Hi all :)

I’ve got a media server set up running Navidrome, Calibre-Web, and Immich along with some other services, and want to get access to them from outside the house now. I’ve read that Caddy is good for securing things by making it easier to set up encryption, but I’m not sure I understand that side of things.

I’ve set up a Cloudflare tunnel for a Minecraft server, and I’ve got Tailscale installed but not set up with an exit server yet, but understand that Caddy would be better. I ideally want to set up apps on my wife’s phone so that she can access the libraries too.

Is it just a case of installing Caddy and setting up the services I want to share through it? That seems too easy, like I’ve missed something.

If it makes any difference, I’ve got a standard UK ISP router with a few ports forwarded, and I’m going to add an access point and then a LevelOne GEP-5070 managed switch to learn about things like VLANs. The link to the switch is here:

https://mayflex.com/shop/product/GEP-5070

I feel like I’m missing something, but can’t think what, so I’d be grateful for any help :)

  • irmadlad@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    2 days ago

    I do appologize for not getting back sooner.

    through the Cloudflare tunnel is encrypted,

    Yes indeed

    I thought you needed something like Caddy to get certificates

    You can, and Caddy works well. It just didn’t make sense in this scenario. No worries, mate.

    but I’m going to give it a proper look once I’ve had some sleep.

    Well. I do have some notes tjat might help put the pieces together, if you get stuck.

    The main thing I’m still not sure of is Tailscale

    I use tailscale on the server as a overlay protective overlay, which could be accessed as well if needed,

    • Tippon@lemmy.dbzer0.comOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 days ago

      Please don’t apologise, you and the other commenters have been a massive help :)

      It’s sod’s law though, I was supposed to have two pretty much free days yesterday and today, and they’ve turned out to be two of the busiest days I’ve had for a long time. Networking is one of my blind spots, I can never quite get my head around it, so gave myself two days to try to get up to speed and seem to have jinxed myself :D

      I’m going to spend an hour or two now playing around with Cloudflare and Navidrome and see if I can get a better grip on it all.

      Thanks again for the help :)

      • irmadlad@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 days ago

        It’s sod’s law though, I was supposed to have two pretty much free days yesterday and today, and they’ve turned out to be two of the busiest days I’ve had for a long time. Networking is one of my blind spots, I can never quite get my head around it, so gave myself two days to try to get up to speed and seem to have jinxed myself :D

        OK, well the notes offer is still valid if you should so need them.

        • Tippon@lemmy.dbzer0.comOP
          link
          fedilink
          English
          arrow-up
          2
          ·
          23 hours ago

          Sorry, I didn’t get a notification for your reply until this morning.

          Thanks for the offer, I’d be happy for any notes or advice :)

          I managed to get Navidrome and Immich set up last night through subdomains, like music.domain.com and photos.domain.com, using the existing Cloudflare tunnel. They seem to be working properly, but I’m going to check them when I’m out later to make sure that nothing was cached rather than being served live.

          One thing I want to look at in the future is local domain names, so music.local etc. and possibly set up certificates to get rid of any warnings about insecure sites. I might switch from AdGuard to PiHole to help with that.

          Something that might make you laugh, I got stuck for an hour or so last night trying to connect to Navidrome through the domain name. I could get to the login page, but couldn’t get it to accept my credentials. Substreamer wouldn’t log in either. I looked through pages and pages of search results, forum posts, and manuals, but couldn’t find an answer. Just before I gave up, I copied the address from Firefox to try in another browser, and realised that I’d forgotten the s in https 😫