this post was submitted on 27 Jan 2025
441 points (98.5% liked)

Selfhosted

41572 readers
797 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

Just exposed Immich via a remote and reverse proxy using Caddy and tailscale tunnel. I'm securing Immich using OAuth.

I don't have very nerdy friends so not many people appreciate this.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 22 points 3 days ago* (last edited 3 days ago) (29 children)

Like, good for you, man.

But you should really keep your stuff inside the VPN and not expose things, it opens up a pile of potential risks that you don't need to have. You can still use a reverse proxy inside the VPN and use your own DNS server that spits out that internal address to your devices for your various applications. If you absolutely, positively must have something exposed directly, put it on it's own VLAN and with no access to anything you value.

[–] [email protected] 8 points 3 days ago* (last edited 3 days ago) (7 children)

I don’t even bother with the internal DNS server. I just set my A records in Cloudflare to point to the private IPs

[–] [email protected] 4 points 3 days ago (4 children)

Do the private IPs not change at all? Or can you handle that automatically?

I have next to no experience, but I’m pretty sure that wouldn’t work for me since my IP changes? Idk

[–] [email protected] 4 points 3 days ago (1 children)

You can either set a DHCP reservation in your router, or manually set the IP on the device.

When I say private IP, I’m referring to the internal IP e.g 192.168.1.X

Means internally I just go to the domain without having to remember the IP I set.

[–] [email protected] 1 points 3 days ago* (last edited 3 days ago)

Oooh. That makes more sense, thank you.

I somehow thought you’d meant your global IP addresses, lol

load more comments (2 replies)
load more comments (4 replies)
load more comments (25 replies)