Which route did you go for your homeland, a tunnel to your services or setting up tail scale/wireguard and access them on your trailer?

top 50 comments

sorted by: hot top controversial new old
[–] 17 points 4 months ago (2 children)

I have wireguard, it's supported by my router (Fritzbox).

  • source
  • hideshow 2 child comments
  • [–] 11 points 4 months ago (6 children)
  • [–] [S] 1 point 4 months ago (3 children)

    When I looked into it first, Pangolin seemed a bit overwhelming.

    Is it hard to set up?

  • source
  • parent
  • hideshow 3 child comments
  • [–] 2 points 4 months ago (2 children)

    No, ridiculously easy with docker.

    Then it follows the same principles as cloud flare. Create a site (vpn endpoint), get a docker snippet for a newt (what they call the vpn connector), paste it in the docker compose on your Homeserver and see it come up in the Webinterface.

    Then you create a public resource and point it to said site and give it a url.

    Done.

    Ask me if you have questions

  • source
  • parent
  • hideshow 2 child comments
  • [–] 8 points 4 months ago (11 children)

    tailscale. works perfectly, the only problem is needing a google acc for login

  • source
  • hideshow 11 child comments
  • [–] 8 points 4 months ago

    I am very happy with Tailscale

  • source
  • [–] 8 points 4 months ago (7 children)

    Pangolin on a free Oracle VPS.

  • source
  • hideshow 7 child comments
  • load more comments (7 replies)
    [–] 7 points 4 months ago (2 children)

    I do run wireguard on my router, but the main reason is ad blocking, not hiding services. Most services are publicly exposed.

  • source
  • hideshow 2 child comments
  • [–] 7 points 4 months ago (1 child)

    Wireguard.

    Dunno if Cloudflare does effective auth for the tunnel or if you have to set that up yourself, but I don't bother trying to expose services to the internet in any way because some of this stuff was just never designed for proper web security (cough Jellyfin).

    It's still worth setting up a wildcard cert with ACME so you get nice https and a real domain.

  • source
  • hideshow 1 child comment
  • [–] [S] 2 points 4 months ago

    Cloudflare has some opt-in auth. Mail-OTP is a nice balance imo: You can allowlist mail addresses per service/subdomain and set expiry for each. Then for access, you first have to enter the mail address, get the OTP and then access the service.

    So, nobody without access to allowed mail addresses even gets to knock on you door.

    But yeah, that's why I think about going tail scale: why bother having something exposed when not needed?

    I just think, some services might be nice to provide to friends, too - and having them connect to my tailnet for this is a bit too much friction, I guess

  • source
  • parent
  • [–] 6 points 4 months ago (3 children)

    Netbird via a free cloud VM. Works great.

  • source
  • hideshow 3 child comments
  • load more comments (1 reply)
    [–] 5 points 4 months ago (2 children)

    How about both? I run the evil Cloudflare Tunnels/Zero Trust with Tailscale as an overlay on the server.

  • source
  • hideshow 2 child comments
  • [–] 5 points 4 months ago
    [–] 5 points 4 months ago

    Headscale on fly.io

  • source
  • [–] 4 points 4 months ago

    Asked my ISP for a public IP, exposed all things that can handle that to the public. Custom Wireguard server for VPN

  • source
  • [–] [B] 4 points 4 months ago* (last edited 4 months ago)

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:

    Fewer Letters More Letters
    DNS Domain Name Service/System
    IP Internet Protocol
    VPN Virtual Private Network
    VPS Virtual Private Server (opposed to shared hosting)

    [Thread #265 for this comm, first seen 30th Apr 2026, 19:30] [FAQ] [Full list] [Contact] [Source code]

  • source
  • Temp stuff where I could care less about the free tier domain name or things that I just want to funnel to my existing devices: Tailscale

    Widespread, prolonged services that will be more actively maintained for a longer amount of time and can just spin off of its own domain/subdomain: Cloudflare

    Both are great.

  • source
  • [–] 3 points 4 months ago

    I'm liking self hosted NetBird atm

  • source
  • [–] 3 points 4 months ago (1 child)

    Just Wireguard on a router, but I'm thinking Netbird.

    WG can be a bit PITA to set up, but once you do, it just works. What I would to have is more fine grained control over who goes where if I were to expose some of the services to friends.

  • source
  • hideshow 1 child comment
  • [–] 1 point 4 months ago

    wg-easy can greatly simplify your wireguard setup. Allows you to quickly generate access configs for friends and family on the fly (QR-codes, too). You still get access to post-up/-down hooks if you want tp create a more specialised deployment.

  • source
  • parent
  • [–] 3 points 4 months ago
    [–] 2 points 4 months ago

    Zerotier. I found it easy to set up and use. Free tier gives you one network and ten hosts, I think.

  • source
  • [–] 2 points 4 months ago

    I used wireguard, then switched to Pangolin. Wireguard was simpler and worked better with mobile apps though. I'll prob switch back for most apps.

  • source
  • [–] 2 points 4 months ago (2 children)

    Wildcard dns with port 80 & 443 port forwarded to traefik with tinyauth & fail2ban

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 2 points 4 months ago* (last edited 4 months ago) (2 children)

    I actually have Wireguard running on a pi zero 2, all it really does is provide me my pihole DNS.

    Edit:

    I should say I have pihole running on a couple of pi 5’s currently, overkill yes but one of my pi 4’s was sacrificed to the whims of magic smoke another was donated to a friend and another now hosts HAOS, I have a few pi zero 2’s (only one was sacrificial) the one that hosts wireguard has one of my last few working SD cards. The pi 5’s host many other things other than just pihole.

  • source
  • hideshow 2 child comments
  • [–] 1 point 4 months ago

    I have a port forwarding without any tunnel to third parties and Wireguard.

  • source
  • load more comments
    view more: next ›