people who host publicly-facing servers at home (not on a VPS), do you just directly use your home IP address w/ port forwarding or use a tunnel to a VPS (or a service like CF tunnels) with a reverse proxy?
@mirabilos I mean like just hosting directly off your home connection's public IP. I know port forwarding isn't strictly necessary with IPv6, but I'd imagine some people are on IPv4 only setups where you do have to deal with NAT
@mirabilos I do think there's still a usecase for a separate router from a server, but I do agree with ditching consumer-grade routers or the ISP provided stuff
@norm if the server is either running all the time or cheap enough power-wise to keep running all the time, I’ll argue it makes a better router anyway since you can run BSD with a proper firewall on it and are much better network-wise than with a separate router
@ezio the caveat to using cloudflare's reverse proxy is that it only proxies inbound connections, so if the server you are running makes outbound connections, those will use your regular internet access
using a VPN tunnel means both inbound and outbound connections go through a different IP
@norm back when I did this I had a Linux box as my router so I had a reverse proxy running on that proxying over to the server at home (so it can have a dhcp lease and everything), which came with the extra funny added benefit of being able to reverse proxy direct to containers if THEY go through dhcp and get picked up by dnsmasq etc, though I think what allowed that to work has been broken since
@norm I run everything on a bare metal server at home, since it's way easier to do, I have a few other things tho Discord bots run outside of the Wireguard connection because of connectivity issues. Those have a separate server. The nginx on the main server can direct traffic to there if needed. Status page and mail server runs on the VPS.
This setup kind of allows me to have almost no loss of data when e.g. my VPS gets terminated over a failed transaction
@norm Its kinda mixed here lol. I tunnel through a VPS but not for privacy.
My privacy is fucked by having that imprint (government mandated) on my sites. I tunnel I can have IPv4 Traffic to my home. Otherwise I would just the IP at home as is.
@norm Mix of both. IP gets tunneled in from a friends router bc my provider only gives me a single dynamic /64. Im lucky enough to not sit behind CGNAT so my Legacy IP is native
@norm why would you tunnel unless you don’t have a public IP, or you can’t be arsed to setup a ddns resolver? there are very few reasons not to just use your IP…
@wolf480pl@norm@snow with this sort of threat model you should be tunneling ALL of your traffic through a vpn of some sort. there’s plenty of ways an attacker can discover your home IP otherwise.
@norm (nice hostname btw) I am using @eleboucher 's instance of towonel on his VPS: it gives me the convenience and comfort of Cloudflare Tunnel, without giving them data or allowing any decryption of the traffic outside my home (it stays encrypted until it gets to my hardware), and I am supporting an important open source project!