• qjkxbmwvz@startrek.website
    link
    fedilink
    arrow-up
    6
    ·
    6 hours ago

    VPS+VPN, this is what I do.

    VPS has public IP and runs WireGuard “server”* and a reverse proxy (and fail2ban…). Reverse proxy points to my home computer over the WireGuard link. No open ports on my home router.

    For private facing/LAN-only services I just don’t have an entry in the VPS reverse proxy. DNS on the router points everything to my local server, so if at home I access everything directly. To access internal services remotely requires VPN (i.e., WireGuard to the VPS).

    Works well; I have a tiny free tier VPS but even so, no complaints.

    *Yes I know there are no wg clients or servers, only peers, but it plays a server-likr role.

    • yxp@lemmy.radio
      link
      fedilink
      English
      arrow-up
      3
      ·
      5 hours ago

      I’ve been thinking about this setup but it depends on external server after all…

      • qjkxbmwvz@startrek.website
        link
        fedilink
        arrow-up
        2
        ·
        5 hours ago

        Yes, but you can run multiple VPS, from different providers, simultaneously.

        What I like is that while it does depend on an external provider, it doesn’t depend on a specific external provider. Any VPS with a public IPv4 would work.