I've recently migrated away from iOS to GrapheneOS and I need a way to have a family shared calendar and reminders. I'm thinking NextCloud because I don't really know of anything else.

I've been doing some research and I'm a bit overwhelmed since I have never self hosted before and I'm not too familiar with these technologies. I have an old HP ProDesk with an old i3, 4GB of RAM, and 120 GB SSD that I was hoping to use intermittently until I get a newer machine. I want to be able to expose the instance to the wider internet so we (my partner and I) can access it on the go, but I'm worried about messing it up. I was reading that I need a reverse proxy as bare minimum, but do I also need fail2ban, Anubis (or Go Away), and special UFW rules? I got as far as installing NextCloud with podman on Ubuntu Server 26.04.01 LTS and I can access it locally, but I'm not sure how to get move forward.

Ideally I would like to have a bash script that sets everything up with user data being handled by an external drive so I can easily reproduce it to a new machine later down the line and facilitate backups. I'm not married to Ubuntu and I am open to using something else.

I also want to run other self hosted open source services like Navidrome, Yamtrack, Standard Notes, etc. Any guidance would be appreciated.

you are viewing a single comment's thread
view the rest of the comments
[–] 2 points 1 week ago (5 children)

Could you help me learn something conceptually about a reverse proxy?

My understanding is that Virtual Private Servers (vps) charge for bandwidth after you exceed a free cap.

If I set up nextcloud behind a reverse proxy, so that I'm not exposing my residential IP address to the internet, does that mean that when I upload a 500 gigabyte file, let's say, I will incur 500 gigabytes of usage on the virtual private server?

Or is there some system where once you log in to your server, it is smart enough to make a direct connection from the client to the residential IP and bypass the reverse proxy?

  • source
  • parent
  • hideshow 5 child comments
  • [–] 2 points 15 hours ago* (2 children)

    Depending on how you set it up.

    Normally, you run the reverse proxy on the same machine as your NextCloud.
    The job of the reverse proxy is do TLS termination, ie. encrypt your communications. It can also do other things - like virtual hosts (self-host your NextCloud and .. er, whatever else like Standard Notes on the same machine, distinguish them by FQDN: https://cloud.sem.com/ vs https://notes.sem.com/).

    On the topic of transferring 500GB files to your self-hosted storage - it really depends on where you connect from. Home WiFi? It'll take the direct path, and likely be faster. Home, but on the mobile network? You'll make a hop through the nearest cell tower, inflating your internet usage. A VPS, however, is not in this picture at all.

    Now, could you add a VPS? Sure, but you'd need to have a specific reason/goal in mind. Your residential IP address is already exposed to the internet (evidently, as you're posting here). Instead of a VPS-as-a-reverse-proxy, set up a Wireguard split tunnel with https://github.com/wgtunnel/android if you want your whole deployment be hidden/private.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 13 hours ago (1 child)

    The security aspect I've heard is that knowing your IP is one thing, but the more services you have running on your IP the more security holes there are likely to be. That was the idea for having public dns point to a VPS for nextcloud, so it is still reachable by the public, but not exposing the home network to any holes nextcloud may have.

    But I'm not sure that is a great solutiin either.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 1 week ago (1 child)

    In your example it would use that much and no it can't be shortcut, that'd be a big security bug and is not intended.

    The reverse proxy is just a piece of software and can be on the same machine as the actual service, but yeah, if you don't have a public IP at home, you'll need someone like you described and it will need the traffic.

    I think there's different software that does hole punching and actually gets you a peer to peer connection but there's more vpn territory where the vps is just used to find a way between the peers.

    For most use cases, the free traffic is usually enough though.

  • source
  • parent
  • hideshow 1 child comment