• 0 Posts
  • 15 Comments
Joined 3 years ago
cake
Cake day: July 9th, 2023

help-circle
  • +1 for cloudflare tunnels. But if you want to host locally, nginx proxy manager has a very intuitive gui you’ll be able to host your sites on.

    Example:

    Docker container exposes port 8989 for sonarr. Nginx proxy manager entry will be: Sonarr.mydomain.com > http://192.168.0.50:8888/ There’s a setting to allow ssl for your domain.

    In your domain registrar, just put the a record for sonarr.mydomain.com to the local IP of nginx proxy manager, in this case let’s assume it’s the same IP as sonarr.

    So now in your house your computer calls the domain, your dns server responds with 192.168.0.50. That’s the IP of your proxy.

    Your proxy gets your request. Sees you’re trying to access sonarr, and passes your query along to it.

    But like I said, cloudflare tunnels removes ALL of this and even supports google / azure SSO to keep you secure and keep logins convenient.


  • Yes in zero trust > access controls > applications you can specify a web site and then tell it how you want it protected. In its most basic form you can have it email you a login code, but if you link it to either google or Microsoft you can have users of those services use them allowing you to sso straight through.

    You can also specify a wildcard *.mydomain.net and then by default anything that is in your domain will be protected. Means when you’re testing something new you won’t forget to lock it down.

    You’re correct about media, I use nginx proxy manager for emby, but everything else goes through the tunnels

    As for configuring, the cloudflare LLM bot has been trained on all its documentation so it’s one of the few times a chat bot is genuinely useful.





  • There are two types connection in this scenario

    1. Direct - no additional cost to Plex, using the port forwarding instructions you mentioned. No limit on bandwidth - the best (and most common) option
    2. Relay - for whatever reason your client cannot reach the server (CGNAT / port forwarding not possible / firewall on client side etc), Plex will act like a man in the middle & limit the connection to 2mbit. (Yup, megaBIT).

    I switched away from Plex last year because they wouldn’t let me connect with my box in Hetzner. I’m now using Emby, ironically I’m also paying for Emby’s monthly subscription. Not because I believe I need to, but because I want the developer to continue to work on it.










  • If you use NGINX proxy manager you’ll also be able to use a FQDN with SSL for your local services without them being exposed to the internet. It means your local users won’t see the scary insecure page when they access services.

    You can even set your public dns records to have Plex.yourdomain.tld point to the local IP of NGINX - removing the need for local dns entirely. That way if you do need to access a service outside with tailscale; their subnet router feature will just work out of the box.

    Porkbun are still offering a free .dev or .app domain if you don’t already have one: https://porkbun.com/event/freeappdevdomain