Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Wondering if anyone from the #selfhosted crowd could help me with some suggestions for alternatives to Cloudflare tunnels.

Wondering if anyone from the #selfhosted crowd could help me with some suggestions for alternatives to Cloudflare tunnels.

Scheduled Pinned Locked Moved Uncategorized
selfhosted
6 Posts 4 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • tobraha@infosec.exchangeT This user is from outside of this forum
    tobraha@infosec.exchangeT This user is from outside of this forum
    tobraha@infosec.exchange
    wrote last edited by
    #1

    Wondering if anyone from the #selfhosted crowd could help me with some suggestions for alternatives to Cloudflare tunnels. Main things I run behind tunnels now are Vaultwarden and Immich.

    Anyone using some similar service? Or am I better off just fronting everything myself?

    spike@morph.oksocial.netS joseadias@social.diaslan.comJ dergilm@mastodon.socialD 3 Replies Last reply
    0
    • tobraha@infosec.exchangeT tobraha@infosec.exchange

      Wondering if anyone from the #selfhosted crowd could help me with some suggestions for alternatives to Cloudflare tunnels. Main things I run behind tunnels now are Vaultwarden and Immich.

      Anyone using some similar service? Or am I better off just fronting everything myself?

      spike@morph.oksocial.netS This user is from outside of this forum
      spike@morph.oksocial.netS This user is from outside of this forum
      spike@morph.oksocial.net
      wrote last edited by
      #2
      Ideally, VaultWarden should be run on a private VLAN with local LAN accessibility and VPN (or ssh-tunneled) remote connectivity; it shouldn't be exposed to the Net unless you have no other option.

      I probably wouldn't expose Immich to the Net either, unless you need to share with folks (relatives ...) who can't handle a VPN.

      The Algo VPN server configurator is pretty good at setting up VPN servers, though I've had to write some scripts to make managing users on them less annoying.

      (This may not be useful, since I dunno why you're using Cloudflare; I'd be happy to try to be more useful if you want to detail your use case more.)

      @tobraha
      tobraha@infosec.exchangeT 1 Reply Last reply
      0
      • spike@morph.oksocial.netS spike@morph.oksocial.net
        Ideally, VaultWarden should be run on a private VLAN with local LAN accessibility and VPN (or ssh-tunneled) remote connectivity; it shouldn't be exposed to the Net unless you have no other option.

        I probably wouldn't expose Immich to the Net either, unless you need to share with folks (relatives ...) who can't handle a VPN.

        The Algo VPN server configurator is pretty good at setting up VPN servers, though I've had to write some scripts to make managing users on them less annoying.

        (This may not be useful, since I dunno why you're using Cloudflare; I'd be happy to try to be more useful if you want to detail your use case more.)

        @tobraha
        tobraha@infosec.exchangeT This user is from outside of this forum
        tobraha@infosec.exchangeT This user is from outside of this forum
        tobraha@infosec.exchange
        wrote last edited by
        #3

        @spike thanks for the tips! I do have Immich locked down behind mTLS, but I do share vaultwarden with family members for whom mTLS would be much more difficult to manage.

        I definitely don't like having vaultwarden open like this. I do have a Wireguard server setup which might be an easier way to lock down access to my family members. wg has pretty good support across mobile platforms for app specific routing and such.

        Your advice is helpful! I have these tiny humans to take care of that demand most of my brainpower 🤣

        1 Reply Last reply
        0
        • tobraha@infosec.exchangeT tobraha@infosec.exchange

          Wondering if anyone from the #selfhosted crowd could help me with some suggestions for alternatives to Cloudflare tunnels. Main things I run behind tunnels now are Vaultwarden and Immich.

          Anyone using some similar service? Or am I better off just fronting everything myself?

          joseadias@social.diaslan.comJ This user is from outside of this forum
          joseadias@social.diaslan.comJ This user is from outside of this forum
          joseadias@social.diaslan.com
          wrote last edited by
          #4

          @tobraha I run a wireguard VPN to get to my passbolt password storage. Passbolt has no exposure to the internet and I can do a wireguard "split tunnel" where only my network resources go through the vpn or I can send all traffic back to my home network. I do have resources that are proxies by nginx (nextcloud, subsonic music, plex, and soon mailcow). It is doable but it takes a good infrastructure and baby steps.
          Let me know if you have questions...

          1 Reply Last reply
          0
          • tobraha@infosec.exchangeT tobraha@infosec.exchange

            Wondering if anyone from the #selfhosted crowd could help me with some suggestions for alternatives to Cloudflare tunnels. Main things I run behind tunnels now are Vaultwarden and Immich.

            Anyone using some similar service? Or am I better off just fronting everything myself?

            dergilm@mastodon.socialD This user is from outside of this forum
            dergilm@mastodon.socialD This user is from outside of this forum
            dergilm@mastodon.social
            wrote last edited by
            #5

            @tobraha maybe have a look at Pangolin https://github.com/fosrl/pangolin
            I’m using that with great satisfaction.
            Alternatively netbird might be what you’re after https://netbird.io/

            tobraha@infosec.exchangeT 1 Reply Last reply
            0
            • dergilm@mastodon.socialD dergilm@mastodon.social

              @tobraha maybe have a look at Pangolin https://github.com/fosrl/pangolin
              I’m using that with great satisfaction.
              Alternatively netbird might be what you’re after https://netbird.io/

              tobraha@infosec.exchangeT This user is from outside of this forum
              tobraha@infosec.exchangeT This user is from outside of this forum
              tobraha@infosec.exchange
              wrote last edited by
              #6

              @dergilm thank you for the tips, I've not heard of either of these. Pangolin looks interesting!

              1 Reply Last reply
              1
              0
              • R relay@relay.infosec.exchange shared this topic
              Reply
              • Reply as topic
              Log in to reply
              • Oldest to Newest
              • Newest to Oldest
              • Most Votes


              • Login

              • Login or register to search.
              • First post
                Last post
              0
              • Categories
              • Recent
              • Tags
              • Popular
              • World
              • Users
              • Groups