Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.
-
No spam posting.
-
Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.
-
Don't duplicate the full text of your blog or github here. Just post the link for folks to click.
-
Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).
-
No trolling.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
view the rest of the comments
At a high level you forward ports 80 and 443 to NPM from your router. In NPM you set up your proxy by IP address and port and you can also set up automatic SSL certs when you create the proxy via letsencrypt. I also run a DDNS auto update that tells porkbun if my IP changes. I'd be happy to get into some more specifics if there's a particular spot you're stuck. This is all assuming you have a public IPv4 and aren't behind cgnat. If you have cgnat you're not totally fucked but it makes it more complicated. If it's OPNsense related struggles that shit is mysterious to me, I've only been running it a few weeks and it's not fully configured. Still learning.
Why am I forwarding all http and https traffic from WAN to a single system on my LAN? Wouldn't that break my DNS?
You would be forwarding ingress traffic(traffic not originating from your internal network) to 443/80, this doesn't affect egress requests(requests from users inside your network requesting external sites) so it wouldn't break your internal DNS resolution of sites. All traffic heading to your router from outside origins would be pushed to your reverse proxy where you can then route however you please to whatever machine/port your apps live on.
The reverse proxy is th single system because it tells the incoming traffic where to go. It also doesn't really do anything unless the incoming traffic is requesting one of the domains you set up. it doesn't affect your internal DNS. You are able to redirect from the public address to your internal server through DNS though.