Comment on Immich: opinion revised

<- View Parent
enumerator4829@sh.itjust.works ⁨1⁩ ⁨month⁩ ago

Well, I’d just go for a reverse proxy I guess. If you are lazy, just expose it as an ip without any dns. For working DNS, you can just add a public A-record for the local IP of the Pi. For certs, you can’t rely on the default http-method that letsencrypt use, you’ll need to do it via DNS or wildcards or something.

But the thing is, as your traffic is on a VPN, you can fuck up DNS and TLS and Auth all you want without getting pwnd.

source
Sort:hotnewtop