4 ms·
I tried to have a setup similar to this during covid but ended up with a bit of a mess. What I wanted was a home server that used X forwarding to forward servi
by grep_name 6y ago
I tried to have a setup similar to this during covid but ended up with a bit of a mess.
What I wanted was a home server that used X forwarding to forward services to my VPS, which also had some images running in a docker-compose stack that I wanted to have more robust uptime than my home server. I ended up being unable to get traefik to pick up on the x-forwarded ports, and ran into SSL certification issues that seemed insurmountable wrt hosting jellyfin this way.
Does anyone here use a hybrid home-server / VPS setup like this and know of a better setup? I prefer x port forwarding because I move about once a year and don't always have access to router settings
- megous 6y agoYes, I use wireguard to link VPS with an array of computers in my home via point to point tunnels. This solves the "my home IP not being completely static" problem, because wg handles roaming quite gracefully. And then I just use either DNAT or nginx reverse proxy to proxy https to some http ports at home, depending on the service.
- grep_name 6y agoInteresting! I've never used wireguard before. When you link it with the VPS, is it able to behave as if ports from your home network are running natively on the VPS? I'll look into using DNAT/nginx, but I really do like having everything in a format where all the configuration is self contained in code and can be spun up / down easily, and I'm not sure if I can accomplish that using those tools
- megous 6y agoYou'll see a wireguard network interface on all the connected devices, and you can configure some private address subnet on it, like 192.168.1.0/24 and give the devices some addresses from this range. Then you can just talk between any of the devices via this subnet. Wireguard will securely tunnel the traffic. https://www.wireguard.com/ https://www.wireguard.com/ DNAT is just a concept https://en.wikipedia.org/wiki/Network_address_translation https://en.wikipedia.org/wiki/Network_address_translation You can set it up using iptables or nftables. You don't need to use nginx, use http reverse proxy you know.
- ex3ndr 6y agoI use zerotier + haproxy. Works well except some fluctuations in zerotier.