Exposing a Homelab to the Internet Without Exposing Myself

Once the homelab had more than one service worth using away from home (Nextcloud for files, Jellyfin for media), “just port forward it” stopped being an option I was willing to consider. I spend enough of my working hours dealing with what happens to services that sit on the open internet unpatched or misconfigured for a week. I wasn’t going to do that to my own network. Layer One: A Private Network That Doesn’t Need Open Ports Tailscale solved the “I want access from anywhere” problem without opening a single inbound port on my router. It’s WireGuard under the hood: every device gets a key, joins the same private tailnet, and talks to every other device directly (or through a relay when direct connection isn’t possible) over an encrypted tunnel. My phone, laptop, and homelab nodes all land on the same private address space no matter which network they’re actually sitting on. For anything only I need to reach, that’s the entire solution: no public DNS record, no exposed port, nothing for an internet-wide scanner to ever find. ...

June 12, 2022 · Alexander Bakin

Deploying Vaultwarden with Ansible: My Homelab's First Real Service

I started self-hosting for a boring reason: I didn’t like that a single cloud account breach could hand someone every password I own. A self-hosted password manager has its own risks, but at least the blast radius is mine to control. Vaultwarden (a lightweight Bitwarden-compatible server) was the obvious first service, and I used it as an excuse to do my homelab properly instead of SSH-ing in and running commands by hand. ...

July 18, 2021 · Alexander Bakin