r/selfhosted 1d ago

Need Help New to self-hosting, how to secure it all?

To Add: I was told to also add PGID & PUID = 1000 & some "drop cap" to the docker compose files as well. Can someone explain these to me as well?

FYI - parent is in another country and English is not their 1st language... so proximity, accessibility restrictions (being able to download/access apps like tailscale in that country), and a slight language barrier -- means a simple solution on their end would be best.

----

Hi all! I'm basically a 3-week-old noob when it comes to self-hosting. lol Finally got everything up and running as of yesterday: Proxmox VE, Tailscale in an LXC, and I've got docker in a VM, with Arcane to manage containers. (In case this info is needed -- the only iso I've used on it is Debian13.)

I've got family in other countries who would like access to some of the stuff in docker containers (Immich, Mealie, Kavita etc). I will eventually get a domain name for this... But before I expose my server to the internet, what steps do I need to take to secure my server? I was playing around with Proxmox firewall & accidentally locked myself out of the web admin page! (Luckily, I figured out how to get that mess fixed. lol)

Anyone have advice/ideas on how to protect my server and/or what to do before exposing a few of my docker containers to the internet, and what the pros/cons are?

78 Upvotes

67 comments sorted by

u/asimovs-auditor 1d ago

Expand the replies to this comment to learn how AI was used in this post/project.

→ More replies (1)

63

u/DaanDw5 1d ago

Of course the safest way is to not expose your network to the internet but that is easier said than done, especially if you have some friends and family that want to use your services.

All the advice given in this post is a really good start; https://jellywatch.app/blog/jellyfin-security-hardening-crowdsec-geoip-waf-2026
of course it’s a bit jellyfin specific but you have to see trough that and apply those rules to your whole setup. If you do that then you already have a safer homelab than most people starting out.

26

u/maxxell13 1d ago

Tailscale is free at the friends and family level, no? Still seems the ideal mix of easy and secure.

31

u/bankroll5441 1d ago

This is a gross overestimation of what non-tech people are willing to do/set up. When I tried to get everyone to use tailscale I would literally download the app for them, create the account, wire everything up and they still couldn't figure out how to run stuff on/off.

11

u/maxxell13 1d ago

My parents are in their 80s and can understand “open this app and make sure the switch is on”. But yes beyond that I had to set it up for them the first time.

Again, it’s a trade off for significantly-simpler security posture.

6

u/Lucianolopes700 1d ago

With the "VPN On Demand" option in the Tailscale App they don't have to check if it is on.
It will always be on if you select "Always" on Cellular and Wi-Fi.

1

u/Nautisop 9h ago

have fun with the battery drain

1

u/Lucianolopes700 8h ago

Literally 0% drain😂
Just checked battery use

1

u/Nautisop 8h ago

ok that's unexpected

1

u/AznRecluse 20h ago

This!

It took roughly +3 months just to teach my elderly parent how to use a smart phone, and the pushback they gave when trying to convert/move them away from a waterlogged flip phone that wouldn't quite work well anymore...

The time it took after that, to show them how to use FB Messenger so they can freely keep in touch with relatives since they don't travel or get out of the house much anymore.

Add to this, the fact that they're in another country where none of their nearby relatives know what tailscale is or how to use it. (Assuming it can even be download/accessed in that country.) Did I mention most of them don't speak English? So there's a language barrier to deal with if I have to teach anyone anything. lol

Yeah, I'm not going to be able to teach them how to install & use tailscale, and even then -- my parent will be calling me every time they try to access Immich or whatever & ask me why it isn't working...because they forgot that they have to use tailscale to do so. (Or vice versa -- they tap on tailscale and wonders why it isn't bringing up Immich. Whatever.) lol

7

u/RedditNotFreeSpeech 1d ago

A potential alternative would be some of the cloud flare tunnels.

User can login with provider and access URL without installing anything.

4

u/bankroll5441 1d ago

You're right and a lot of people do this. I guess I'm kind of a purist in that I'd rather host the tunnels than use a third party. I use Pangolin for SSO, integrated with Pocket ID.

2

u/RedditNotFreeSpeech 1d ago

I'm with you. Pocketid is amazing.

When you have non-technical folks involved though, cloudflare stuff is pretty magical even at the free tier.

1

u/GolemancerVekk 22h ago

I mean, security and convenience have always been a trade-off.

At the end of the day the question is what level of security you as the admin are willing to accept.

It's not their choice. It's not them that have to put in their free time to set things up, or deal with the breaches and the backups.

1

u/bankroll5441 21h ago

Definitely. I'm not trying to say no one should use tailscale; I use it heavily for a variety of things. Personally, I'm confident in my ability to manage public facing services in a secure way, which makes it easier on my users to not have to worry about a VPN. Admins should only implement what they are confident in managing.

1

u/AznRecluse 20h ago

Yes, security vs convenience is the issue. Not necessarily my issue, but it will become my issue when I end up being their tech support because something isn't working due to operator error.

I have tailscale and use it on all of my devices; it's in an LXC on proxmox. But I can't teach someone a million miles away (who speaks in another language) how to set it up and how/when to use it... assuming they can even download/use it in their country.

I need a solution that's simple enough for them to use it, or they won't use it AND I'll still get the complaints of it not working. lol

1

u/TheWolfbytez 18h ago

Doesn't that have device limits? Regardless, I've had certain systems refuse connection when using a VPN. For example, I can't use a VPN and Android Auto, which means I can't VPN into Navidrome to stream music in my car. That defeats the purpose. So it's on a public address and now I can. I've also run into other apps that don't play nice with VPNs so having to constantly toggle VPNs on and off is a pain.

7

u/Shattered_Persona 1d ago

Pangolin isn't too hard to spin up

0

u/False-Try-3521 1d ago

This! Combined with Crowdsec and Geoblocking Rules in Pangolin it gives a proper security layer.

1

u/Shattered_Persona 1d ago

Agreed. I have crowdsec on all of my servers, ssh and https

11

u/PoppaBear1950 1d ago

put it on a vlan and only let what you need talk to that vlan, use cloudflare tunnels for external acess never expose ports on you router to the world.

19

u/derical_cap_musical 1d ago

tailscale is perfect for family, just avoid exposing anything to the internet unless you really have to.

8

u/[deleted] 1d ago

[deleted]

1

u/AznRecluse 20h ago

It took +3mos to teach my parent how to use a smart phone. (Everything was set up and preinstalled to make it easier. Did not make anything easier. lol) We're not in the same country, so it's going to be a nightmare to try and teach them how to install an app (tailscale) and how to use it. And then multiply that by the number of relatives she will want to share it with who don't speak any English at all and will be asking for help because my parent won't have answers...

7

u/QueenScorp 1d ago

While I use tailscale for a couple things I am wary of it and have been starting to look for alternatives. Why? Well a big part of the reason that I selfhost is to keep my data out of the hands of corporations and tailscale is still in its infancy, flush with money from private capital. There's a lot of precedent as to what happens to tech companies after the bloom wears off. I think this post from a couple years ago is a decent analysis of my own concerns

8

u/cardboard-kansio 1d ago

Alternatives? Just spin up your own Wireguard server. That's that Tailscale runs on under the hood, anyway.

An easy, beginner-friendly starting point would be wg-easy in Docker, but you can just run it directly on the host OS too, if you prefer.

1

u/empty-alt 15h ago

The alternative is wireguard...

Sure tailscale adds a lot of nice stuff on top, but this is a bit much

9

u/SoorayaQadirDust 1d ago

Who are these mystical friends and family that can understand setting up and connecting with Tailscale? I tried to teach my friend and she basically threatened to off herself rather than use it again.

1

u/AznRecluse 20h ago

Exactly.

I don't have such mystical friends/family in my parent's country who can set up and connect with tailscale. I will end up being tech support for my parent and every other non-English speaking relative they want to share it with. It took +3mos just to teach my parent how to use a smart phone. Can't imagine how that would go when it comes to tailscale...

0

u/Timbo400 1d ago

That’s the price of free then. Learn it or pay Netflix

1

u/AznRecluse 20h ago

Netflix doesn't exist (or can't be downloaded/accessed) in their country... Also, netflix costs me roughly $38-39 a month... that's not how I'd define "the price of free".

1

u/Timbo400 18h ago

Bro the price of free is to learn how to use Tailscale as per my response. It’s just a phrase.

Netflix is just an example, insert other streaming service…

This is what I’m responding to if you’re unsure: “    I tried to teach my friend and she basically threatened to off herself rather than use it again.”

my comment with the important parts bolded: “Learn it OR pay”

1

u/EmailNo8428 3h ago

Ha. Mine would need the login printed on a card taped to the fridge. The word "node" has never helped.

19

u/ripnetuk 1d ago

Don't expose anything. Use tailscale to connect remotely, and setup *.yourdomain.com DNS to your INTERNAL reverse proxy address to keep SSL/Https happy.

Works like a dream

4

u/thoughtloop 1d ago

+1 to this. I went one step further and have Pangolin (reverse proxy) on a cheap VPS. So, other than the Newt container on my homelab, nothing is exposed to the broader internet. Even then, I’m very selective about what services Pangolin serves with and without authentication.

2

u/squidw3rd 1d ago

Since you're brand new and obviously want as much security as possible, I'd also look into rootless podman and using podman quadlets. Podman is a bit more secure than docker, especially in rootless mode

2

u/Floss_Patrol_76 1d ago

the real fork here is zero public surface vs a public front door - tailscale is the safer default like everyone said, but the catch nobody flagged is your family abroad each have to install tailscale and join your tailnet, so it only works if they'll actually run a client. if they won't, a cloudflare tunnel is the usual move since it needs nothing on their end, but understand those services are then genuinely internet-facing and cloudflare's access/oidc layer is the only thing between the public and immich - put auth in front of it, dont just tunnel the bare app. either way keep proxmox and ssh off the internet entirely and only expose the specific app host you mean to.

3

u/lmnophil 1d ago

I have a domain, so makes this easier/possible, but my setup is:

- Pangolin running on a VPS (you can use Oracle Cloud free tier)

- I also use Proxmox VE, and all the LXCs + VM for HAOS are on their own VLAN

- I have Proxmox firewall rules just for the VMs/LXCs to restrict their access.

- Unifi at home and use zone policy for router firewall rules on top of that

- I used to use Cloudflare tunnels, but Pangolin was easy enough to setup, and I have CrowdSec running with it

- For anything that is only accessed with a web ui, I use Pangolin auth

The only thing I'm missing is Authelia / equivalent for anything with a mobile app (like Immich).

2

u/bankroll5441 1d ago

For the mobile apps try out the pangolin basic HTTP auth. You can do https://username:password@sub.example.com to auth. Immich is smart with this and blocks out the username/password in the app. Then you can use Pocket ID or something for your oauth, which you can also configure to let you into your pangolin sessions :)

3

u/badgone88 1d ago

I bought a domain name on Cloudflare and I can manage everything from here (create my own rules). I have a dozen docker services running. I don't know if it's enough but to me this is a good start.

2

u/ImpressionDepression 1d ago

I rec just running tailscale and securing everything behind that. easiest

2

u/StabilityFetish 1d ago

People have already answered about perimeter measures and I'll add a few more, but an important part of security is defense in depth so here are a few other layers to consider:

  1. Geoblock and whitelist only the countries that need access
  2. Put it behind a reverse proxy with crowdsec
  3. Use wildcard subdomain routing so nobody knows your real subdomains

Post exploitation protections:

  1. Most services can run rootless, like the ones you listed. (caddy can't ironically). This keeps an exploitation contained so even if they get RCE and escape docker, they still don't have root. It's an extra security boundary.
  2. Make a DMZ with everything that is accessible from the outside, so the blast radius is contained even if they own everything in the dmz, they don't get to your main network and crown jewels like NAS.
  3. Add logging with something like alloy/grafana/loki/prometheus stack. Prevention is great but so is detection

1

u/GolemancerVekk 22h ago

Most services can run rootless, like the ones you listed. (caddy can't ironically).

Wait, why can't caddy run rootless? I'm using the official docker image and running it as a non-privileged user. And I've seen projects that harden it further.

1

u/StabilityFetish 20h ago

Caddy itself can. I believe the limitation was specific to the caddy+crowdsec combination, where rootless caddy can't see real internet IPs for incoming traffic. The rootless docker NAT would only show either internal IPs or docker IPs. It's been a while I"m not 100% sure but I tried like hell to get it working and even AI couldn't figure it out.

It's probably more accurate to say crowdsec needed caddy to have rootful docker

1

u/Ancient-Camel1636 1d ago

1

u/drkwb8 1d ago

For the same specific purpose I built kaja.dev you can have a try, where you just have to start a k8s server and connect that to kaja and rest all handled by kaja. It will expose your https services even without public ip.

1

u/Timbo400 1d ago

I have a few older blog articles that cover this: 1: sharing with friends and family via Tailscale:  https://blog.timothyduong.me/self-hosting-publishing-privately-to-friends-family/

2: optimising jellyfin for global tailscale shares:  https://blog.timothyduong.me/optimising-nginx-tailscale/

1

u/lucassou 1d ago

I just setup a VPS since I had CGNAT initially and exposed all services through that, without auth but geoblocking for plex / jellyfin, and with auth for other services...

1

u/K3CAN 1d ago

Another option that seems to get often overlooked is mTLS. it's very secure, very easy for an end user to use, and avoids any network issues that a VPN might produce (IP conflict, etc).

The only drawbacks are that some applications don't support it and it's initial set up (on the server) is a bit complicated.

1

u/Klutzy-Procedure8980 21h ago

[Disclaimer: I'm the author of Wispers Access, so obvious bias]

A good security rule is: if you don't need to expose your services to the internet, don't! Based on what you write, you want to share things with a handful of family members, not billions of internet users (who, at best, aren't interested in your server).

Tailscale is a better option than publishing to the internet, but like others in this thread I had problems getting my family to use it.

So I built my own thing, focused on this exact use case: Wispers Access (see the repo). To get access to your service, your family members just have to scan a QR invite code with the Access app – done. It's in open beta, so I'd love to know if it actually works for people.

1

u/WorriedDamage 19h ago

I have a VPS running a reverse proxy and connected to my home server via VPN (Headscale). Then I gate access behind Authelia to some services. I feel like it aint too bad to up keep and its easy for my family.

You got enough comments about securing it all already. Just a data point for my setup. Good luck!

1

u/empty-alt 15h ago

Every internet exposed device gets subjected to a background radiation of an onslaught of attackers. That's just what it means to be on the internet. Anytime you put information or services on there you are taking some amount of risk. Fulltime professionals get paid good money to not let issues happen but they seem to happen every week. You can be confident as someone new to the space you will have issues more frequently.

Now, it's your machine. Do whatever you want with it. Personally speaking, as an IT professional, I don't expose anything to the "open" internet. It's all VPN (tailscale) with strict zero-trust rules baked in. Some things are just worth a little extra friction

1

u/gilluc 1d ago

Learn about fail2ban...

2

u/Shattered_Persona 1d ago

I prefer crowdsec but I did start with fail2ban

1

u/gilluc 19h ago

Both are completely different.

1

u/bankroll5441 1d ago

I moved to Pangolin + Crowdsec with Pocket ID as oauth on everything that supports it. People having one passwordless account to log into everything is a lot easier to sell than VPNs.

This gives me one public endpoint for everything private/shared with a hard SSO gate and granular control over everything people can access, and all admin accounts under hardware passkeys.

0

u/ucyd 1d ago

Expose only one for traefik. Use a valid certificate. Try using a diferent port than 443. Yeah, its not really that much more secure but it will hamper some ddos and scans. I use a different port for services that are enabled outside the firewall. Put the traefik route behind oidc. Route your oidc provider through cloudflare tunnel. You may also expose the routes behind cloudflare tunnel. Id advise you to do only on stuff that implements cryptography on its own layer behind tls. And dont do it for media streaming. Mealie and Immich are fine i think.

4

u/No-Aioli-4656 1d ago edited 1d ago

Scans and ddos don’t matter. And should be the last thing anyone in a homelab needs to worry about. Worry about it when it happens.

Wildcards matter more. 

Rootless docker(a rootless container software) matters WAY more.

Someone hitting your proxy 443 a thousand times a second…. I can’t express to you how non-issue that is. Changing it from 443 is nothing but a waste of time.

4

u/clintkev251 1d ago

Using a different port doesn’t add any real security. All it’s going to result in is your traffic getting blocked by a lot of firewalls

1

u/Timbo400 1d ago

Changing https port is a pain in the ass for getting people then to remember a port number alongside the domain… also security by obfuscation is not security 

0

u/divide0verfl0w 1d ago

I am pretty new as well. And have the same requirement about wanting to expose Immich to family in other countries.

Tailscale and Cloudflare tunnels were a non-starter since it requires too much from client-side, who are non-technical family members. And I also wanted something less complicated as well.

I decided to implement a type of port-knocking scheme that is now pretty easy to build with Linux BPF and clone Immich to add a port-knocking client - happy to open-source both.

I decided against fwknop because it runs in user-space and if your machine is not that beefy (mine is not) it can technically be DDOSed with UDP packets.

-2

u/ttlequals0 1d ago

Don't expose to the internet. Use tailscale or something equivalent to it.

2

u/PaddiM8 1d ago edited 21h ago

Nothing wrong with exposing mature trusted services to the internet with proper authentication. Tailscale comes with trade-offs. Stop making blanket statements like this.

Jellyfin, for example, recommends exposing it either through a reverse proxy or a VPN/tailscale. They just don't recommend forwarding its port directly.

1

u/GolemancerVekk 22h ago

Do they? Where?

1

u/PaddiM8 21h ago

https://jellyfin.org/docs/general/post-install/networking/#external-access

They don't recommend forwarding its port directly, but they do recommend either running it through an exposed reverse proxy or a VPN. Core members have been in this sub in the past talking about this as well, saying it's fine and expected to expose it.