Comment on My stupidity saved me from being hacked today!
qjkxbmwvz@startrek.website 8 months agoNot sure how reverse proxy is avoided this way — do you enter port numbers for your services when you access them, or have one service per machine?
I have a few publicly accessible services, and a bunch of private services, but everything is reverse proxy’d — I find it very convenient, as for example I can go to wap.mydomain.net for my access point admin page, or photos.mydomain.net for my Immich instance. I have a reverse proxy on my VPS for public services, and another one on my lan for private services; WireGuard between VPS, LAN, and my personal devices. Possibly have huge security holes of course…
nyakojiru@lemmy.dbzer0.com 8 months ago
Yep correct hostname:port por each application, all running in the same host on docker. The only thing it would be that any device that would want to connect to an app needs the Tailscale client. And would take over the VPN slot. That’s why they offer exit nodes with mullvad and also DNS privacy resolvers like NextDNS.