this post was submitted on 11 Aug 2023
33 points (97.1% liked)

Selfhosted

40926 readers
905 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I'm just a novice at self hosting and I see a lot of talk about the risks of exposing stuff to the world. Here's my setup:

-Rpi4 hosting Overseerr
-Desktop computer hosting Nginx and some Cloudflare DDNS update containers

Cloudflare directs request.domain.com to my home IP address. Nginx forces HTTPS and directs the request to the Pi.

Is there any risk in this setup or are there more steps I can take to secure it?

you are viewing a single comment's thread
view the rest of the comments
[–] 418teapot 1 points 1 year ago (1 children)

Ah yes cloudflare: MITM as a service.

It really depends on who your adversaries are that you want to keep private. The coffee shop owner + their ISP + your ISP, or cloudflare. Seeing as cloudflare MITMs an insane amount of the internet these days I'm way more suspicious of them than I am of the alternative. If you're really after privacy I'd recommend self hosting wireguard or something.

[–] GlitzyArmrest 1 points 1 year ago (1 children)

Of course, that's why I said some resemblance of privacy - it's still more secure (and possibly more private) than just opening ports.

[–] 418teapot 1 points 1 year ago

Right, but that's why I said it depends who your adversaries are. Really though, think why you care so much about privacy.

Is it because you're doing some shady shit? Probably should do everything in your power to avoid clear text communication every step of the way, including cloudflare.

Or is it (like me) because you are so sick of the corporate surveillance and monetization of your internet activity, and you want to fight back? If that's the case you should absolutely avoid cloudflare like the plague since they literally see all traffic for every website they sit in front of, which these days, anecdotally feels like >50% of the internet.