view the rest of the comments
Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
Please don't expose your services to the internet directly. Use something like Tailscale/Headscale/whatever mesh VPN is relevant now. It'll always be 100 times better than this and you wouldn't worry about Authelia, f2b and CrowdSec (though updating your services and server(s) is always worth it).
It will not be a 100 times better than this, you'd need the vpn setup already on every client, how could others ever connect to it? Its also just cool to have a domain and expose it properly, I already use a vpn for admin only things
I also do this, you're good
“Okay mom, you need to install this VPN, log in, and make sure it’s on whenever you’re using Immich. Can you install it for Dad too? Now I’m going to call grandma back and explain that it isn’t a Deen Peen Em and she’s never going to find that.”
There are times and places. The moment you want the non tech side of the family involved, a proper with server over the open internet is usually the better option.
But I run a VPN on my phone by default, so I'd have to disconnect from that to access stuff on my home network (and remember to turn it back on after).
That's why I'm planning on using mTLS until I get my router configured to direct my BTH VPN through the gateway I have running on my phone.
I just need to figure out how to get VLANs properly set up in Mikrotik without having to nuke everything and start from scratch.
I, too, run an always on VPN from my mobile devices. I can still access my home network with pihole and DNS entries to my services. It's not that difficult. I agree though, mTLS is a good option.