User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
8h
people who host publicly-facing servers at home (not on a VPS), do you just directly use your home IP address w/ port forwarding or use a tunnel to a VPS (or a service like CF tunnels) with a reverse proxy?
:black_sparkling_heart@fire.asta.lgbt:1
8
4
2
1

User avatar
purple 💜 @purple@nya.social
7h
@norm i use a wireguard tunnel to a vps running traefik for ingress. everything other than a landing page is hosted off the cluster at home 😌
0
0
1
0
User avatar
Toast @toast@donotsta.re
7h
@norm back when I did this I had a Linux box as my router so I had a reverse proxy running on that proxying over to the server at home (so it can have a dhcp lease and everything), which came with the extra funny added benefit of being able to reverse proxy direct to containers if THEY go through dhcp and get picked up by dnsmasq etc, though I think what allowed that to work has been broken since
0
0
0
0
User avatar
Alex Bissessur @alexb@alexbissessur.dev
6h
@norm
I used to expose my home IP w/ port forwarding, but
@eleboucher made Towonel (codeberg.org/towonel/towonel) and I run it on a small VPS
0
0
0
0
User avatar
stefan (stefbun) @stefan@akko.lightnovel-dungeon.de
7h
@norm Its kinda mixed here lol. I tunnel through a VPS but not for privacy.

My privacy is fucked by having that imprint (government mandated) on my sites. I tunnel I can have IPv4 Traffic to my home. Otherwise I would just the IP at home as is.
1
0
1
0
User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
7h
@stefan do you have cgnat?
1
0
0
0
User avatar
stefan (stefbun) @stefan@akko.lightnovel-dungeon.de
6h
@norm DS-lite basically yeah. Though tbh I never. checked if the new ISP does give me an actual IPv4 instead...
0
0
0
0
User avatar
Oha @Oha@pobierz.net
7h
@norm Mix of both. IP gets tunneled in from a friends router bc my provider only gives me a single dynamic /64. Im lucky enough to not sit behind CGNAT so my Legacy IP is native
0
0
1
0
7h
@norm why would you tunnel unless you don’t have a public IP, or you can’t be arsed to setup a ddns resolver? there are very few reasons not to just use your IP…
3
0
0
0
User avatar
Norm (ノーム) CastoriceBlushing @norm@shrimp.biribiri.dev
7h
@domi at least in my case I am somewhat paranoid about exposing my home IP and also my ipv4 address changes whenever I reboot my router or modem.

I might just go down the port forwarding route with a ddns setup soon though
0
0
0
0
User avatar
snow @snow@cofe.rocks
7h
@domi @norm i'd never host on my home ip despite having a public one bcs it's basically a free doxx [small local isp]
also the VPS is a nice point to cache things so a fedi post going viral doesn't destroy my home internet
0
0
1
0
User avatar
Wolf480pl @wolf480pl@mstdn.io
5h
@domi
eg. you live in a small town and your revdns reveals which small town
@norm
1
0
0
0
@wolf480pl @norm @snow with this sort of threat model you should be tunneling ALL of your traffic through a vpn of some sort. there’s plenty of ways an attacker can discover your home IP otherwise.
1
0
0
0
User avatar
snow @snow@cofe.rocks
5h
@domi @wolf480pl @norm guess what i'm already doing :D
1
0
1
0
@snow @wolf480pl @norm not saying that’s smart, but at least consistent
0
0
1
0
User avatar
freek🔸 @freek@kubes.cloud
6h
@norm (nice hostname btw) I am using @eleboucher 's instance of towonel on his VPS: it gives me the convenience and comfort of Cloudflare Tunnel, without giving them data or allowing any decryption of the traffic outside my home (it stays encrypted until it gets to my hardware), and I am supporting an important open source project!
0
0
0
0