As I start to host more and more services on my home server, my family and friends are interested in using some of the services I host as well. Up to now, all of my services have been internal-only, and my wife and I just use Tailscale to access everything. Getting others set up with tailscale isn’t an issue, but I can only have up to 4 other users before I have to pay to add more, and I have more than 4 people I would like to have access to some of the things I host.

Right now I’m using cloudflare tunnels to make some services available externally. I’m behind CGNAT, so I’m forced to use something like tunnels or similar. I’ve always read that if you are going to open things up externally to use a reverse proxy (which I use internally), but does this still apply with cloudflare tunnels? What else should I be looking at to make sure I have everything secured properly?

you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 4 weeks ago (17 children)

With being behind a CGNAT tunnels is your only option.

  • source
  • hideshow 17 child comments
  • [–] 7 points 4 weeks ago (16 children)

    https://pangolin.net/

    What about this? Pangolin is probably fine if they rent a vps.

  • source
  • parent
  • hideshow 16 child comments
  • [–] 5 points 4 weeks ago (6 children)

    I think this is a similar approach to Cloudflare tunneling just self hosted. I personally miss reverse proxy with my own domain, but my apartment complex forced an ISP on us that killed that.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 2 points 4 weeks ago (4 children)

    I rent a free tier oracle vm that does nothing more than tunnel traffic using GOST. Ports 80/443/25 and a control port that my homelab can connect to to establish the tunnel. No ports open at my house, public IP is the cloud VM, and the raw encrypted tcp traffic is tunneled through whatever NAT shenanigans my ISP might have and straight into Caddy within a docker (podman) network. I'm pretty happy with it and it works well!

    It's a single binary and can parse a config file or command line parameters. If I ever switch public VM providers, it's a single binary download and a systemd service file. Switch my DNS records to the new VM and I'm completely done. And since my homelab establishes the connection to the VM's port, I don't have to reconfigure anything if I move buildings, switch providers, get stuck behind NAT, or can't open ports.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 0 points 4 weeks ago (3 children)
  • [–] 2 points 3 weeks ago (2 children)

    Not sure if this is meant to be sarcastic, but I'm not particularly smart on this matter, just persistent in trying to get things to work. I used to use rathole but came around to GOST as a replacement for several reasons. I don't think Pangolin was around yet when I made the switch.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 3 weeks ago (1 child)

    No sarcasm. I'm genuinely out of my depth on a lot of this.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 3 weeks ago

    We all are until we aren't. Good documentation goes a long way and gost has extensive documentation and examples for every option it has. It helped a lot in figuring out how to use the tool and I was very excited when I finally got it working!

  • source
  • parent
  • [–] [S] 2 points 4 weeks ago (6 children)

    I would like to avoid paying for a VPS. I probably should have clarified in my post too that I am specifically looking for advise on securing public facing services. While I certainly could make everyone use a tailscale-like service, at this point I think securing an external service would be easier. Especially since most of these people would not be tech savvy and I don’t particularly want to play tech support for their VPN.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 5 points 4 weeks ago (2 children)

    That's what pangolin is. Your users don't need to use anything special. The VPN is used internally to connect your server and the VPS. It's not actually public facing. For the enduser it's the same as if you used cloudflare tunnels.

    One word of warning if you choose to go with Cloudflare: Using their tunnels for streaming video is technically against their TOS. It's not really enforced most of the time, but you might run into problems, if you plan on really high usage.

    An alternative service is Netbird. Open Source, based in Germany and as far as I know they don't have this limitation

  • source
  • parent
  • hideshow 2 child comments
  • [–] [S] 2 points 4 weeks ago (1 child)

    Thanks for the warning. My Plex server is currently behind a Cloudflare tunnel, so I probably need to look at moving that.

    I mistook pangolin for netbird, so thanks for the clarification!

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 4 weeks ago

    Happy to help. One further point of clarification: Netbird traditionally was a VPN solution that required client software on the end user device, that's what you were thinking of presumably. However they recently-ish expanded into offering reverse proxy services as well: https://docs.netbird.io/manage/reverse-proxy

    So if you are looking for a cloudflare tunnels alternative and don't want to go the fully selfhosted route, then Netbird can do that. I can't speak to it's reliability though, because I run a selfhosted Pangolin for my setup, and Netbird themselves mention that the feature is currently still in beta.

  • source
  • parent
  • [–] 2 points 4 weeks ago* (1 child)

    EDIT no wait, this post is about secure, not hosting/tunneling in general. This comment is off topic ig.

    I would like to avoid paying for a VPS

    Oracle cloud free tier, but it does have a history of randomly killing the VPS's created.

    Public ipv4 addresses are scarce, and becoming more expensive now. You are probably going to have to shell out some cash if you don't already get one as part of your internet plan.

  • source
  • parent
  • hideshow 1 child comment
  • [–] [S] 1 point 4 weeks ago

    My ISP is charging $20/mo for static IP’s, so almost any other solution would be cheaper.

    I hate Oracle with the passion of a thousand suns, so I don’t want to touch them with a 10ft pole. I would happily pay anyone else to avoid using anything affiliated with Oracle.

  • source
  • parent