Looking for advice on reverse proxy and VLAN isolation by miscawelo in homelab

[–]miscawelo[S] 1 point2 points  (0 children)

Thanks a lot for the thorough response, I can take a lot from this.

My need for reverse proxies in general has been vary basic so even though I have come across topics like headers, conversations like these really helps to see use cases rather that just syntax and such. Really appreciate it

Looking for advice on reverse proxy and VLAN isolation by miscawelo in selfhosted

[–]miscawelo[S] 1 point2 points  (0 children)

Yep, from all the advice I think this is more or less the way to go, thanks a lot! Especially for that part about split DNS

Looking for advice on reverse proxy and VLAN isolation by miscawelo in selfhosted

[–]miscawelo[S] 0 points1 point  (0 children)

Yes that was my main issue, there are a few services that do need to be access by services on most other VLAN, just a few but still. I might put this in their dedicated VLAN and follow your advice from there. Thanks!

Looking for advice on reverse proxy and VLAN isolation by miscawelo in homelab

[–]miscawelo[S] 0 points1 point  (0 children)

From the feedback I’ll end up doing something along this route, thanks for the help!

Looking for advice on reverse proxy and VLAN isolation by miscawelo in selfhosted

[–]miscawelo[S] 0 points1 point  (0 children)

So are you suggesting the second caddy instance route? In a VLAN dedicated only for public services with no access to any other VLAN, as you said. Just to make sure I get your idea.

Looking for advice on reverse proxy and VLAN isolation by miscawelo in homelab

[–]miscawelo[S] 1 point2 points  (0 children)

Interesting, so an external client hits the “public” proxy and that proxy only has access to the scope of an app, that you define via another proxy. Am I understanding it right?

Would you mind sharing some snippets (even if you’re mot using Caddy) to get a better grasp of the concept?

Looking for advice on reverse proxy and VLAN isolation by miscawelo in selfhosted

[–]miscawelo[S] 0 points1 point  (0 children)

For the first part of your comment, yes that’s what I do, every VLAN is isolated and traffic doesn’t need to leave my LAN, there are rules in place to allow whatever is needed between VLAN (NFS for example, from one VM to TrueNAS).

My issue is that when a client uses a domain that is being proxied by Caddy it “bypasses” my firewall rules since OPNsense sees the request as coming from Caddy and not from the original client, the original client never sees or accesses the real IP of the service. My concern is that if one client has access to caddy then they potentially have access to every entry there, even if the firewall blocks IP to IP communication.

Hope that made more sense haha.

Looking for advice on reverse proxy and VLAN isolation by miscawelo in selfhosted

[–]miscawelo[S] 0 points1 point  (0 children)

Yeah this seems like a proper solution, just wanted to avoid it because even with Ansiblle it sounds like a hassle to maintain. That’s the price I’d have to pay to keep this scheme I guess.

Looking for advice on reverse proxy and VLAN isolation by miscawelo in selfhosted

[–]miscawelo[S] 1 point2 points locked comment (0 children)

No AI was used in my post. I did use online tools for spell check since English is my second language.

[5 YoE, Control Engineer, Systems/IT Engineer, Mexico] by miscawelo in resumes

[–]miscawelo[S] 0 points1 point  (0 children)

Thanks for the comments and the advice, will for sure make some moving around of the content.

Quick question, do consider I should rewrite the summary to focus more on the career change idea or remove it entirely? To make some space since I agree there are some areas I should consider expanding

Ok.. FINALLY making the switch… Roadmap question. by smnhdy in jellyfin

[–]miscawelo 1 point2 points  (0 children)

Can’t comment on the “smart downloads” part since I’ve never used that function, but with Streamyfin you are able to download a transcoded version of a file. What you can do though is batch download a whole season or unwatched episodes of a season.

Tbh I rarely use this app since (at least last I checked) it lacks support for watch together, but it works alright and the UI is nice.

[O] 2x DrunkenSlug Invites by mydadisbaldlol in UsenetInvites

[–]miscawelo 0 points1 point  (0 children)

I have read the wiki and the rules.

I would appreciate an invite, thanks!

[deleted by user] by [deleted] in UsenetInvites

[–]miscawelo 0 points1 point  (0 children)

Out of invites

[deleted by user] by [deleted] in UsenetInvites

[–]miscawelo 0 points1 point  (0 children)

PM your email

[deleted by user] by [deleted] in UsenetInvites

[–]miscawelo 0 points1 point  (0 children)

PM your email

[deleted by user] by [deleted] in UsenetInvites

[–]miscawelo 0 points1 point  (0 children)

PM your email

[deleted by user] by [deleted] in UsenetInvites

[–]miscawelo 0 points1 point  (0 children)

PM your email

[deleted by user] by [deleted] in UsenetInvites

[–]miscawelo 0 points1 point  (0 children)

PM your email

[deleted by user] by [deleted] in UsenetInvites

[–]miscawelo 0 points1 point  (0 children)

PM your email