I want to expose my services publicly on my own domain name, how would you guys do that?

I have seen people using Cloudflare, but I don’t want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I’ve done some rough researching.

What do you guys do?

  • AllYourSmurf@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    16 hours ago

    Authentication & single sign-on service

    Plugged into Reverse proxy, routing to each service by name

    With a wild card cert so there are no name leaks.

    Make your urls unexpected. If your domain is example.com, don’t put your jellyfin server at jellyfin.example.com. Instead, use watch.example.com or telly.example.com. Anything that’s memorable to you about what the service is without using a specific brand name.

    With a wildcard dns record to point all names to your IP, and a wildcard certificate that works for all names loaded on your load balancer, it becomes hard for a hacker to know what name to use to get the load balancer to send them to the service they want to hack.

    If you then use a sso tool like traefik’s ForwardAuth middleware, you won’t even get to the service until you’ve first authenticated.

    • Helix 🧬@feddit.org
      link
      fedilink
      English
      arrow-up
      5
      ·
      edit-2
      14 hours ago

      If you use TLS like you should, your domains will be on the internet in the certificate transparency log. Yes, you should use a wildcard cert if you want this security by obscurity, but it’s still security by obscurity.

      • frongt@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        6 minutes ago

        Or run an internal CA, if you’re the only one accessing the services.

      • AllYourSmurf@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        8 hours ago

        Of course. The goal here is to not advertise. Make it hard for the bots to find you. With these steps, they can try your IP, but there’s nothing directly on your IP.

        You still need proper security. Authentication is a good start, and it has the extra effect of adding an extra layer to prevent the bots from going further if they get lucky and guess a host name.