I want to expose my services publicly on my own domain name, how would you guys do that?

I have seen people using Cloudflare, but I don’t want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I’ve done some rough researching.

What do you guys do?

  • frongt@lemmy.zip
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    2
    ·
    20 hours ago

    That first page says exposing it to the Internet is “not recommended”. Putting a reverse proxy in front of it does not meaningfully change the security posture. A malicious request to http://jellyfin.homelab.com/exploitable-page will be sent to jellyfin in effectively the same way, whether through a reverse proxy or not. You would need a WAF set up specifically to look for relevant exploit attempts.

    https://github.com/jellyfin/jellyfin/issues/5415

    Those are some outstanding known vulnerabilities, most of them unfixed. They are not particularly severe, but it shows that thorough security is not a priority for the jellyfin devs.

    • ampersandrew@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 hours ago

      It says exposing a port directly to the internet is not recommended; do you know of any project that would recommend directly exposing a port? What is meaningfully different here?

      • frongt@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 hours ago

        Sure, any project designed to be exposed to the Internet. Web servers would be the most obvious.

        • ampersandrew@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 hours ago

          Probably the number one recommendation I see in self hosting communities is to not open ports directly (other than for a reverse proxy). It seems like a common recommendation no matter the service. To be clear: I am a beginner. I know very little about this, but I’ve spent months learning. I can’t say you’re wrong, but I don’t think you’ve made a convincing argument for me to actually understand why Jellyfin is unsafe to expose to the internet compared to any other service.

          • frongt@lemmy.zip
            link
            fedilink
            English
            arrow-up
            1
            ·
            4 hours ago

            You are welcome to expose it at your own risk. Assess you own tolerance for compromise (personal data compromise, becoming part of a botnet, becoming a host for spam or CSAM) and proceed accordingly.

            • ampersandrew@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              4 hours ago

              Yes, that’s exactly what I’ve done. You still haven’t shown me why it’s unsafe. If you can’t, that’s fine. At some threshold or another, nothing is secure. The one thing I know for sure is that that first page, that says it doesn’t recommend exposing a port, does not say what you said it does.

              • frongt@lemmy.zip
                link
                fedilink
                English
                arrow-up
                1
                ·
                3 hours ago

                It sounds to me like you just have a higher risk tolerance, and if you accept that, that’s okay.