proxmox

No more Cloudflare Tunnels for me…

No more Cloudflare Tunnels for me…

#Cloudflare #Tunnels #me..

“Raid Owl”

Try American Cloud ($10 w/ my link) –
Tailscale –
Nginx Proxy Manager –

——————————————————————————————-
🛒 Amazon Shop -…

source

 

To see the full content, share this page by clicking one of the buttons below

Related Articles

38 Comments

  1. I've been using this exact setup for a few years. Well, not this exact setup…. Just using Namecheap for name server management and using Oracle Cloud because it's free.
    Was actually going to do a video about it until you stole my thunder! Thanks for that 😂 Still might to cover the couple points you missed 🤔

    Thanks for showcasing it, though! Definitely a cool way to go!

  2. Depending on the use case, both Cloudflare tunnel and tailscale are viable options. Cloudflare is nice for simple sites like overseer or home assistant, but I would definitely use tailscale for services like jellyfin and Plex!

  3. Tailscale is such a killer solution. We have the enterprise license for work and it eliminated so many time consuming tasks. At home it's running on my Apple TV acting as a subnet router – probably the most set-and-forget and low power solution out there.

  4. Been doing exactly this for a few months except for one little thing that makes a huge difference:

    I'm using the Tailscale IPs in Ngnix Proxy Manager. That way they're protected by my ACLs in Tailscale. So my stuff is only accessible from within my Tailnet with 0 open ports open to the Internet.

    Also, using a $5 linode on akamai and it is more than enough. Haven't hit any data caps on the VPS even while accessing my Linux ISOs.

    You could also use Tailscale Serve and Docker to eliminate NPM altogether.

  5. Why is the VPS necessary? Why not just access Tailscale containers directly? If you enable Tailscale's MagicDNS you get a fully qualified domain name by which machines/services can be accessed privately over your tailnet. If you need to share those machines/services with others, tailscale lets you share devices on your tailnet with other tailscale users. If they are not a tailscale user, and you still want to share with them, you can make the device available publicly via Tailscale Funnel. So what am I missing here? Why the need for the VPS?

  6. funny thing that i had something similar idea some months ago where I ran a Wireguard server on my end and connected it to a VPS the same way just with a Wireguard client and nginx proxy manager on the vps it self, for a test really I do have a static IP but it was fun to try it out and only have one port exposes was kinda a benefit, have to try it some time later.

  7. If I am correct, this can be done without cloudflare? As long as your domain name provider has their own DNS? Or is cloudflare an integral part of this?

  8. Im a bit confused was the issue with cloudflare tunnels the limitations on video streaming or privacy because right now with this arent you just trusting a different company like american cloud access to your tailscale vpn that comes directly in to your home? You are basically just trusting american cloud instead of cloudflare and by that logic alot more as cloudflare can see only whats being shared on that tunnel?

  9. Color me weird, I just use nginx locally on my server (not docker), then just use tailscale to connect to nginx which does all the traffic routing for me.

    Nice lightweight uses less than 100kb of memeory

  10. No need for any of this port or monthly cost stuff. Either host the DNS server yourself or add the ip from tailscale to cloudflare for your services. (The IP should be the VM or LXC you have both Tailscale and NPM/Traefik installed on.) Only devices approved on your tailnet can access the services. Nothings 'exposed' and even publicly posting your IP makes no difference as no one can access it unless i approve your device beforehand. 🙂

  11. That is basically what I used last year to allow my parents to watch jellyfin while I'm hosting it on my university campus dorm wifi on my Windows desktop, I was even able to get Minecraft tunneled. Speed isn't so great but that's b/c my dorm throttle connection at 30 Mbps, so transcoding is a necessity. I used Oracle Clouds which is completely free. Now since my parents upgraded internet with faster upload, I just permanently setup my hard drives and servers at home and I don't use this anymore. Still a good trick for bypassing CGNAT or internet restrictions.

  12. For my jellyfin server I set up a ssh tunnel to an Oracle Cloud instance via a cobbled-together autossh docker service. I'm pretty proud of it, and I learned how to make docker containers in the process.

    This setup looks a lot cleaner though.

  13. Using netbird instead of tailscale because it is completely open source and it can completely be self hosted. I'm still thinking about how I can make it so that the Nginx Proxy Manager web interface (port 81) can only be accessed via the private tunnel and not via the Internet. Shouldn't really be a problem. This would mean that it would no longer be a tragedy that Nginx does not support MFA.

  14. Hey Brett (small squeaky voice/head), if you are already using a VPS, why don't you run your own HeadScale server on it? Then you don't even need a TailScale account.

  15. As shown in the video "American Cloud" wants $43/month for this VPS, while any $5/month box from DigitalOcean, Linode or Vultr would do just fine for the task. I get it that you had or still have a sponsorship deal from them, but they are really, really mediocre in their space and their offers are not attractive. Agreeing on sponsorship to promote a mediocre product is nothing to be proud of.

  16. If you put it at a friend’s house, would your media have to pass through their home to serve, and thus be limited by their upstream bandwidth? I have decent upstream but have cgnat. My parents do not, but have a public ip.

  17. You do know you can use ip and ditch Cloudflare if you don’t want to expose your services to the internet, right? For me, I don’t think I will open my truenas to the world😂

Leave a Reply