this post was submitted on 12 Jul 2023
19 points (91.3% liked)

Selfhosted

50135 readers
496 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

Running a TrueNAS Scale server with Jellyfin and planning to add Nextcloud. How would I be able to access these services from outside my network? I have heard portforwarding is unsafe and a VPN seems inconvenient to me.

you are viewing a single comment's thread
view the rest of the comments
[–] Im_old@lemmy.world 15 points 2 years ago (9 children)

Port forwarding is unsafe, but even crossing the road is unsafe. Do you cross the road without watching? In the same way, you just don't let a published server online without doing regular updates. You set up docker, run nextcloud (docker) behind nginx proxy manager, and have watchtower update them regularly. You can also setup 2fa in docker, and pair it with fail2ban.

Every port open widens the attack surface, but those services are made to be published, so there are mitigations against the risks.

[–] MaggiWuerze@feddit.de 1 points 2 years ago (3 children)

How does watchtower work with compose stacks? Does it update the whole stack (docker compose pull && docker compose up) in one go or each container individually?

[–] AES@lemmy.ronsmans.eu 3 points 2 years ago (1 children)

Found out the hard way, it does not. Now I just run a script every week (pull and compose up)

[–] MaggiWuerze@feddit.de 1 points 2 years ago

That's my current solution, just hoped I could properly automate that

load more comments (1 replies)
load more comments (6 replies)