view the rest of the comments
Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
I host some private stuff on mine, hidden behind an authentication service that is. But because I just use a wildcard no-one can really tell what I have hosted - the same login page occurs for every subdomain, regardless of whether it's actually wired up to something.
That doesn't help with services you wish to make semi-public (like a lemmy instance) though.
Interested in learning about the wildcard. How do you set up the DNS to accept that?
I'm using cloudflare as my DNS, and it's literally just:
*On the letsencrypt side, it's pretty similar. Create a certificate with
domain.nameand*.domain.name(if you want them to share a cert) and you're off.I have a similar setup.
Getting the DNS to return the right addresses is easy enough: you just set your records for subdomain
*instead a specific subdomain, and then any subdomain that's not explicitly configured will default to using the records for*.Assuming you want to use Let's Encrypt (or another ACME CA) you'll probably want to make sure you use an ACME client that supports your DNS provider's API (or switch DNS provider to one that has an API your client supports). That way you can get wildcard TLS certificates (so individual subdomains won't still leak via Certificate Transparency logs). Configure your ACME client to use the Let's Encrypt staging server until you see a wildcard certificate on your domains.
Some other stuff you'll probably want: