this post was submitted on 29 Dec 2023
111 points (96.6% liked)

Selfhosted

40296 readers
265 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 1 year ago
MODERATORS
 

I work in tech and am constantly finding solutions to problems, often on other people's tech blogs, that I think "I should write that down somewhere" and, well, I want to actually start doing that, but I don't want to pay someone else to host it.

I have a Synology NAS, a sweet domain name, and familiarity with both Docker and Cloudflare tunnels. Would I be opening myself up to a world of hurt if I hosted a publicly available website on my NAS using [insert simple blogging platform], in a Docker container and behind some sort of Cloudflare protection?

In theory that's enough levels of protection and isolation but I don't know enough about it to not be paranoid about everything getting popped and providing access to the wider NAS as a whole.

Update: Thanks for the replies, everyone, they've been really helpful and somewhat reassuring. I think I'm going to have a look at Github and Cloudflare's pages as my first port of call for my needs.

you are viewing a single comment's thread
view the rest of the comments
[–] originalucifer@moist.catsweat.com 1 points 10 months ago (1 children)

if you setup everything with even moderate attention to the security involved, youll be fine. sounds like youre already there.

this is a common scenario, not a crazy idea or implementation. just keep your shit up to date

[–] TedZanzibar 1 points 10 months ago (2 children)

That's one of the issues I'm concerned about. I'm happy enough to let things auto-update on a tight schedule and capable enough to fix things if eg. Watchtower goes wrong or updates a container to a dodgy version, but what I don't want is to have "keeping things secure" turn into a second job.

[–] pete@lemmy.world 1 points 10 months ago* (last edited 10 months ago)

One option here is to host it internally, and then VPN or ssh tunnel to your network for access.

Keeping openssh or a VPN up to date and secure is a much simpler thing than a web framework.

Separate your network access and your services. You get in trouble trying to use your service to gate access to your network.

[–] erev@lemmy.world 0 points 10 months ago

I run plenty of stuff off my home network, although I use VPSs now more for the higher availability than residential internet. So long as you put basic protections in place like fail2ban and a sensible firewall, you shouldn't have any issues.