I’ve been using Linux for decades, I’ve worked as a software engineer/architect/sre for around a decade, but networking has always been my biggest gap in knowledge.

I have a local server, I have caddy spun up, a glinet router running their version of openwrt, and I have a domain name purchased through porkbun.

I am looking to setup “local.domain.com” to point to my local server, ideally without exposing it publicly, and enable devices on my home network to be able to access it from that url. Id also like to be able to access containers running on that server by something like “searxng.local.domain.com” or “local.domain.com/searxng” aka without using the port suffix. Id also like to enable https.

I have read so many guides that have fragments of what I need, but nothing that ties enough together to get it working. And with all the options around different domain registers, let’s encrypt, reverse proxies, etc, im struggling just a bit.

Are their any guides (prefer text over YouTube, but beggars cant be choosers) that people recommend that encompass the whole process, instead of just pieces? Id like to understand it instead of just fumble through it.

  • d13@programming.dev
    link
    fedilink
    English
    arrow-up
    13
    ·
    edit-2
    14 hours ago

    Lots of overcomplicated answers, imo.

    Here’s what I did:

    1. Set up a DNS server (I just used Pi Hole docker)
    2. Tell router to use the DNS server
    3. Register domain
    4. Set up Caddy with https to use DNS challenge with registrar’s API key for Let’s Encrypt or similar.
    5. Add subdomain DNS entries to the DNS server for each service. The records point to Caddy’s IP (e.g. jellyfin.<domain>.com)
    6. Add each container to Caddy’s list

    Now every device at home can hit all services by domain name over https. No need for any manual configuration on any client device (certs, hosts, etc.)

    Bonus: Set up split DNS and subnet routing with Tailscale so that it uses the DNS server for that domain. Now any device connecting to the tailnet can connect to the services just like at home. No need to reconfigure apps, etc.

    Simple and it works like magic.

    • dabe@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 hours ago

      This is the way. Been running (basically) this for years and genuinely keep my eye out for any simpler suggestions, but nothing comes close.

      I do it slightly different where I use an external DNS (bunny) and point the A records to the tailscale IP of the server running Caddy.

      The benefits are:

      • I don’t force the whole house to rely on my local DNS setup.
      • Nothing breaks when I change routers and mess up IP mappings (which I was doing a lot, but I finally got some nice unifi equipment, so maybe I don’t have to worry about that anymore).
      • I don’t “leak my LAN configuration” to public DNS but I don’t care about that anymore.
      • I can use Tailscale DNS override if I want just my tailnet devices to go through some private/premium DNS resolver.
      • Don’t need to set up subnet routing in Tailscale

      The downside is it doesn’t work at all for devices not on Tailscale. Real bummer when, like, I want my smart TV to just be able to find jellyfin on my LAN with the same domain names. But everything else about it is very convenient.