Resource / help learning self hosting

Hello,
I want to start learning self-hosting. I have basic programming skills and some networking knowledge. Previously, I’ve used cloud platforms like AWS, GCP, and Heroku back when it was free (mostly for coursework few years back so I’m somewhat rusty), but I haven’t hosted anything on my own hardware. All the free tier cloud hosting doesn’t seems to too many caveat for my stuff but I don’t feel like paying them either, so I might as well learn self hosting.

I want to start with hosting a few small web apps I’ve built, then gradually go deeper into managing eventually. I want to understand networking, security, and deployment better .

I’ve read some beginner guides, but I’m still unclear about safely exposing services. Many guides suggest port forwarding, but I’m not confident about the security implications. I’ve also heard a little bit about Tailscale, which seem to avoid direct exposure, but I don’t fully understand when to use them versus traditional approaches. I thought I’d ask the grey beards here before I shoot myself in the foot.

My questions:

  • What is the recommended starting setup for self-hosting at home?

  • Is port forwarding acceptable for beginners if properly configured, or should I avoid it entirely?

  • When should I use something like Tailscale instead of exposing services publicly?

  • Any structured resources or learning paths you recommend?

Thanks in advance

I’ll share my personal experience bc I’m also relatively new and still learning, and since the best way to the right answer is posting the (potentially) wrong one. I’ll start with port forwarding. I’d advise against it pretty much always. It carries too much risk and the likelihood of leaving yourself exposed is too high. Not impossible, but there are many other ways to access self hosted services outside your network.

Tailscale or WireGuard would probably be the best option. I personally went with WireGuard bc I wanted to figure it out myself and didn’t want to use a hosted service if I didn’t have to. Of course there’s risk in doing it yourself, but my router allows connections only for devices with registered public keys.

I’ve heard people will use NGINX for a reverse proxy to access locally hosted services, but honestly that’s not something I’ve personally done, so I can’t speak to it. My understanding is that it’s a way to route requests from outside your network into your network, but no clue if there’s a way to restrict access.

All in all, my experience with self hosting has primarily been working with local services only. Relatively recently I set up WireGuard and that’s been a great help, but it doesn’t always work on public Wi-Fi. I’ve used the the mess around and find out method when it comes to setting up anything that’s local only, but anything exposed to the outside web, I’ve tried to move cautiously. If you can use WireGuard or Tailscale, that might be a good way to go, at the very least having some experience with their setup is probably a good thing to know. I think things get trickier when you want to allow other people besides yourself and maybe a few family members get access to your locally hosted services, if that’s the case, I look forward to hearing what others in the community recommend.

1 Like

Before even considering self-hosting at home, analyse your network traffic to your existing site(s). That metric gives you a ballpark idea of how much traffic you can expect at home and your ISP connection needs to be capable of handling this comfortably with sufficient head room to allow your normal household traffic to proceed unhindered. It might mean you need a 2nd ISP connection or upgrade your current connection to a (more expensive) higher tier. Your budget needs to allow for this too.

Next is your hardware. based on the aforementioned metrics for traffic and throughput you should spec the hardware to an optimum between hardware cost, throughput, speed, efficiency and energy consumption. That’s a multi-way puzzle only you can lay, I’m afraid :roll_eyes:

Once you figured this out the next steps will be how to make sure your projects are presented online safely. This too is a complex task, as you correctly identified, one I’m not willing to make so I keep stuff offline :stuck_out_tongue:

I wasn’t clear about it, but my concern with the free tier stuff is not the traffic, I think most of my use case would be for my own personal use, maybe show it to a couple of friend here and there. But I kind of want to get my hand dirty in actually try to learn all I can, so I want to closely mimic what a “commercial“ grade one whilst spending as little as possible. Though the security part is a real concern. I don’t want to screw over everyone in my household that use the internet just by me trying to learn things. But thanks for the response, I guess scaling it up to an actual “commercial” is harder than I initially thought.

I thought I’d ask the grey beards here before I shoot myself in the foot.

My beard isn’t fully grey yet, but there are quite a few grey strands of hair. Does that count?

What is the recommended starting setup for self-hosting at home?

Good question. I’d say this is a good starting point:

Is port forwarding acceptable for beginners if properly configured, or should I avoid it entirely?

Avoid it entirely. No reason to let bad actors on your network, just because you didn’t patch the yet-to-be-disclosed 0-day.

Reverse proxy to a VPS via a WireGuard VPN, that’s the safer route. And setup unattended upgrades (for security repos only!) on the VPS!

Would highly recommend going with a SELinux enabled distro, like Rocky Linux and investing some time in setting up proper firewalld and SELinux policies on that VPS.

Only allow SSH traffic over the WireGuard VPN, only open up port 80 and 443 to the internet on the VPS etc. etc.

When should I use something like Tailscale instead of exposing services publicly?

Never. Don’t encourage companies that repackage open-source software and sell it as a service. SaaS is cancer. Not to mention, you’re giving some company literally access to your home network (and paying for it), does that sound like a good idea?

Same reason to avoid Cloudflare. Don’t pay for SaaS MITM.

Any structured resources or learning paths you recommend?

Uhhhhh.. Arch wiki, Gentoo wiki, Rocky Linux wiki, Fedora wiki.

Learning how NGINX works, and how to set it up as a TLS termination layer to reverse proxy back over the VPN to your home network.

(Add a Varnish cache and second layer Apache Traffic Server cache in-between for bonus points)

Learning configuration management systems like SaltStack, learning about kickstart.cfg and Packer. Then combining everything, to effectively have stateless servers that can be spin up with your exact infrastructure in seconds using Terraform.

Avoid Nix, it hides too many complexities and introduces its own. Better to know the real tools it triggers.

Learn about podman, podman-quadlet; allows for easy adoption of OCI containers without all the bloat that comes with the Kubernetes ecosystem.

(Bonuspoints if you run all those containers in a single QEMU microVM booted from a ISO pre-provisioned with all the stuff)

All of this to truly grasp will take you at least a year to a decade, and then you are effectively a self-taught sysadmin/SRE.

The strategies I described above are one path of many.

1 Like

I’ve never heard of FUTO, much appreciated. Though from brief skimming it’s more complicated than I initially thought it would be, but I guess that’s the fun part. Thank you for all the answer, I discovered so many unknown unknown and I got a decent place to start.

Just speaking from my amateur, self-taught experiences…

Where I Began

I started low cost by just using an old laptop/PC to run a couple of Apache web servers (only because I had previous experience with Apache, not necessarily recommending them :grin:) and added network paths so I can use my main computer for file editing. I forwarded the ports on the router and only had it running when I was working on it. Probably not the safest but probably low risk as well. This was the “hello world” moment of me spinning up a public-facing web server.

Where I Am

When COVID hit I decided to upgrade to a dedicated rig for more horsepower and a Unifi infrastructure for better control & reliability. I decided Unraid fit my needs best and I started tinkering to finally learn some low-level networking. I’m currently using SWAG for my reverse proxying (its dockerized Nginx + LetsEncrypt) routing through CloudFlare.

Solid References

I would strongly suggest getting a good understanding from some thorough guides. The best resources I used:

AI as a Finishing Tool

From there I found Claude to be the best tool to complete the last mile. Every setup has nuance that start getting harder to find via a guide. For example I have multiple VLANs, recursive DNS, hostname docker flags that need to be accounted for. Plugging in these details and having that foundational understanding from the guides got everything setup, secure and even a little automated when another service needs to be exposed.

Best of luck!