16 ms·
You may not need Cloudflare Tunnel. Linux is fine
- mcovalt 5y agohttps://web.archive.org/web/20220408055110/https://kiwiziti.com/~matt/wireguard/ https://web.archive.org/web/20220408055110/https://kiwiziti.... in case my power goes out or something
- jgrahamc 5y agoYou could put a CDN that does caching in front of the site and not worry about a power outage.
- mcovalt 5y agoHey look, my crush I wrote about! Naw, that's no fun. The better solution is buying a Honda generator or maybe trying to build one.
- jgrahamc 5y agoSorry, I couldn't resist.
- diamondo25 5y agoA CDN like CloudFlare with "Always Online"?
- deleted 5y ago[deleted]
- pabs3 5y agoI'd use a Tor Onion service over Cloudflare.
- 2000UltraDeluxe 5y agoTOR is underrated for breaking through NAT and provide a link home. It's not really an alternative if you want to host stuff yourself, though.
- ZoomZoomZoom 5y agoI used Tor Hidden Service to access an SSH port to a router in my home network and it works great... as long as Tor works. Being constantly under attacks and censorship makes Tor unreliable.
- kreetx 5y agoA downside with tor is that it is slow (or, was slow at about five years ago when I tried it, even with a low hop count).
- fxtentacle 5y agoI believe that to be true for most cloud offerings these days. If you find the open source project that they are using internally, a cheap Linux VPS is all you need to copy it. Yes, it won't scale to a million visitors, but then again, your purse won't scale to a million cloud visitors either.
- phkahler 5y ago>> Yes, it won't scale to a million visitors His simple static page seems to be taking the load of making the front of HN.
- fxtentacle 5y agoThat's probably only 2k-3k unique visitors, though.
- withinboredom 5y agoPer minute.
- tick_tock_tick 5y agoYes? The whole point is it's barely any traffic for a static site.
- fxtentacle 5y ago3k unique visitors per 10 hours
- brimble 5y agoI think people sometimes forget that tons of high-traffic sites used to be served from what would, today, be laughably weak machines and very simple architectures (say, just a failover second machine, or LB between just two servers, or sometimes even just a single YOLO server). No, they didn't get the traffic of a modern Google, say, because not as many people were online, but they did receive as much traffic as an upper-mid-tier modern site, and served it with machines weaker than a lot of modern phones. Just serving HTML and small media files is something computers are very good at, if you get out of their way.
- Animats 5y ago"Get yourself a cheap VPS near you and make sure you get two IPv4 addresses." If you're going to rent a server, why not just put your stuff there?
- naoqj 5y agoBecause putting your stuff there is expensive because of the necessary disk space, not to mention the company or LE can take your data from there easily.
- MrJohz 5y agoI ran a Minecraft server off a raspberry pi like this for a while. I had the VPS for another project, so stuff was running there, but Minecraft was just too much for it. On the other hand it could run on my pi, but my router wouldn't let me open that up to the internet. So I used SSH to tunnel from the VPS to the pi and it worked pretty well. It's also a lot easier to show off demo projects like this - you don't need to copy everything to your VPS and figure out how to run it, you just need to have it running on your local machine (e.g. your development laptop) and let other people access that. Obviously that's not a great system for anything long-term, but if you just want to show a friend something you've made, it's quite useful.
- throwaway48375 5y agoWhat kind of VPS is less powerful than a pi?
- iolo 5y agoPi 4 has a dedicated quad core ARM A72 @ 1.5Ghz and up to 8GB of RAM. A $5 VM from Digitalocean has 1vCPU and 1GB of RAM.
- capableweb 5y agoAlso, Raspberry Pi 4 (Model B) costs ~35 USD as a one-time cost, the 5 USD VM from DigitalOcean is per month. If you're planning to run something for longer than ~7 months, you'll save money (and get better CPU/IO [not network probably though] performance) by going with the Pi instead of DigitalOcean.
- easton 5y agoI do something similar with a reverse proxy on a DO droplet (Pomerium so I don’t have to think about certs or SSO) which is on a ZeroTier network along with a box at home. I probably wouldn’t have bothered setting it up if Tunnel had been free at the time, but it’s very convenient to have a random box to do stuff on outside the network (and to be able to access services at home without having to install ZeroTier).
- omnicognate 5y agoWhat's actually being done here is buried in a mass of analogies. AFAICT it's: * Exposing a server running on the home network (behind NAT on a dynamic IP) to the internet. * Doing so by renting a cheap VPS and using wireguard to forward traffic to the server at home. I love wireguard and use it continuously. My phone has always on wireguard to my home network so all my phone traffic goes through my home router/dns, I can access the various private servers I have at home, get dns based ad blocking etc. I use an ISP that give me a static IP so it was easy to set up. It works like a dream. That said when I want to run a public server I just rent a VPS and run it on that. I don't want anything I don't own initiating connections to anything on my home network in any way.
- BlueTemplar 5y agoThese days, your ISP would (hopefully) give you at least a whole (static) /56, so you can always reserve some prefixes for your not-really-home networks ? https://www.ripe.net/publications/docs/ripe-690#4-2-3--prefixes--longer-than--56 https://www.ripe.net/publications/docs/ripe-690#4-2-3--prefi...
- omnicognate 5y agoI have a static ip4 address, but were that not the case yes I'd take the ip6 plunge. Edit: Which I could do as my ISP and mobile network both support ip6. Y'all need better ISPs :D
- folkrav 5y ago> Y'all need better ISPs :D If only there was one around here, but alas, they're all basically the same 2-3 ISPs - a couple of main ISPs, then smaller ones who are just using their network and renting bandwidth.
- mort96 5y agoHahahahaha your ISP supports IPv6 already?
- jart 5y agoIn China you need a VPN in order to be able to consume information that's blocked by the great firewall. In America you need a VPN to be able to serve information that isn't blocked by the great firewall. Which system is the more reliable?
- isaacimagine 5y ago> In America you need a VPN to be able to serve information that isn't blocked by the great firewall. I'm pretty sure this is true in China too. What point are you trying to make?
- btgeekboy 5y agoThe Chinese firewall is a government run censorship apparatus. The American one you refer to is standard network security (or CGNAT out of necessity) on networks you don't 100% control, but I'd hardly call it a "great firewall." Those aren't really comparable. What does "reliability" mean in this context?
- msla 5y ago> In America you need a VPN to be able to serve information that isn't blocked by the great firewall. Empirically false.
- dancsi 5y agoThis looks neat, but I don't really understand how it works. I imagine that the DNS record is pointed towards the VPS, and the VPS just forwards all traffic to the actual server via wireguard?
- sudhirj 5y agoPretty much, yes.
- zokier 5y agoThis feels very much like the classic dropbox vs ftp+svn comment. I don't think the point of CF Tunnel is some novel technical capability or performance, but convenience and having a service you don't need to worry about and not have a server that you need to maintain.
- ghoshbishakh 5y agoAbsolutely. Look at ngrok. One command and boom I have a public address. People pay to avoid the headache.
- kevsim 5y agoNgrok is one of those things that I know isn't that complex but I gladly pay for it year after year because I just don't want to deal with that stuff and it rarely lets me down.
- stingraycharles 5y agoExactly, I’m running Cloudflare’s tunnel as a sidecar container in the kubernetes pods that need to be reachable from the internet. It’s a very convenient way of doing so, CloudFlare can even load balance it on their side, and it has been very stable. It’s the convenience of it that is the big selling point to me.
- DenseComet 5y agoYep. The hardest part of a k8s cluster at home is ingress and storage. Previously I was using metallb and port forwarding, which worked ok, but not very reliably for various reasons. A cloudflare tunnel sidecar completely solved the ingress issues.
- oneplane 5y agoIt's also a pattern to commodify things that used to be basic knowledge for any systems administrator. That is both good and bad; new generations of computer people don't know how their systems work or how to actually do certain things, on the other hand, it makes it more accessible to more people.
- Jiejeing 5y agoI don’t really get the point of fronting and even caching for 99% of people out there. The analogies don’t really do it for me, do you expect to get DDoSed on a daily basis? That has not been my experience in 15 years of home-hosting. If you have FttH you will be ok in most situations. The only upside I can see is that it can protect against targeted attacks on the crappy modem provided by my ISP. But if such an attack is widespread it will probably hit me anyway.
- dx034 5y agoThe advantage with cloudflare tunnel is that you can block all incoming requests via firewall. That alone drastically reduces your attack surface. And your actual location and IP is obfuscated via Cloudflare. I'd imagine these two points are much more important than DDOS Protection and Caching for most people.
- funman7 5y agoI was hoping there wouldn’t be a renting a vps in the story.
- password4321 5y agoNo mention of forwarding a port on your home router + dynamic DNS here in the comments yet. I would appreciate recommendations for dynamic DNS providers.
- 3np 5y agoBasically any decent normal DNS provider (eg Porkbun or Gandi) will have shorter TTL than most forwarding nameservers anyway, and have APIs that are fairly straightforward.
- smorrebrod 5y agoI do dynamic DNS by updating Gandi LiveDNS entries thanks to their API and a botched shell script.
- freeone3000 5y agoNamecheap's DNS provides dyndns support. It's now just an add-on to your DNS or domain name provider.
- scns 5y agohttps://www.duckdns.org/about.jsp https://www.duckdns.org/about.jsp
- dx034 5y agoDid that in the past but I'm kind of glad these free tunnels exist now. I always felt a bit uncomfortable forwarding ports in my home setup, esp if it wasn't to a linux server that I could harden reliably.. For me, NAT was always a layer of security, much like a firewall.
- shukantpal 5y agoI’ve setup ddns with digitalocean
- tssva 5y agoI use Cloudflare for my DNS. ddclient has built-in support for updating Cloudflare DNS or if you have to use a device which only supports the dyndns protocol the DNS-O-Matic service can be used to update Cloudflare DNS. Also many ACME clients have built-in support for using Cloudflare for DNS-01 challenge verification to get certificates from Let's Encrypt.
- Tobu 5y agoA port forwarding utility like rathole/tunnelto (tobaru/frp…) seems simpler than the proposed WireGuard setup.
- randomtwiddler 5y agoYou can just use ssh also. Which I have found to be not only easier but has better performance for a simple port forward case.
- prmoustache 5y agoYou can do that with iptables if you don't need traffic to be encrypted between vps and internal server.
- dspillett 5y ago*> Get yourself a cheap VPS near you and make sure you get two IPv4 addresses. IPv4 isn't cheap these days, so those two requirements are not as easy to attain. Given they specifically mention Hetzner who significantly increased their prices for additional addresses in the middle of 2021 I'm going to assume this page was written some time ago. Using a single IPv4 should be fine - just port forward that over the VPN. Given most of what people want to publish this way these days is wrapped in HTTP(S), if you want something both local to the VPS and back on your home⁵ server, use nginx or similar as a proxy to split traffic by [sub]domain. You probably want SSH to both the VPS to manage it and to the proxied home server, but that can be done many ways using just SSH¹² or better still use wireguard to connect to the VPN from your remote location and simply route SSH to the home machine over its VPN connection³. But using something like wireguard is the way to go, many similar examples use SSH tunnels which while fine for some things (I use them all the time) will have additional performance issues in some cases due to TCP-in-TCP congestion management conflicts, and do not deal with temporary connectivity blips (not uncommon on home connections) as gracefully. ---- [1] Though most of these suffer from the TCP-in-TCP issues, that might be less significant than for hosting an app or other service but you are already using wireguard/similar so why not use it some more? [2] The pure SSH options, which have different [dis]advantages depending on key management, interaction with other tools that wrap SSH, and so forth, include: just manually double-hopping, using the -J option to jump through in one command, configure an alternate named host in your .config using ProxyCommand to configure the second hop, and at least one other that has slipped my mind ATM. [3] I would still be inclined to have a pure SSH option available as well, in case the VPN is blocked if I find myself constrained by a funky network at a client/other site that isn't limited enough to also block SSH⁴ [4] If you want to go a little more hacky to deal with networks that block try SSH completely but are fairly open wrt HTTPS, there are a couple of options there. I've used shell-in-a-box previously though that seems to be unmaintained ATM, Bastillion may be a better option though I've not tried it myself. Be careful how you secure these tricks if you use them… [5] I've referred to a “home server” throughout as that is the most common use for this sort of thing in my experience, but it all applies to any other situation where you want to host something on a box that is NAT encumbered and/or not on a fixed IP address.
- gregoriol 5y agoAlmost everything Cloudflare does can be done as self-hosted, it's mostly a matter of your time vs your money
- api 5y agoThat applies to a huge amount of SaaS and cloud.
- Hardik_Shah 5y ago
- candiddevmike 5y agoCloudflare tunnels are INCREDIBLE for local development. Get a domain name for testing on Cloudflare, give your developers access to it, boom everyone gets an internet-accessible hostname wherever they are without having to mess with firewall rules. You can test external API calls coming into your apps and let other folks access your dev environment, all self-service for your devs.
- bravetraveler 5y agoNebula is probably a better choice for something a little longer term -- bandwidth isn't funneled through one VPN gateway. Once the clients talk to the lighthouse to build the tunnel they communicate directly https://github.com/slackhq/nebula https://github.com/slackhq/nebula
- dinosaurdynasty 5y agoI've done this, I really wish I could recommend this. When the NAT punching works it's great. However (AFAIK) there's no option to use the lighthouse as a backup for when NAT punching fails, and when NAT punching inevitably fails it just doesn't work, even when everything can talk to the lighthouse.
- bravetraveler 5y agoAh, interesting! I've only used this on very conventional networks, so I haven't quite noticed this difficulty. With this in mind, it is a little harder to generally recommend.
- juandjara 5y agoYou are missing out on the fact that Cloudflare Tunnel is free. You don't need to pay for an vps nor an extra IP, plus, you don't need to learn about tunneling software such as Wireguard or Zerotier
- stevenicr 5y agofree as in dollars, but not free as in privacy and solidifying monopoly. although clicking the pricing tab - it says hobby / personal use free / "For professional websites that aren't business-critical." - $20 /month and "For small businesses operating online." - $200 / month custom price for non-small business.. Although I did not see tunnel there specifically, and the tunnel page just has a 'download the paper' CTA - so it's hard to know what price one should be paying, on top of the first two things of course.
- drunner 5y agoIf you ran something like Headscale, Netmaker, or Netbird (WG mesh network managers), then all your traffic is direct point to point and you don't need to care about the limits imposed by a VPS.
- johnklos 5y agoThis is actually very simple in concept and is just as simple or even simpler to do with tinc (https://tinc-vpn.org https://tinc-vpn.org). Since I can use tinc in bridge mode, I can run tinc on the upstream server and on a local machine which then provides access to several physical machines without running extra software on each of those machines, which is particularly useful for machines that are resource limited, like my Macintosh LC II and LC III+: http://elsie.zia.io/ http://elsie.zia.io/ It'd be nice if it weren't so difficult to get public addresses.
- scottlamb 5y agoI wouldn't use tinc, particularly version 1.0. Its protocol is weak. [1] (Every time I see tinc mentioned, I'm frustrated 1.1 hasn't been released. I made contributions to it 15 years ago that still haven't been released.) [1] https://www.tinc-vpn.org/pipermail/tinc-devel/2006-January/000277.html https://www.tinc-vpn.org/pipermail/tinc-devel/2006-January/0...
- johnklos 4y agoI'm running 1.0.36, but I do see that 1.1pre18 is an option. I'll have to try that out some time.
- mamcx 5y agoWell, this is what I have believed, but I can't make work wireguard for my setup: https://serverfault.com/questions/1098093/how-setup-wireguard-nixos-to-access-servers-postgresql-nginx-from-workstati https://serverfault.com/questions/1098093/how-setup-wireguar... The combination of wireguard + firewalls and the complexity of iptables is not intuitive at all...
- mcovalt 5y agoI see you use NixOS. Check out these NixOS modules for setting up what I'm talking about: https://gist.github.com/mcovalt/c1fc476385bd2b65513809c5bc6895c2 https://gist.github.com/mcovalt/c1fc476385bd2b65513809c5bc68...
- randombits0 5y agoAutoSSH and port forwarding. You can even forward points behind a NAT. I use this technique to get to “my” box on “your” network, no firewall config changes, no issues, it “just works”. Now I’ve never tested this with a public/high(er) volume service but it lets me pen test internal networks just like I’m sitting in the NOC. And my “VPS” host can handle dozens of simultaneous connections to dozens of endpoints. I have SSH listening on a non-standard port (eliminates 95% of the script-kiddie noise) and cert auth. That’s the only listening service on the VPS box. I am familiar with some “TCP-in-TCP” problems but I’ve never had any. If it falls down, it just reconnects when traffic can pass again. So what am I missing?
- creeble 5y agoI use this technique as well, and don’t understand enough about wireguard to know why it would be better. AutoSSH has been 100% reliable for me, with any lost connection restarting without conflicts, duplication, or error. My AT&T connection is definitely not five nines, so any tunnel needs to deal with restarts very well.
- quaintdev 5y agoI wish we all switch to IPv6 asap so that we can avoid tunnels, NATs and all the mess that comes with it.