as long as you have control over the dns and are able to set https up it will work. This is why for me I still use cloudflare, you can even setup a subdomain through their tunnels and they act as a cdn. For example, I run a linkstack instance, send instance and much more

    https://linkstack.relayeasy.com/@3dcadmin

  • source
  • parent
  • [–] 1 point 1 year ago (12 children)
  • [–] 2 points 1 year ago (11 children)

    Care to explain what I got wrong?

  • source
  • parent
  • hideshow 11 child comments
  • [–] 1 point 1 year ago (10 children)

    Static IP is helpfull but not necessary. Even with NAT and a changeing IP there's options, such as:

    1. dynamic dns.
    2. Public reverse proxy or tunnel.
    3. Onion routing.
  • source
  • parent
  • hideshow 10 child comments
  • [–] 1 point 1 year ago (9 children)
    1. How do you open the https port behind a nas?
    2. That public tunnel needs at least a public IP address again.
    3. Ok, forgot that one. But then you're only accessible through Tor, isn't it?
  • source
  • parent
  • hideshow 9 child comments
  • [–] 1 point 1 year ago (8 children)
    1. Port forwarding
    2. Yes, and there's services that do that for you
  • source
  • parent
  • hideshow 8 child comments
  • [–] 1 point 1 year ago (7 children)

    You can't port-forward if you sit behind a nat.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 1 point 1 year ago (6 children)

    Port forwarding was invented for exactly that

  • source
  • parent
  • hideshow 6 child comments
  • [–] 1 point 1 year ago (5 children)

    Hou will you configure the ISP's NAT router to port-forward? You won't be able to reach the forwarded port if your ISP doesn't foward the port as well.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 2 points 1 year ago

    You can't, this guy doesn't know what he's taking about.

    Port forward behind CGNAT won't get you out. Best bet here would be ipv6.

    Tor would work. However, only over Tor obviously.

  • source
  • parent
  • [–] 1 point 1 year ago (2 children)

    ISP’s NAT

    That has it's own name... CG-NAT. Thus why people are responding to you as if you're wrong. As you wrote it you are wrong though. But there's still answers like argo tunnels (if you are okay with cloudflare) and other similar solutions.

    Or you can setup a vps and tunnel through that.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 1 year ago (1 child)

    Oh, I see. Sorry I was too dumb to research that term for the comment.

    Or you can setup a vps and tunnel through that.

    But then the VPS needs a static address.

  • source
  • parent
  • hideshow 1 child comment