Replying to @⁨pineapplelover@lemmy.dbzer0.com⁩

You will.

Anything you expose should be designed for it (e.g. not jellyfin). You should have a WAF configured for the type of service you’re hosting. You can’t just drop one and have it magically protect you, they take configuration. Same with fail2ban.

And you should have these services in a DMZ, so that a compromise in one doesn’t provide an entry point to other resources on your network.

Replying to @⁨pineapplelover@lemmy.dbzer0.com⁩

Keep in mind that you wouldn’t route local traffic through it, so everything watched at home would be direct and not count.

I have a $5/mo VPS with OVH and they allow unlimited bandwidth within reason. Unless you have multiple households streaming from your server all the time, likely totally fine. If you do end up with one relative streaming 24x7, then I would look at installing the tailscale app on their TV and configuring things to connect that one user direct to your home server.

A VPS takes some learning, but IMHO, it is the “correct” answer and worthile learning.

Replying to @⁨pineapplelover@lemmy.dbzer0.com⁩

There are constant scanners on any site and scrapers on websites, but it is far less of a problem than you would imagine unless you have a big wiki or software forge with hundreds of nested commit history pages for them to spider into.

I also run private servers on hidden subdomains (with wildcard certs and DNS entries), so the low effort scanners never bother them.

DDOS attacks take money, so they aren’t typically going to go after some random homelabber. If it did happen, I would either just shut it off for a while or change the VPs IP. Ovh also has some of its own ddos protection.

Replying to @⁨spork@pawb.social⁩

Same but nftables and also crowdsec.

Also I had some trouble with the wireguard tunnel dropping lots of packets, which resulted in my services not loading 50% of the time. I did a lot of suggestions at the same time so I’m not sure which one fixed it but here is a list in case anybody has similar troubles:

  • lowering MTU
  • routing ipv6 through the tunnel as well
  • rewriting nftables rule order

(will update after work, notes are at home)

Replying to an earlier post

Pangolin officially says on their site :

Pangolin generally requires minimal resources to run effectively. A basic VPS with 1 vCPU, 2GB RAM, and 8GB SSD is sufficient for most deployments.

If you choose a VPS with only 1GB RAM, you may need to create swap space to avoid memory pressure during installation, updates, or periods of higher traffic.

I’ve got a 1 vCPU, 1GB RAM, 25GB Disk droplet for $6/mo and have no issues for my limited home use. Updates don’t really take a noticeably long time or anything, it takes maybe 45 seconds to fully bring up the docker container again after an update. But it runs just fine.

Pangolin DocsChoosing a VPS - Pangolin DocsCompare hosting options and find the best VPS for your Pangolin deployment

Replying to @⁨pineapplelover@lemmy.dbzer0.com⁩

Authentication & single sign-on service

Plugged into Reverse proxy, routing to each service by name

With a wild card cert so there are no name leaks.

Make your urls unexpected. If your domain is example.com, don’t put your jellyfin server at jellyfin.example.com. Instead, use watch.example.com or telly.example.com. Anything that’s memorable to you about what the service is without using a specific brand name.

With a wildcard dns record to point all names to your IP, and a wildcard certificate that works for all names loaded on your load balancer, it becomes hard for a hacker to know what name to use to get the load balancer to send them to the service they want to hack.

If you then use a sso tool like traefik’s ForwardAuth middleware, you won’t even get to the service until you’ve first authenticated.

Replying to @⁨RanchBranch@anarchist.nexus⁩

I have seen netbird pop around every now and again. I might try out their cloud free version first and if I like it I might try self hosting it.

So you host netbird on a vps you rent and that is used for reverse proxy? So with that reverse proxy I can have my home server be publicly accessible and I can have friends log in to my jellyfin server without having to connect to my tailnet.

My last concern is security. How is this set up good for making sure I don’t just get constantly botted and exploited?

Replying to @⁨innocentzero@kbin.earth⁩

By all means correct me if you know more, but what I tend to see is one or two people here saying that Jellyfin devs don’t recommend exposing it publicly, only to be corrected by looking at the actual documentation. I suspect those cautioning against it are on outdated information and that Jellyfin carries much the same risk as exposing any other service.

Replying to @⁨irmadlad@lemmy.world⁩

That first page says exposing it to the Internet is “not recommended”. Putting a reverse proxy in front of it does not meaningfully change the security posture. A malicious request to http://jellyfin.homelab.com/exploitable-page will be sent to jellyfin in effectively the same way, whether through a reverse proxy or not. You would need a WAF set up specifically to look for relevant exploit attempts.

github.com/jellyfin/jellyfin/issues/5415

Those are some outstanding known vulnerabilities, most of them unfixed. They are not particularly severe, but it shows that thorough security is not a priority for the jellyfin devs.

Collection of potential security issues in Jellyfin This is a non exhaustive list of potential security issues found in Jellyfin. Some of these might cause controversy. Some of these are design fla...GitHubCollection of potential security issues in Jellyfin · Issue #5415 · jellyfin/jellyfinCollection of potential security issues in Jellyfin This is a non exhaustive list of potential security issues found in Jellyfin. Some of these might cause controversy. Some of these are design fla...by GermanCoding

Replying to @⁨frongt@lemmy.zip⁩

Probably the number one recommendation I see in self hosting communities is to not open ports directly (other than for a reverse proxy). It seems like a common recommendation no matter the service. To be clear: I am a beginner. I know very little about this, but I’ve spent months learning. I can’t say you’re wrong, but I don’t think you’ve made a convincing argument for me to actually understand why Jellyfin is unsafe to expose to the internet compared to any other service.

Replying to @⁨innocentzero@kbin.earth⁩

While Netbird is generally just one of the many alternatives to Tailscale, they also do have a Reverse Proxy feature that allows access without a Netbird client. Haven’t tested it yet, seems to be in beta.

docs.netbird.io/manage/reverse-proxy

docs.netbird.ioReverse Proxy - NetBird DocsExpose internal services to the public internet with automatic TLS, authentication, access restrictions, and traffic routing through the NetBird mesh network.

Replying to @⁨pineapplelover@lemmy.dbzer0.com⁩

I do this albeit with Tailscale. Netbird/Tailscale would act as a node of your VPN and you can configure reverse proxy routes (via tailscale serve or Netbird’s equivalent) from the VPS edge to the homelab. You can even do SNI passthrough and have TLS terminated at your home, if you want, though this can be a bit slower

Alternatively you can even expose stuff via their servers. Tailscale Inc calls this service Funnels, and Netbird should have similar offerings. It’s kinda like Tunnels but you gotta use their domains, so a VPS acts greater as a dedicated entrypoint.

Lastly yes you’d be exposing the service to the general public internet, so some basic security is needed. Netbird has a Crowdsec module integration, might wanna look at that one and set up rules/detections. Consider putting extra auth in front of Jellyfin, use Authelia or something with an auth screen. And only expose the stuff you need, not your internal dashboard or whatever admin UI.

Replying to an earlier post

Yup! They can either connect to your Netbird meshnet (ie, similar a tailnet) or you can reverse proxy it out to the internet (no tailnet needed)

I saw a couple comments below concerned about security, one of the nice things about Netbird is that they have reverse proxy auth built in if you want. Some stuff (Navidrome or VoidAuth for instance) only has geolocation locked down (US only) but other things that I’m either more concerned about or don’t necessarily trust being open (Paperless or Komodo for instance) have Netbird Auth and VoidAuth as sign in options before it will let me open the page. Its worked flawlessly so far, and has kept my sanity intact because I wanted some stuff publically accessible without it being OPEN.

As far as being hammer fucked, it has CrowdSec and Geolocation lockdowns so you can set it to only accept traffic from ONE location and the Crowdsec also catches everything.

Replying to @⁨pineapplelover@lemmy.dbzer0.com⁩

Why do you want to expose them? This might limit the solutions.

The way I do this is in 2 different ways:

  1. Tailscale, my server connects to tailscale so all I have to do is connect to it from my phone and I can access things remotely easily. This is the best for most things, but has the downside that others can’t access it as easily

  2. I have a VPS (two actually at the moment as I’m switching providers from Vultr to IONOS) that also connects to tailscale so it can access my home server through it, then using Caddy I expose the services on a subdomain of the VPS. This is what I do for things that others might want to access, or things I don’t want to have to connect to tailscale to access.

If you’re going down the second route do consider that you will need to:

  • Add something like fail2ban or crowdsec to the VPS as attacks will happen.
  • Same reason you should add a dedicated authentication on front of most things. While I don’t expect the auth on services to be weak, it might be more vulnerable than a dedicated authentication service. You should look into Authelia, Authentik, or similar to put on front of your services so any attacker would first have to pass that to even get to your services.

Replying to @⁨pineapplelover@lemmy.dbzer0.com⁩

I can’t answer your question as I haven’t taken that step yet, everything is still confined to my LAN.

Here’s a similar thread from last month that had a lot of replies. Hopefully will be some useful info there for you. Good luck!

lemmy.zipIs they're an easy way to make my Jellyfin accessible outside of my home network for free? - Lemmy.zipI have docker installed, but only have a vague idea of how it works. Back in the day, I would just port forward, but even then, I would need a static IP somehow. I have heard a reverse proxy is an option, but that is an entirely new topic to me. Surely there is an easy way to access Jellyfin outside of my home network that I’m just missing. *Edit: I am blown away by all the help and support! I currently have tailscale running, and I’m in the process of purchasing a domain. Thanks everyone!

Replying to @⁨pineapplelover@lemmy.dbzer0.com⁩

Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

Fewer Letters More Letters CA (SSL) Certificate Authority CSAM Child Sexual Abuse Material DNS Domain Name Service/System Git Popular version control system, primarily for code ISP Internet Service Provider SSD Solid State Drive mass storage TLS Transport Layer Security, supersedes SSL VPN Virtual Private Network VPS Virtual Private Server (opposed to shared hosting) nginx Popular HTTP server

[Thread #74 for this comm, first seen 6th Aug 2026, 09:00] [FAQ] [Full list] [Contact] [Source code]

Hachyderm.ioImran Nazar ~ عمران نزر (@Two9A@hachyderm.io)2.8K Posts, 301 Following, 262 Followers · Front-end #typescript developer and general keyboard tapper; author of Internet RFC 7168 (Hypertext Coffeepot Control Protocol for teapots); occasional plumber, more than occasional #c64 #retrocomputing enthusiast, terrible at classical #piano. Header photo is a verdant scene looking over the landscape near Buxton, England, taken from a single-track country road.

Replying to an earlier post

Netbird reverse proxy: https://docs.netbird.io/manage/reverse-proxy

It’s like Tailscale, but Open Source. You can self-host the components, if you want. I just use the cloud offering. I have a domain name that resolves to my server. There’s different ways you can do auth. I just hard coded an allow list of IPs. Otherwise, devices in my Netbird network can use the private IP.

docs.netbird.ioReverse Proxy - NetBird DocsExpose internal services to the public internet with automatic TLS, authentication, access restrictions, and traffic routing through the NetBird mesh network.

Replying to @⁨pineapplelover@lemmy.dbzer0.com⁩

I have a Flint 2 with a vanilla install of openWRT, that hosts wireguard. I have 2 static IPs, because I thought hey running my own mail and smtp services cannot be that hard (turns out yes it is hard and not worth the time to deal). Any who I have Wireguard running on my firewall and Caddy running on one of my pi’s, it gets TLS from lets encrypt.

I have a couple of domains that Caddy uses to point things out to the world or my LAN/vLANs/VPNs. Very few of the things go out to the whole world, but if I wanted to share say a Jellyfin server with someone I could wip up a VPN that only allows Jellyfin through and points DNS to my piholes. Why do I mention my ad blocker? I mention pihole because that what hosts the A records to my domain names that Caddy can serve up, I do not remember why I set it up like this, I would have to look through my notes but pihole points “service”.domain1or2.xyz to caddy which than points to the right service.

Edit: went and looked A records are hosted on pihole for my LAN/vLANs/VPNs to prevent things needing to go out and come back just to tell devices where on my LAN services are.

Replying to an earlier post

If you have a UniFi gateway, you can enable region based firewall on your port forward ip. This then blocks most of the world (incoming) as a first step. Then like others suggest, a reverse proxy. I use Caddy built with the Maxmind geolocation plugin, and I also run fail2ban on my exposed service.

I figure if you don’t need most of the world accessing your services, it is best to exclude them

Replying to @⁨matron1049@lemmy.dbzer0.com⁩

To some degree yes. I ran an experiment to see and found there is just too much of the existing internet infrastructure not implementing IPV6 for this to be reliable. For instance, you can’t use it for email intake because only 2 major players do IPV6.

You still get dynamic assignments from the ISP and have to automate keeping your AAAA records up to date.

The short answer is, it depends. For what OP is doing here, I expect it would work.

If anyone else has messed with this, I’d love to here about it. Might be good as it’s own post.

Replying to @⁨pineapplelover@lemmy.dbzer0.com⁩

I bought myself a Synology disk station and a domain.

Yes I use Cloudflare for DNS so I can get a wildcard domain cert using ACME.

I use the Synology supplied login portal as a web application firewall for every site I want to host with the wildcard SSL cert. Like bar.mydomain.com, mealie.mydomain.com, etc.

The Synology routes the traffic to the services hosted on other services within my network.

Anything else I don’t want open to the public web, I use the Synology supplied OpenVPN server to connect.