I want to expose my services publicly on my own domain name, how would you guys do that?

I have seen people using Cloudflare, but I don’t want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I’ve done some rough researching.

What do you guys do?

  • /home/pineapplelover@lemmy.dbzer0.comOP
    link
    fedilink
    English
    arrow-up
    0
    ·
    29 days ago

    I have seen netbird pop around every now and again. I might try out their cloud free version first and if I like it I might try self hosting it.

    So you host netbird on a vps you rent and that is used for reverse proxy? So with that reverse proxy I can have my home server be publicly accessible and I can have friends log in to my jellyfin server without having to connect to my tailnet.

    My last concern is security. How is this set up good for making sure I don’t just get constantly botted and exploited?

    • InnocentZero@kbin.earth
      link
      fedilink
      arrow-up
      0
      ·
      29 days ago

      Opening jellyfin up publicly is kind of asking for trouble if you ask me. I haven’t done so myself, but seen enough on this community and elsewhere to know that it’s probably not a good idea.

      • ampersandrew@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        29 days ago

        By all means correct me if you know more, but what I tend to see is one or two people here saying that Jellyfin devs don’t recommend exposing it publicly, only to be corrected by looking at the actual documentation. I suspect those cautioning against it are on outdated information and that Jellyfin carries much the same risk as exposing any other service.

        • irmadlad@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          28 days ago

          but what I tend to see is one or two people here saying that Jellyfin devs don’t recommend exposing it publicly

          I think what the devs are saying is ‘don’t expose Jellyfin to the public in an unsafe manner’. I don’t run Jellyfin, but can confirm what you’ve read here. In that vein, don’t expose anything to the public in an unsafe manner.

            • irmadlad@lemmy.world
              link
              fedilink
              English
              arrow-up
              0
              ·
              28 days ago

              Again, I do not run Jellyfin, but what you’re saying seems contradictory to what the devs are implying: here and here. Since I lack the hands on experience, I will leave the issue with the experts.

              • frongt@lemmy.zip
                link
                fedilink
                English
                arrow-up
                0
                ·
                28 days ago

                That first page says exposing it to the Internet is “not recommended”. Putting a reverse proxy in front of it does not meaningfully change the security posture. A malicious request to http://jellyfin.homelab.com/exploitable-page will be sent to jellyfin in effectively the same way, whether through a reverse proxy or not. You would need a WAF set up specifically to look for relevant exploit attempts.

                https://github.com/jellyfin/jellyfin/issues/5415

                Those are some outstanding known vulnerabilities, most of them unfixed. They are not particularly severe, but it shows that thorough security is not a priority for the jellyfin devs.

                • ampersandrew@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  28 days ago

                  It says exposing a port directly to the internet is not recommended; do you know of any project that would recommend directly exposing a port? What is meaningfully different here?

                  • frongt@lemmy.zip
                    link
                    fedilink
                    English
                    arrow-up
                    0
                    ·
                    28 days ago

                    Sure, any project designed to be exposed to the Internet. Web servers would be the most obvious.