I want to expose my services publicly on my own domain name, how would you guys do that?

I have seen people using Cloudflare, but I don’t want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I’ve done some rough researching.

What do you guys do?

  • irmadlad@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 day ago

    but what I tend to see is one or two people here saying that Jellyfin devs don’t recommend exposing it publicly

    I think what the devs are saying is ‘don’t expose Jellyfin to the public in an unsafe manner’. I don’t run Jellyfin, but can confirm what you’ve read here. In that vein, don’t expose anything to the public in an unsafe manner.

      • irmadlad@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        20 hours ago

        Again, I do not run Jellyfin, but what you’re saying seems contradictory to what the devs are implying: here and here. Since I lack the hands on experience, I will leave the issue with the experts.

        • frongt@lemmy.zip
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          2
          ·
          19 hours ago

          That first page says exposing it to the Internet is “not recommended”. Putting a reverse proxy in front of it does not meaningfully change the security posture. A malicious request to http://jellyfin.homelab.com/exploitable-page will be sent to jellyfin in effectively the same way, whether through a reverse proxy or not. You would need a WAF set up specifically to look for relevant exploit attempts.

          https://github.com/jellyfin/jellyfin/issues/5415

          Those are some outstanding known vulnerabilities, most of them unfixed. They are not particularly severe, but it shows that thorough security is not a priority for the jellyfin devs.

          • ampersandrew@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            4 hours ago

            It says exposing a port directly to the internet is not recommended; do you know of any project that would recommend directly exposing a port? What is meaningfully different here?

            • frongt@lemmy.zip
              link
              fedilink
              English
              arrow-up
              1
              ·
              4 hours ago

              Sure, any project designed to be exposed to the Internet. Web servers would be the most obvious.

              • ampersandrew@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                4 hours ago

                Probably the number one recommendation I see in self hosting communities is to not open ports directly (other than for a reverse proxy). It seems like a common recommendation no matter the service. To be clear: I am a beginner. I know very little about this, but I’ve spent months learning. I can’t say you’re wrong, but I don’t think you’ve made a convincing argument for me to actually understand why Jellyfin is unsafe to expose to the internet compared to any other service.

                • frongt@lemmy.zip
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  3 hours ago

                  You are welcome to expose it at your own risk. Assess you own tolerance for compromise (personal data compromise, becoming part of a botnet, becoming a host for spam or CSAM) and proceed accordingly.

                  • ampersandrew@lemmy.world
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    3 hours ago

                    Yes, that’s exactly what I’ve done. You still haven’t shown me why it’s unsafe. If you can’t, that’s fine. At some threshold or another, nothing is secure. The one thing I know for sure is that that first page, that says it doesn’t recommend exposing a port, does not say what you said it does.