64
Security considerations about hosting Immich from home
(lemmy.world)
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.
No spam.
Posts here are to be centered around self-hosting. Please ensure it is clear in your post how it relates to self-hosting.
Don't duplicate the full text of your blog or git here. Just post the link for folks to click.
Submission headline should match the article title.
No trolling.
Resources:
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
I think this should be talked about more. Does every selfhosted app need to be public facing?
I use Immich as a backup service, so i really don't have any need to have it public facing. It connects when I'm home. Same with contacts/calendar.
I have many services that doesn't "need" to be public, as public facing for one specific reason. TLS.
A lot of the times android apps won't connect to http directions, not even local ones, and require a proper https connection with a well known CA.
For that I put the services behind a caddy reverse proxy to get a valid tls certificate.
And them I do the trick, and basically on caddy reject any connection that's not local. Thus, making the supposedly "public" site a practical "local" one.
Once there I just connect through wireguard.
Clever. I'm just starting to mess with Caddy. Been struggling with Vaultwarden lately and your solution might fit my needs.