SSL Certificates on EVERYTHING! (DDNS, Local Domains, Cloudflare) - Full Walkthrough Guide Pt.4
Read full transcript 20 segments
-
in this video I am going to be exposing in this video I am going to be exposing myself that is using a combination of myself that is using a combination of myself that is using a combination of Docker enginex proxy manager and Cloud Docker enginex proxy manager and Cloud Docker enginex proxy manager and Cloud flare to actually access various flare to actually access various flare to actually access various services in my home lab from the services in my home lab from the services in my home lab from the external internet and in addition to external internet and in addition to external internet and in addition to that we're going to be setting up a that we're going to be setting up a that we're going to be setting up a local top Lev domain that I'm going to local top Lev domain that I'm going to local top Lev domain that I'm going to be using for my internal Network for be using for my internal Network for be using for my internal Network for those services that I don't want those services that I don't want those services that I don't want completely exposed and for both the completely exposed and for both the completely exposed and for both the public and internal domain we're going public and internal domain we're going public and internal domain we're going to be generating SSL certificates for to be generating SSL certificates for to be generating SSL certificates for everything so then when I'm traveling to everything so then when I'm traveling to everything so then when I'm traveling to proxmox here for example I don't get a proxmox here for example I don't get a proxmox here for example I don't get a warning like that and it will be proxmox warning like that and it will be proxmox warning like that and it will be proxmox do whatever my domain is.com or net my do whatever my domain is.com or net my do whatever my domain is.com or net my internal domain is going to be Hop key. internal domain is going to be Hop key. internal domain is going to be Hop key. net but not only are we going to do net but not only are we going to do net but not only are we going to do those two things but at the end of the those two things but at the end of the those two things but at the end of the video we're going to be setting up our video we're going to be setting up our video we're going to be setting up our sponsor twin gate which will allow us to sponsor twin gate which will allow us to sponsor twin gate which will allow us to access those internal domain names access those internal domain names access those internal domain names basically anywhere in the world quate is basically anywhere in the world quate is basically anywhere in the world quate is a zero trust networking platform that a zero trust networking platform that a zero trust networking platform that allows you to actually remote Connect allows you to actually remote Connect allows you to actually remote Connect into your local network without have to into your local network without have to into your local network without have to use like a traditional VPN you use their use like a traditional VPN you use their use like a traditional VPN you use their web gooey to set up very ious resources web gooey to set up very ious resources web gooey to set up very ious resources networks add users there's group networks add users there's group networks add users there's group privileges so you could have multiple privileges so you could have multiple privileges so you could have multiple users and give them certain access to users and give them certain access to users and give them certain access to certain machines under certain ports it certain machines under certain ports it certain machines under certain ports it is a wonderful platform I've been using is a wonderful platform I've been using is a wonderful platform I've been using them for a long time and if you check them for a long time and if you check them for a long time and if you check out the link down below the first five out the link down below the first five out the link down below the first five users for your account are completely users for your account are completely users for your account are completely free so you go ahead try it out and see free so you go ahead try it out and see free so you go ahead try it out and see if it fits your needs for remote if it fits your needs for remote if it fits your needs for remote connection as you'll see later in this connection as you'll see later in this connection as you'll see later in this video all we really need to do is set up video all we really need to do is set up video all we really need to do is set up our resource on their web interface set our resource on their web interface set our resource on their web interface set up a connector via Docker and of course up a connector via Docker and of course up a connector via Docker and of course there's other methods than docker and there's other methods than docker and there's other methods than docker and then use a client on whatever device to
-
then use a client on whatever device to then use a client on whatever device to go ahead and remote into our Network so go ahead and remote into our Network so go ahead and remote into our Network so again we will be setting that up later again we will be setting that up later again we will be setting that up later there are chapters in this video so you there are chapters in this video so you there are chapters in this video so you can go ahead and Skip around to whatever can go ahead and Skip around to whatever can go ahead and Skip around to whatever parts of this video you are most parts of this video you are most parts of this video you are most interested in we're going to be first interested in we're going to be first interested in we're going to be first starting with uh having a public domain starting with uh having a public domain starting with uh having a public domain in which I will have very specific in which I will have very specific in which I will have very specific services that I want to access in my use services that I want to access in my use services that I want to access in my use case it's going to be uh like a basic case it's going to be uh like a basic case it's going to be uh like a basic website jelly Fin and nextcloud the website jelly Fin and nextcloud the website jelly Fin and nextcloud the nextcloud stuff is going to come in its nextcloud stuff is going to come in its nextcloud stuff is going to come in its own separate nextcloud set video but I own separate nextcloud set video but I own separate nextcloud set video but I will be showing you some tips and tricks will be showing you some tips and tricks will be showing you some tips and tricks with jelly Fin and basically everything with jelly Fin and basically everything with jelly Fin and basically everything else on my home lab is going to use the else on my home lab is going to use the else on my home lab is going to use the local domain that I'm going to set up local domain that I'm going to set up local domain that I'm going to set up with local IP addresses and this is with local IP addresses and this is with local IP addresses and this is technically part three in my ultimate uh technically part three in my ultimate uh technically part three in my ultimate uh proxmox server guide walk through this proxmox server guide walk through this proxmox server guide walk through this is my proxmox server uh compared to last is my proxmox server uh compared to last is my proxmox server uh compared to last time you will notice a minor differences time you will notice a minor differences time you will notice a minor differences I restored my home assistant virtual I restored my home assistant virtual I restored my home assistant virtual machine in here just of course using one machine in here just of course using one machine in here just of course using one of those proxmox helper scripts I do of those proxmox helper scripts I do of those proxmox helper scripts I do have a little window VM if I need access have a little window VM if I need access have a little window VM if I need access to that and we set up proxy here this is to that and we set up proxy here this is to that and we set up proxy here this is what we're going to be doing everything what we're going to be doing everything what we're going to be doing everything on this is an auntu container if you on this is an auntu container if you on this is an auntu container if you haven't seen the previous videos it's haven't seen the previous videos it's haven't seen the previous videos it's basically the exact same setup process basically the exact same setup process basically the exact same setup process of our serve R instance here all the way of our serve R instance here all the way of our serve R instance here all the way up until we installed protainer so you up until we installed protainer so you up until we installed protainer so you just get this you use the abutu 22.041 that is where I'm currently at 22.041 that is where I'm currently at right now with this and this right here right now with this and this right here right now with this and this right here is that protainer instance you could see is that protainer instance you could see is that protainer instance you could see there is nothing going on in here I did there is nothing going on in here I did there is nothing going on in here I did test everything to make sure it works
-
test everything to make sure it works test everything to make sure it works and another thing that is important and another thing that is important and another thing that is important everything that you are going to be everything that you are going to be everything that you are going to be seeing in this video has a companion seeing in this video has a companion seeing in this video has a companion repository over here on GitHub within my repository over here on GitHub within my repository over here on GitHub within my home lab so if you go to home lab you go home lab so if you go to home lab you go home lab so if you go to home lab you go over here to proxy this is absolutely over here to proxy this is absolutely over here to proxy this is absolutely everything that we're going to be doing everything that we're going to be doing everything that we're going to be doing in this video with various tips tricks in this video with various tips tricks in this video with various tips tricks all the specific steps and everything all the specific steps and everything all the specific steps and everything you're going to want to know for example you're going to want to know for example you're going to want to know for example here you could see my personal uh here you could see my personal uh here you could see my personal uh enginex proxy manager compose but if you enginex proxy manager compose but if you enginex proxy manager compose but if you go down here and want to use the go down here and want to use the go down here and want to use the official layout I do have that for you official layout I do have that for you official layout I do have that for you as well as explaining if you want to do as well as explaining if you want to do as well as explaining if you want to do this in bridge mode how that's going to this in bridge mode how that's going to this in bridge mode how that's going to work how to set up uh ddns and work how to set up uh ddns and work how to set up uh ddns and unfortunately my internet provider does unfortunately my internet provider does unfortunately my internet provider does have a dynamic IP address that means have a dynamic IP address that means have a dynamic IP address that means every couple days my IP my public IP every couple days my IP my public IP every couple days my IP my public IP automatically switches up we're going to automatically switches up we're going to automatically switches up we're going to need that in our a records to actually need that in our a records to actually need that in our a records to actually have the domain public but because it have the domain public but because it have the domain public but because it switches up I don't want to have it switches up I don't want to have it switches up I don't want to have it crash and go down all the time and have crash and go down all the time and have crash and go down all the time and have to manually update it so there is a to manually update it so there is a to manually update it so there is a little Cloud flare Docker container that little Cloud flare Docker container that little Cloud flare Docker container that we're going to set up to automatically we're going to set up to automatically we're going to set up to automatically scan our IP address and update it which scan our IP address and update it which scan our IP address and update it which in my testing has been working great in my testing has been working great in my testing has been working great goes over port forwarding and how to do goes over port forwarding and how to do goes over port forwarding and how to do just about everything so if you're more just about everything so if you're more just about everything so if you're more of a reader this will be there and of of a reader this will be there and of of a reader this will be there and of course if you want to go ahead and copy course if you want to go ahead and copy course if you want to go ahead and copy and paste various code this is going to and paste various code this is going to and paste various code this is going to be there as well and the main thing be there as well and the main thing be there as well and the main thing we're going to focus on real quick right we're going to focus on real quick right we're going to focus on real quick right here is this compose yaml this is going here is this compose yaml this is going here is this compose yaml this is going to have everything that I'm going to run to have everything that I'm going to run to have everything that I'm going to run in it we have the proxy here this is in it we have the proxy here this is in it we have the proxy here this is enginex proxy manager we have the uh enginex proxy manager we have the uh enginex proxy manager we have the uh ddns this is cloudflare DD DNS this is ddns this is cloudflare DD DNS this is ddns this is cloudflare DD DNS this is the container that will automatically the container that will automatically the container that will automatically update our IP address our public IP
-
update our IP address our public IP update our IP address our public IP address in the a records of whatever address in the a records of whatever address in the a records of whatever domain we tell it to and then we have a domain we tell it to and then we have a domain we tell it to and then we have a twin gate connector here this is going twin gate connector here this is going twin gate connector here this is going to allow remote connections to services to allow remote connections to services to allow remote connections to services that we don't expose to the open that we don't expose to the open that we don't expose to the open internet and then last but not least we internet and then last but not least we internet and then last but not least we have a little hello world container have a little hello world container have a little hello world container which is going to help us actually test which is going to help us actually test which is going to help us actually test our proxy so jumping right into it I'm our proxy so jumping right into it I'm our proxy so jumping right into it I'm just going to copy this entire thing just going to copy this entire thing just going to copy this entire thing copy so let's add a stack and then all copy so let's add a stack and then all copy so let's add a stack and then all we need to do I'm going to call this we need to do I'm going to call this we need to do I'm going to call this proxy this is my proxy stack and then proxy this is my proxy stack and then proxy this is my proxy stack and then from there I'm going to paste this on in from there I'm going to paste this on in from there I'm going to paste this on in so let's paste it in and the first thing so let's paste it in and the first thing so let's paste it in and the first thing we're going to pay most attention to is we're going to pay most attention to is we're going to pay most attention to is the proxy itself this is engine X proxy the proxy itself this is engine X proxy the proxy itself this is engine X proxy manager gives us a beautiful gooey for manager gives us a beautiful gooey for manager gives us a beautiful gooey for actually managing our subdomains main actually managing our subdomains main actually managing our subdomains main domains SSL certifications everything domains SSL certifications everything domains SSL certifications everything I'm a sucker for a good web guey so the I'm a sucker for a good web guey so the I'm a sucker for a good web guey so the container name we have here restart container name we have here restart container name we have here restart unless stopped I am going to be running unless stopped I am going to be running unless stopped I am going to be running this in network mode host I've had the this in network mode host I've had the this in network mode host I've had the best success with this especially if best success with this especially if best success with this especially if you're trying to proxy containers that you're trying to proxy containers that you're trying to proxy containers that are in the same machine and I will know are in the same machine and I will know are in the same machine and I will know if you do want to run it in bridge mode if you do want to run it in bridge mode if you do want to run it in bridge mode you can see down here an example of that you can see down here an example of that you can see down here an example of that so Network Mode bridge this is an so Network Mode bridge this is an so Network Mode bridge this is an example of changing some of the default example of changing some of the default example of changing some of the default ports and one thing you may need to do ports and one thing you may need to do ports and one thing you may need to do is actually open the port within engine is actually open the port within engine is actually open the port within engine X proxy manager for a service that's X proxy manager for a service that's X proxy manager for a service that's running on a separate machine so for running on a separate machine so for running on a separate machine so for example I have jelly fin in a separate example I have jelly fin in a separate example I have jelly fin in a separate container so I'm going to need to expose container so I'm going to need to expose container so I'm going to need to expose this port within the engine X proxy this port within the engine X proxy this port within the engine X proxy manager kind of similar to what we did manager kind of similar to what we did manager kind of similar to what we did in the last video with our VPN but just in the last video with our VPN but just in the last video with our VPN but just to avoid all that I just run a network to avoid all that I just run a network to avoid all that I just run a network mode or host mode the main thing you mode or host mode the main thing you mode or host mode the main thing you want to be aware of is on this machine want to be aware of is on this machine want to be aware of is on this machine since it is using your host Network make
-
since it is using your host Network make since it is using your host Network make sure no other services are using the sure no other services are using the sure no other services are using the port 80 81 or 443 for volumes I just do port 80 81 or 443 for volumes I just do port 80 81 or 443 for volumes I just do two regular volumes you could bind Mount two regular volumes you could bind Mount two regular volumes you could bind Mount this if you want to but I found that this if you want to but I found that this if you want to but I found that this typically works the best I have one this typically works the best I have one this typically works the best I have one volume data and one volume let's encrypt volume data and one volume let's encrypt volume data and one volume let's encrypt and since we are doing this in a stack and since we are doing this in a stack and since we are doing this in a stack it will have the prefix for proxy or it will have the prefix for proxy or it will have the prefix for proxy or whatever you name it there so you'll be whatever you name it there so you'll be whatever you name it there so you'll be able to tell the different volumes that able to tell the different volumes that able to tell the different volumes that you have running on your uh instance you have running on your uh instance you have running on your uh instance here of course we have a health check here of course we have a health check here of course we have a health check there and really there is nothing else there and really there is nothing else there and really there is nothing else you need to do to go ahead and set this you need to do to go ahead and set this you need to do to go ahead and set this up this is probably one of the easiest up this is probably one of the easiest up this is probably one of the easiest Docker containers to go ahead and spin Docker containers to go ahead and spin Docker containers to go ahead and spin up as long as you have an understanding up as long as you have an understanding up as long as you have an understanding of the difference between the host and of the difference between the host and of the difference between the host and Bridge networks and some of the Bridge networks and some of the Bridge networks and some of the differences that may cause in your differences that may cause in your differences that may cause in your configuration next we have ddns this is configuration next we have ddns this is configuration next we have ddns this is using this container right here from using this container right here from using this container right here from faviana I think so container name and faviana I think so container name and faviana I think so container name and let stop it does have user permissions let stop it does have user permissions let stop it does have user permissions so I'm using a th000 a th000 for this so I'm using a th000 a th000 for this so I'm using a th000 a th000 for this one this is just my current user one this is just my current user one this is just my current user permissions and then for the most part I permissions and then for the most part I permissions and then for the most part I go with all of the default settings so I go with all of the default settings so I go with all of the default settings so I have read only to True cap drop all you have read only to True cap drop all you have read only to True cap drop all you can read more about that here and in can read more about that here and in can read more about that here and in their official repository and security their official repository and security their official repository and security opt no new privileges true I went ahead opt no new privileges true I went ahead opt no new privileges true I went ahead and disabled and disabled and disabled IPv6 because I just don't use it at the IPv6 because I just don't use it at the IPv6 because I just don't use it at the moment and because of that I disabled moment and because of that I disabled moment and because of that I disabled Network Mode host so now it's just going Network Mode host so now it's just going Network Mode host so now it's just going to be in bridge mode this makes it to be in bridge mode this makes it to be in bridge mode this makes it easier for I IPv6 to work uh completely easier for I IPv6 to work uh completely easier for I IPv6 to work uh completely optional and then here these are the optional and then here these are the optional and then here these are the environmental variables that you are environmental variables that you are environmental variables that you are actually going to want to kind of play actually going to want to kind of play actually going to want to kind of play around with here is going to be your around with here is going to be your around with here is going to be your Cloud flare API token which I'll show Cloud flare API token which I'll show Cloud flare API token which I'll show you how to get these are going to be
-
you how to get these are going to be you how to get these are going to be your domain names that you want it to your domain names that you want it to your domain names that you want it to push to Cloud flare to go ahead and push to Cloud flare to go ahead and push to Cloud flare to go ahead and update that IP address in an a record update that IP address in an a record update that IP address in an a record and I keep proxy to true and ip6 and I keep proxy to true and ip6 and I keep proxy to true and ip6 provider to none and then we have our provider to none and then we have our provider to none and then we have our twin gate connector and I'm actually twin gate connector and I'm actually twin gate connector and I'm actually just going to get rid of this for now just going to get rid of this for now just going to get rid of this for now because I don't want this to spin up and because I don't want this to spin up and because I don't want this to spin up and throw a bunch of Errors at me we're throw a bunch of Errors at me we're throw a bunch of Errors at me we're going to set that up near the end of going to set that up near the end of going to set that up near the end of this video and of course just for a this video and of course just for a this video and of course just for a simple little web page spun up easy for simple little web page spun up easy for simple little web page spun up easy for testing I have this hello world testing I have this hello world testing I have this hello world container running on the port container running on the port container running on the port 8888 and then we have our volumes here 8888 and then we have our volumes here 8888 and then we have our volumes here data and let's encrypt so now for this data and let's encrypt so now for this data and let's encrypt so now for this part of the video I'm going to be part of the video I'm going to be part of the video I'm going to be focusing on setting up a ddns getting focusing on setting up a ddns getting focusing on setting up a ddns getting our Cloud FL API key and plugging in our Cloud FL API key and plugging in our Cloud FL API key and plugging in some domain names here so this right some domain names here so this right some domain names here so this right here is the cloud flare overview for the here is the cloud flare overview for the here is the cloud flare overview for the domain name that we're going to make domain name that we're going to make domain name that we're going to make public for this one I'm going to be public for this one I'm going to be public for this one I'm going to be blurring it throughout the video because blurring it throughout the video because blurring it throughout the video because I don't want it to be something people I don't want it to be something people I don't want it to be something people try to go to a lot because it's for me try to go to a lot because it's for me try to go to a lot because it's for me and a select group of people so for this and a select group of people so for this and a select group of people so for this one the first thing recommend here is go one the first thing recommend here is go one the first thing recommend here is go under SSL TLS and click on that and then under SSL TLS and click on that and then under SSL TLS and click on that and then here under SSL TLS encryption you might here under SSL TLS encryption you might here under SSL TLS encryption you might have it set to partial to start but have it set to partial to start but have it set to partial to start but you're going to want to go ahead and you're going to want to go ahead and you're going to want to go ahead and click configure and make sure you select click configure and make sure you select click configure and make sure you select full full is what I found to be the one full full is what I found to be the one full full is what I found to be the one that works the best overall with uh that works the best overall with uh that works the best overall with uh using it with in Genex proxy manager if using it with in Genex proxy manager if using it with in Genex proxy manager if you use strict you're going to have to you use strict you're going to have to you use strict you're going to have to use cloudflare API keys and I've noticed use cloudflare API keys and I've noticed use cloudflare API keys and I've noticed flexible doesn't work with some Services flexible doesn't work with some Services flexible doesn't work with some Services I was having issues with jelly fin using I was having issues with jelly fin using I was having issues with jelly fin using flexible so I've had the best look with flexible so I've had the best look with flexible so I've had the best look with full but depending on your service is full but depending on your service is full but depending on your service is you may want to kind of play around with you may want to kind of play around with you may want to kind of play around with this so now the fun part let's go over this so now the fun part let's go over this so now the fun part let's go over to DNS and head over to records what to DNS and head over to records what to DNS and head over to records what we're going to want to do here is create
-
we're going to want to do here is create we're going to want to do here is create some records so first I'm going to add a some records so first I'm going to add a some records so first I'm going to add a record for my rout just like so and for record for my rout just like so and for record for my rout just like so and for the ipv4 honestly right now I'm not the ipv4 honestly right now I'm not the ipv4 honestly right now I'm not going to put in my public IP address going to put in my public IP address going to put in my public IP address because I want to actually make sure because I want to actually make sure because I want to actually make sure that this is going to work so I'm going that this is going to work so I'm going that this is going to work so I'm going to put in something random maybe uh to put in something random maybe uh to put in something random maybe uh something like 8.8.8.8 and then save something like 8.8.8.8 and then save something like 8.8.8.8 and then save that there we go so now we have that and that there we go so now we have that and that there we go so now we have that and the uh container that we're setting up the uh container that we're setting up the uh container that we're setting up right now should automatically up that right now should automatically up that right now should automatically up that now additionally what I'm going to do is now additionally what I'm going to do is now additionally what I'm going to do is create another one for jelly fin create another one for jelly fin create another one for jelly fin technically right now if you wanted to technically right now if you wanted to technically right now if you wanted to if you're not going to use media if you're not going to use media if you're not going to use media streaming you could set this up as a c streaming you could set this up as a c streaming you could set this up as a c name put in an asterisk and then set it name put in an asterisk and then set it name put in an asterisk and then set it to whatever your domain name is but one to whatever your domain name is but one to whatever your domain name is but one thing that's important to know is under thing that's important to know is under thing that's important to know is under the uh Cloud flare terms and conditions the uh Cloud flare terms and conditions the uh Cloud flare terms and conditions you can't use their proxy service to do you can't use their proxy service to do you can't use their proxy service to do media streaming so in order to not break media streaming so in order to not break media streaming so in order to not break the to I'm going to create a new a the to I'm going to create a new a the to I'm going to create a new a record I'm going to call this uh jelly record I'm going to call this uh jelly record I'm going to call this uh jelly fin actually for this one I'm going to fin actually for this one I'm going to fin actually for this one I'm going to do I'm going to call this stream stream do I'm going to call this stream stream do I'm going to call this stream stream like like like that and I'm going to disable the proxy that and I'm going to disable the proxy that and I'm going to disable the proxy just for this one because I don't want just for this one because I don't want just for this one because I don't want to break their terms of service here I'm to break their terms of service here I'm to break their terms of service here I'm going to put another random IP address going to put another random IP address going to put another random IP address and then hit save so now you can see I and then hit save so now you can see I and then hit save so now you can see I have stream at this IP and then my have stream at this IP and then my have stream at this IP and then my domain at this IP without a proxy on domain at this IP without a proxy on domain at this IP without a proxy on this one again I'm only doing that not this one again I'm only doing that not this one again I'm only doing that not to break their terms of service so now to break their terms of service so now to break their terms of service so now now we're going to want to go and grab now we're going to want to go and grab now we're going to want to go and grab the API key so this will automatically the API key so this will automatically the API key so this will automatically update to do that we're just going to go update to do that we're just going to go update to do that we're just going to go over to our profile go over to my over to our profile go over to my over to our profile go over to my profile and then here under API tokens
-
profile and then here under API tokens profile and then here under API tokens you can see I have one right here I'm you can see I have one right here I'm you can see I have one right here I'm not using it anymore so I'm going to go not using it anymore so I'm going to go not using it anymore so I'm going to go ahead and delete this and then create a ahead and delete this and then create a ahead and delete this and then create a new token this token the only thing we new token this token the only thing we new token this token the only thing we really need it to do is edit Zone DNS so really need it to do is edit Zone DNS so really need it to do is edit Zone DNS so we're going to click use template here we're going to click use template here we're going to click use template here Zone DNS edit looks good include we're Zone DNS edit looks good include we're Zone DNS edit looks good include we're going to do all zones and that should be going to do all zones and that should be going to do all zones and that should be everything that we need to do at least everything that we need to do at least everything that we need to do at least for now so let's go ahead and continue for now so let's go ahead and continue for now so let's go ahead and continue to summary create the token and then to summary create the token and then to summary create the token and then here is our token I'm just going to give here is our token I'm just going to give here is our token I'm just going to give that a copy head back over to portainer that a copy head back over to portainer that a copy head back over to portainer and then paste that in so now we have and then paste that in so now we have and then paste that in so now we have our key pasted now right here under our key pasted now right here under our key pasted now right here under domains I'm going to add the root domain domains I'm going to add the root domain domains I'm going to add the root domain so whatever your domain is dot at so whatever your domain is dot at so whatever your domain is dot at whatever it is and then that subdomain whatever it is and then that subdomain whatever it is and then that subdomain we just created which for me is going to we just created which for me is going to we just created which for me is going to be stream at my domain just like that so be stream at my domain just like that so be stream at my domain just like that so in this entire Docker composed that in this entire Docker composed that in this entire Docker composed that should be really the only thing I need should be really the only thing I need should be really the only thing I need to edit to get this going so I'm going to edit to get this going so I'm going to edit to get this going so I'm going to click on deploy the stack here and to click on deploy the stack here and to click on deploy the stack here and give it a minute to pull all the give it a minute to pull all the give it a minute to pull all the containers and everything that it needs containers and everything that it needs containers and everything that it needs to do so we have a success so if I head to do so we have a success so if I head to do so we have a success so if I head over here to Containers we can see the over here to Containers we can see the over here to Containers we can see the containers running and starting and containers running and starting and containers running and starting and check the logs of proxy manager and it check the logs of proxy manager and it check the logs of proxy manager and it looks like everything is going good so looks like everything is going good so looks like everything is going good so it's just taking a sec to start up and it's just taking a sec to start up and it's just taking a sec to start up and let's check the logs of this cloudflare let's check the logs of this cloudflare let's check the logs of this cloudflare ddns which it looks like it's good we ddns which it looks like it's good we ddns which it looks like it's good we updated a stale a record of my domain updated a stale a record of my domain updated a stale a record of my domain name and there we go so this is DNS name and there we go so this is DNS name and there we go so this is DNS under that domain name and you can see under that domain name and you can see under that domain name and you can see that my IP address has updated to my that my IP address has updated to my that my IP address has updated to my actual Current public IP address and actual Current public IP address and actual Current public IP address and that container is set up to scan your IP that container is set up to scan your IP that container is set up to scan your IP address every 5 minutes and address every 5 minutes and address every 5 minutes and automatically update the a records in automatically update the a records in automatically update the a records in cloudflare again if you have a static cloudflare again if you have a static cloudflare again if you have a static public IP you don't need to worry about
-
public IP you don't need to worry about public IP you don't need to worry about this step so now we're going to have to this step so now we're going to have to this step so now we're going to have to do some port forwarding we're going to do some port forwarding we're going to do some port forwarding we're going to open up 80 and 443 so that way Cloud open up 80 and 443 so that way Cloud open up 80 and 443 so that way Cloud flare can communicate to it and we can flare can communicate to it and we can flare can communicate to it and we can actually have the domain work and I will actually have the domain work and I will actually have the domain work and I will know out of everything we're doing this know out of everything we're doing this know out of everything we're doing this is technically the most dangerous step is technically the most dangerous step is technically the most dangerous step and there are additional things you can and there are additional things you can and there are additional things you can do to further the security so at the do to further the security so at the do to further the security so at the moment here I using omada these steps moment here I using omada these steps moment here I using omada these steps are going to vary wildly depending on are going to vary wildly depending on are going to vary wildly depending on the router the home network system that the router the home network system that the router the home network system that you happen to be using so do note that you happen to be using so do note that you happen to be using so do note that uh you may have to look up to where port uh you may have to look up to where port uh you may have to look up to where port forwarding is in your specific UI and forwarding is in your specific UI and forwarding is in your specific UI and all that for me it's under settings and all that for me it's under settings and all that for me it's under settings and then we go to transmission natat and then we go to transmission natat and then we go to transmission natat and this is the port forwarding here I've this is the port forwarding here I've this is the port forwarding here I've already done it for HTTP and https but already done it for HTTP and https but already done it for HTTP and https but just so I can give you a little just so I can give you a little just so I can give you a little explanation of something if I click edit explanation of something if I click edit explanation of something if I click edit here for https we have the name of it here for https we have the name of it here for https we have the name of it we're going to set it to the destination we're going to set it to the destination we're going to set it to the destination IP which is the IP address or the local IP which is the IP address or the local IP which is the IP address or the local IP address of whatever the container IP address of whatever the container IP address of whatever the container machine whatever you happen to have machine whatever you happen to have machine whatever you happen to have installed uh enginex proxy manager on so installed uh enginex proxy manager on so installed uh enginex proxy manager on so do note that we have our source port and do note that we have our source port and do note that we have our source port and our destination Port if you're running our destination Port if you're running our destination Port if you're running it under host 443 for both but if you do it under host 443 for both but if you do it under host 443 for both but if you do decide to do a bridge Network and do a decide to do a bridge Network and do a decide to do a bridge Network and do a custom port for these specific you may custom port for these specific you may custom port for these specific you may have some slight changes to do so down have some slight changes to do so down have some slight changes to do so down here I give a little explanation of the here I give a little explanation of the here I give a little explanation of the difference between the source port and difference between the source port and difference between the source port and and the destination Port initiating the and the destination Port initiating the and the destination Port initiating the communication is going to be the source communication is going to be the source communication is going to be the source Port so the initiator is going to be Port so the initiator is going to be Port so the initiator is going to be Cloud flare so 443 is going to be that Cloud flare so 443 is going to be that Cloud flare so 443 is going to be that and the destination Port is going to be
-
and the destination Port is going to be and the destination Port is going to be whatever you happen to set that port to whatever you happen to set that port to whatever you happen to set that port to so in my bridge mode example I used 580 so in my bridge mode example I used 580 so in my bridge mode example I used 580 and 5443 so I would set the destination and 5443 so I would set the destination and 5443 so I would set the destination port to 5443 and the source port to 443 port to 5443 and the source port to 443 port to 5443 and the source port to 443 so we have it just like that you click so we have it just like that you click so we have it just like that you click apply you add it for HTTP if you are apply you add it for HTTP if you are apply you add it for HTTP if you are going to want to use that for something going to want to use that for something going to want to use that for something some Services might require it but then some Services might require it but then some Services might require it but then from there we should be good to go ahead from there we should be good to go ahead from there we should be good to go ahead and set up our actual uh proxies so and set up our actual uh proxies so and set up our actual uh proxies so engine X proxy manager is the port 81 engine X proxy manager is the port 81 engine X proxy manager is the port 81 for this machine so you can see this is for this machine so you can see this is for this machine so you can see this is 203 what you saw in port forwarding 203 what you saw in port forwarding 203 what you saw in port forwarding there so we' go to 10.0.0 there so we' go to 10.0.0 there so we' go to 10.0.0 203 and the port 203 and the port 203 and the port 81 just like that and here's engine X 81 just like that and here's engine X 81 just like that and here's engine X proxy manager what are the default proxy manager what are the default proxy manager what are the default credentials so the email is going to be credentials so the email is going to be credentials so the email is going to be admin example.com and then our password admin example.com and then our password admin example.com and then our password is going to be change me so here go is going to be change me so here go is going to be change me so here go ahead and set up your account so fill in ahead and set up your account so fill in ahead and set up your account so fill in your user and then hit save and then your user and then hit save and then your user and then hit save and then it's going to ask us to change our it's going to ask us to change our it's going to ask us to change our password just like that so let's click password just like that so let's click password just like that so let's click save and there we go so now let's first save and there we go so now let's first save and there we go so now let's first generate our SSL certificate for our generate our SSL certificate for our generate our SSL certificate for our public domain so I'm going to add SSL public domain so I'm going to add SSL public domain so I'm going to add SSL certificate so first you're going to certificate so first you're going to certificate so first you're going to type in your root domain name and click type in your root domain name and click type in your root domain name and click on ADD and then I believe a wild card is on ADD and then I believe a wild card is on ADD and then I believe a wild card is going to work just for generating this going to work just for generating this going to work just for generating this certificate so there you go add that certificate so there you go add that certificate so there you go add that with a wild card and then here you're with a wild card and then here you're with a wild card and then here you're going to want to click on use a DNS going to want to click on use a DNS going to want to click on use a DNS challenge for this we're going to select challenge for this we're going to select challenge for this we're going to select our provider which is going to be our provider which is going to be our provider which is going to be cloudflare and then here for the API cloudflare and then here for the API cloudflare and then here for the API token we're just going to paste in the token we're just going to paste in the token we're just going to paste in the one that we saved earlier if you did set
-
one that we saved earlier if you did set one that we saved earlier if you did set up that uh ddns it's in your stack up that uh ddns it's in your stack up that uh ddns it's in your stack propagation seconds we could set that to propagation seconds we could set that to propagation seconds we could set that to nothing if you have errors setting it to nothing if you have errors setting it to nothing if you have errors setting it to like 120 sometimes resolves that but like 120 sometimes resolves that but like 120 sometimes resolves that but we're going to go ahead and click on we're going to go ahead and click on we're going to go ahead and click on Save and we're going to see if it Save and we're going to see if it Save and we're going to see if it generates them and there we go we have generates them and there we go we have generates them and there we go we have the SSL certificates for the subdomains the SSL certificates for the subdomains the SSL certificates for the subdomains as well as route so now let's go ahead as well as route so now let's go ahead as well as route so now let's go ahead and create a new host so let's go over and create a new host so let's go over and create a new host so let's go over to hosts proxy hosts add a proxy host to hosts proxy hosts add a proxy host to hosts proxy hosts add a proxy host and just the test list to verify and just the test list to verify and just the test list to verify everything's working I'm going to point everything's working I'm going to point everything's working I'm going to point my root to that hello world container so my root to that hello world container so my root to that hello world container so type in your root domain here and add it type in your root domain here and add it type in your root domain here and add it and since this is in the same stack and and since this is in the same stack and and since this is in the same stack and I'm running this uh proxy manager as the I'm running this uh proxy manager as the I'm running this uh proxy manager as the or on the host Network I can just type or on the host Network I can just type or on the host Network I can just type in Local Host and this is going to be on in Local Host and this is going to be on in Local Host and this is going to be on the port 8888 now for here we can block the port 8888 now for here we can block the port 8888 now for here we can block common I'm going to head over to s SL common I'm going to head over to s SL common I'm going to head over to s SL and then pick the certificate that we and then pick the certificate that we and then pick the certificate that we generated right here and I'm going to generated right here and I'm going to generated right here and I'm going to set up Force SSL just to make sure that set up Force SSL just to make sure that set up Force SSL just to make sure that works actually I might as well just works actually I might as well just works actually I might as well just enable all this and then click on Save enable all this and then click on Save enable all this and then click on Save depending on the service you're running depending on the service you're running depending on the service you're running you may need to customize this I know you may need to customize this I know you may need to customize this I know jelly fin that you'll see has a whole jelly fin that you'll see has a whole jelly fin that you'll see has a whole separate thing that we're going to have separate thing that we're going to have separate thing that we're going to have to paste in but for now if I go ahead to paste in but for now if I go ahead to paste in but for now if I go ahead and just click on this Boop there you go and just click on this Boop there you go and just click on this Boop there you go it takes us to our kind of hello world it takes us to our kind of hello world it takes us to our kind of hello world container and if I get my phone I'm container and if I get my phone I'm container and if I get my phone I'm going to disconnect it from my Wi-Fi going to disconnect it from my Wi-Fi going to disconnect it from my Wi-Fi network and if I head over to that network and if I head over to that network and if I head over to that domain well what do you know it's domain well what do you know it's domain well what do you know it's working on the open web and it's proxied working on the open web and it's proxied working on the open web and it's proxied through Cloud flare so your actual IP through Cloud flare so your actual IP through Cloud flare so your actual IP address is going to be hidden so now address is going to be hidden so now address is going to be hidden so now we're going to do jelly Fin and I'm we're going to do jelly Fin and I'm we're going to do jelly Fin and I'm going to show you some tips and tricks going to show you some tips and tricks going to show you some tips and tricks and whatnot to get this to work properly
-
and whatnot to get this to work properly and whatnot to get this to work properly my jelly fin is at 205 my jelly fin is at 205 my jelly fin is at 205 896 and you can see here it's not secure 896 and you can see here it's not secure 896 and you can see here it's not secure it's local but one thing I need to do to it's local but one thing I need to do to it's local but one thing I need to do to get proxy to work is let's go over to get proxy to work is let's go over to get proxy to work is let's go over to Administration dashboard and then we go Administration dashboard and then we go Administration dashboard and then we go under networking here what we're going under networking here what we're going under networking here what we're going to want to do is go over to known to want to do is go over to known to want to do is go over to known proxies can see I have something in here proxies can see I have something in here proxies can see I have something in here I have changed it since then this is I have changed it since then this is I have changed it since then this is going to be on 203 that is the IP going to be on 203 that is the IP going to be on 203 that is the IP address of the uh container or machine address of the uh container or machine address of the uh container or machine that's running enginex proxy manager and that's running enginex proxy manager and that's running enginex proxy manager and here on the jellyfin documentation if I here on the jellyfin documentation if I here on the jellyfin documentation if I go over to enginex proxy manager we are go over to enginex proxy manager we are go over to enginex proxy manager we are going to want to paste this in so I'm going to want to paste this in so I'm going to want to paste this in so I'm just going to grab this give that a copy just going to grab this give that a copy just going to grab this give that a copy and then under engine X proxy manager and then under engine X proxy manager and then under engine X proxy manager we're going to create a new host for we're going to create a new host for we're going to create a new host for jelly fin so let's add a proxy host and jelly fin so let's add a proxy host and jelly fin so let's add a proxy host and then for the domain name I'm going to do then for the domain name I'm going to do then for the domain name I'm going to do stream. my domain name click on ADD and stream. my domain name click on ADD and stream. my domain name click on ADD and then for here the scheme is HTTP the then for here the scheme is HTTP the then for here the scheme is HTTP the only time you're really going to want to only time you're really going to want to only time you're really going to want to change this if your local service kind change this if your local service kind change this if your local service kind of defaults to https or if you manually of defaults to https or if you manually of defaults to https or if you manually kind of configured it to do that so for kind of configured it to do that so for kind of configured it to do that so for the Ford name IP this is going to be the the Ford name IP this is going to be the the Ford name IP this is going to be the IP of jelly fin which is at 205 and it IP of jelly fin which is at 205 and it IP of jelly fin which is at 205 and it is at and that's at is at and that's at is at and that's at 896 so here I'm going to block enable 896 so here I'm going to block enable 896 so here I'm going to block enable websocket support and then I'm going to websocket support and then I'm going to websocket support and then I'm going to go under Advanced paste in that custom go under Advanced paste in that custom go under Advanced paste in that custom configuration go over to SSL add the configuration go over to SSL add the configuration go over to SSL add the Wild Card certificate I'm going to force Wild Card certificate I'm going to force Wild Card certificate I'm going to force SSL and just enable everything and then SSL and just enable everything and then SSL and just enable everything and then click on save so now if I head over here click on save so now if I head over here click on save so now if I head over here it should work there we go now one thing
-
it should work there we go now one thing it should work there we go now one thing I'm going to touch on real quick is I'm going to touch on real quick is I'm going to touch on real quick is something called custom location so something called custom location so something called custom location so instead of using a uh subdomain in the instead of using a uh subdomain in the instead of using a uh subdomain in the beginning of your name we could use kind beginning of your name we could use kind beginning of your name we could use kind of a directory scheme to actually set up of a directory scheme to actually set up of a directory scheme to actually set up our proxies so for the stream subdomain our proxies so for the stream subdomain our proxies so for the stream subdomain that I'm going to be using I'm going to that I'm going to be using I'm going to that I'm going to be using I'm going to have a couple different services that have a couple different services that have a couple different services that are able to stream because I want them are able to stream because I want them are able to stream because I want them all to be on that a record that isn't all to be on that a record that isn't all to be on that a record that isn't proxied or at least proxied through proxied or at least proxied through proxied or at least proxied through cloudflare so with this for jelly fin cloudflare so with this for jelly fin cloudflare so with this for jelly fin specifically re we want to go back to specifically re we want to go back to specifically re we want to go back to where we were in our admin settings where we were in our admin settings where we were in our admin settings under networking here is our base URL so under networking here is our base URL so under networking here is our base URL so you can see add a custom subdirectory you can see add a custom subdirectory you can see add a custom subdirectory for the server URL for example this is for the server URL for example this is for the server URL for example this is the example and this I'm just going to the example and this I'm just going to the example and this I'm just going to put it under jelly Fin and then go down put it under jelly Fin and then go down put it under jelly Fin and then go down and save it for a lot of these and save it for a lot of these and save it for a lot of these configuration changes it is going to configuration changes it is going to configuration changes it is going to require a restart from jelly fin so I'm require a restart from jelly fin so I'm require a restart from jelly fin so I'm going to go ahead and Rebo it yes and going to go ahead and Rebo it yes and going to go ahead and Rebo it yes and then over here under that stream then over here under that stream then over here under that stream subdomain I'm going to go ahead and subdomain I'm going to go ahead and subdomain I'm going to go ahead and click right here and then edit it and click right here and then edit it and click right here and then edit it and then right here under custom locations I then right here under custom locations I then right here under custom locations I can add a location this is going to be can add a location this is going to be can add a location this is going to be under the path jelly Fin and we're going under the path jelly Fin and we're going under the path jelly Fin and we're going to put in some of the same stuff so 205 to put in some of the same stuff so 205 to put in some of the same stuff so 205 AT AT AT 8096 I'm going to go back and grab that 8096 I'm going to go back and grab that 8096 I'm going to go back and grab that advanced config go back to custom advanced config go back to custom advanced config go back to custom locations and drop it in here and then locations and drop it in here and then locations and drop it in here and then click on save so now if I change this to click on save so now if I change this to click on save so now if I change this to for slash jelly fin hit enter for slash jelly fin hit enter for slash jelly fin hit enter you can see I'm now using a custom you can see I'm now using a custom you can see I'm now using a custom location for the specific service but location for the specific service but location for the specific service but now we are going to set it up for local now we are going to set it up for local now we are going to set it up for local top level domains so this is not going top level domains so this is not going top level domains so this is not going to have any external access whatsoever to have any external access whatsoever to have any external access whatsoever you can only access this domain that
-
you can only access this domain that you can only access this domain that we're about to set up if I'm either we're about to set up if I'm either we're about to set up if I'm either actually in my home network or if I'm actually in my home network or if I'm actually in my home network or if I'm using some either a VPN provider or using some either a VPN provider or using some either a VPN provider or something like twin gate So within something like twin gate So within something like twin gate So within cloudflare you can see I have two domain cloudflare you can see I have two domain cloudflare you can see I have two domain names this is the public one right here names this is the public one right here names this is the public one right here and this is going to be my local domain and this is going to be my local domain and this is going to be my local domain I'm going to go ahe and give that a I'm going to go ahe and give that a I'm going to go ahe and give that a click and all we have to do is head over click and all we have to do is head over click and all we have to do is head over to DNS and you can see I already have to DNS and you can see I already have to DNS and you can see I already have some record set up right here Hop key. some record set up right here Hop key. some record set up right here Hop key. net we created an a record and I'm net we created an a record and I'm net we created an a record and I'm pointing this to the internal IP address pointing this to the internal IP address pointing this to the internal IP address of enginex proxy manager so that way of enginex proxy manager so that way of enginex proxy manager so that way whenever I go to hopkey Donnet and it whenever I go to hopkey Donnet and it whenever I go to hopkey Donnet and it asks my DNS server where is this IP it's asks my DNS server where is this IP it's asks my DNS server where is this IP it's going to give it a local IP address and going to give it a local IP address and going to give it a local IP address and that's how it's going to go ahead and that's how it's going to go ahead and that's how it's going to go ahead and connect and if you're outside of your connect and if you're outside of your connect and if you're outside of your home network and you're not using some home network and you're not using some home network and you're not using some other service you try to access this other service you try to access this other service you try to access this it's going to just navigate to this IP it's going to just navigate to this IP it's going to just navigate to this IP address and it's probably not going to address and it's probably not going to address and it's probably not going to work unless if that person has something work unless if that person has something work unless if that person has something oddly specifically set up the same as oddly specifically set up the same as oddly specifically set up the same as you for this one I don't need to you for this one I don't need to you for this one I don't need to separate out a record so I did just do a separate out a record so I did just do a separate out a record so I did just do a wild card as a c name for that domain wild card as a c name for that domain wild card as a c name for that domain right here so once you have all that in right here so once you have all that in right here so once you have all that in place all we need to do is go generate place all we need to do is go generate place all we need to do is go generate those certificates so here under SSL those certificates so here under SSL those certificates so here under SSL certificate we're going to add a new certificate we're going to add a new certificate we're going to add a new let's encrypt one and we're going to put let's encrypt one and we're going to put let's encrypt one and we're going to put in the local domain so let's go ahead in the local domain so let's go ahead in the local domain so let's go ahead and add that and then let's add the wild and add that and then let's add the wild and add that and then let's add the wild card so star . hop. net boom and again card so star . hop. net boom and again card so star . hop. net boom and again we're going to want to use a DNS we're going to want to use a DNS we're going to want to use a DNS challenge choose cloudflare as our challenge choose cloudflare as our challenge choose cloudflare as our provider and then drop in your uh API provider and then drop in your uh API provider and then drop in your uh API token right here let's agree to the token right here let's agree to the token right here let's agree to the terms of service and then click on Save
-
terms of service and then click on Save terms of service and then click on Save do note when you change your a records do note when you change your a records do note when you change your a records and if this doesn't work like right and if this doesn't work like right and if this doesn't work like right after you did it it probably just needs after you did it it probably just needs after you did it it probably just needs a little bit of time for the actual a little bit of time for the actual a little bit of time for the actual domain name server that you're using to domain name server that you're using to domain name server that you're using to propagate and know what it's trying to propagate and know what it's trying to propagate and know what it's trying to connect to so there we go we now have connect to so there we go we now have connect to so there we go we now have Hop key. net so now I'm going to head Hop key. net so now I'm going to head Hop key. net so now I'm going to head back over to proxy hosts and we can test back over to proxy hosts and we can test back over to proxy hosts and we can test it with that hello world so let's go it with that hello world so let's go it with that hello world so let's go right here domain name let's let's just right here domain name let's let's just right here domain name let's let's just throw this on a subdomain so hello. Hop throw this on a subdomain so hello. Hop throw this on a subdomain so hello. Hop key. net add that this is currently key. net add that this is currently key. net add that this is currently under our local host and it's on the under our local host and it's on the under our local host and it's on the port 8888 so from there we go SSL we port 8888 so from there we go SSL we port 8888 so from there we go SSL we could select the SSL for hopkey Donnet could select the SSL for hopkey Donnet could select the SSL for hopkey Donnet that we created goe and force it and that we created goe and force it and that we created goe and force it and select all of that save it and now if I select all of that save it and now if I select all of that save it and now if I navigate to hello . hop. net there we go navigate to hello . hop. net there we go navigate to hello . hop. net there we go hello is it me you're looking for so hello is it me you're looking for so hello is it me you're looking for so really actually a pretty easy thing to really actually a pretty easy thing to really actually a pretty easy thing to go ahead and set up now let's say in go ahead and set up now let's say in go ahead and set up now let's say in theory I wanted to go ahead and access theory I wanted to go ahead and access theory I wanted to go ahead and access this proxmox right here so if I go over this proxmox right here so if I go over this proxmox right here so if I go over here let's add a proxy Host this is here let's add a proxy Host this is here let's add a proxy Host this is going to be proxmox do poopy. net this going to be proxmox do poopy. net this going to be proxmox do poopy. net this scheme is https by default whoops add scheme is https by default whoops add scheme is https by default whoops add that so this is at 10 0 0 and then here that so this is at 10 0 0 and then here that so this is at 10 0 0 and then here 86 it's an able websocket support and 86 it's an able websocket support and 86 it's an able websocket support and then go to our SSL certificate add the then go to our SSL certificate add the then go to our SSL certificate add the one for hop. net that we generated let's one for hop. net that we generated let's one for hop. net that we generated let's go ahead and force it and hit save so go ahead and force it and hit save so go ahead and force it and hit save so now if I click on this go over to now if I click on this go over to now if I click on this go over to proxmox dohop key. net well will you proxmox dohop key. net well will you proxmox dohop key. net well will you look at that log in here and then you look at that log in here and then you look at that log in here and then you can see my domain is at proxmox hop. net
-
can see my domain is at proxmox hop. net can see my domain is at proxmox hop. net with a let's encrypt signed certificate with a let's encrypt signed certificate with a let's encrypt signed certificate so now I'm not going to get that warning so now I'm not going to get that warning so now I'm not going to get that warning every time I open up proxmox and I don't every time I open up proxmox and I don't every time I open up proxmox and I don't have to remember the IP address because have to remember the IP address because have to remember the IP address because it's just proxmox do example.com or it's just proxmox do example.com or it's just proxmox do example.com or whatever yours is so now this domain is whatever yours is so now this domain is whatever yours is so now this domain is locally accessible but not accessible locally accessible but not accessible locally accessible but not accessible publicly but let's say I am publicly and publicly but let's say I am publicly and publicly but let's say I am publicly and I want to access it I want to do that I want to access it I want to do that I want to access it I want to do that securely and that is where twin gate securely and that is where twin gate securely and that is where twin gate comes in so on our GitHub page here we comes in so on our GitHub page here we comes in so on our GitHub page here we removed it earlier but I'm going to read removed it earlier but I'm going to read removed it earlier but I'm going to read it and that is our twin gate connector it and that is our twin gate connector it and that is our twin gate connector here so I'm going to give this a copy here so I'm going to give this a copy here so I'm going to give this a copy and I'm going to drop it in right here and I'm going to drop it in right here and I'm going to drop it in right here so here's our twin gate connector we're so here's our twin gate connector we're so here's our twin gate connector we're going to need some things we're going to going to need some things we're going to going to need some things we're going to need our tenant name our access token need our tenant name our access token need our tenant name our access token and a refresh token now I already have a and a refresh token now I already have a and a refresh token now I already have a twin gate account you go ahead and twin gate account you go ahead and twin gate account you go ahead and create one it's really easy this right create one it's really easy this right create one it's really easy this right here mine is just Tech hut. tate.com so here mine is just Tech hut. tate.com so here mine is just Tech hut. tate.com so I'd goe copy that and drop it under the I'd goe copy that and drop it under the I'd goe copy that and drop it under the name and then basically with twin gate name and then basically with twin gate name and then basically with twin gate there's only a few parts right here there's only a few parts right here there's only a few parts right here under Network insights we have resources under Network insights we have resources under Network insights we have resources remote networks and active remote networks and active remote networks and active devices our remote network is the main devices our remote network is the main devices our remote network is the main Network so you're going to want to Network so you're going to want to Network so you're going to want to create one of those and then under that create one of those and then under that create one of those and then under that Network you're going to want to create Network you're going to want to create Network you're going to want to create some connectors so you can see here I some connectors so you can see here I some connectors so you can see here I have one connector that I have spun up have one connector that I have spun up have one connector that I have spun up on my unraid machine but I want to spin on my unraid machine but I want to spin on my unraid machine but I want to spin up another one on on proxmox and it's up another one on on proxmox and it's up another one on on proxmox and it's cool cuz you could have a connector on cool cuz you could have a connector on cool cuz you could have a connector on like every single machine so if a couple like every single machine so if a couple like every single machine so if a couple machines go down there's probably going machines go down there's probably going machines go down there's probably going to be one that's still live that you can to be one that's still live that you can to be one that's still live that you can use to actually restart and do some work use to actually restart and do some work use to actually restart and do some work on some of your equipment while you're on some of your equipment while you're on some of your equipment while you're on the road or whatever and then on the road or whatever and then on the road or whatever and then resources over here you can see I have resources over here you can see I have resources over here you can see I have uh the proxy I'm going to edit that in a
-
uh the proxy I'm going to edit that in a uh the proxy I'm going to edit that in a minute these are the actual uh services minute these are the actual uh services minute these are the actual uh services or IP addresses that you have on your or IP addresses that you have on your or IP addresses that you have on your network so under overview I'm just going network so under overview I'm just going network so under overview I'm just going to deploy another connector and here to deploy another connector and here to deploy another connector and here these are all the options to go ahead these are all the options to go ahead these are all the options to go ahead and set this up you do have quite a few and set this up you do have quite a few and set this up you do have quite a few you could either use Docker or like a you could either use Docker or like a you could either use Docker or like a system CTL service under Linux for this system CTL service under Linux for this system CTL service under Linux for this one we're going to be using Docker and one we're going to be using Docker and one we're going to be using Docker and then all we need to do is go ahead and then all we need to do is go ahead and then all we need to do is go ahead and generate our tokens so let's click on generate our tokens so let's click on generate our tokens so let's click on that authenticate I have two Factor that authenticate I have two Factor that authenticate I have two Factor right now you can't set up more right now you can't set up more right now you can't set up more authentication methods and make it as authentication methods and make it as authentication methods and make it as secure as you want so these right here secure as you want so these right here secure as you want so these right here are my access tokens so we have access are my access tokens so we have access are my access tokens so we have access and refresh so I'm just going to copy and refresh so I'm just going to copy and refresh so I'm just going to copy and paste these into that uh Docker and paste these into that uh Docker and paste these into that uh Docker compost stack so you can see I went compost stack so you can see I went compost stack so you can see I went ahead and pasted them in right here and ahead and pasted them in right here and ahead and pasted them in right here and then in Twin gate we can see that this then in Twin gate we can see that this then in Twin gate we can see that this connector is current offline now and connector is current offline now and connector is current offline now and before we deploy I made one error we before we deploy I made one error we before we deploy I made one error we don't really need the tate.com right don't really need the tate.com right don't really need the tate.com right there so just the network name so let's there so just the network name so let's there so just the network name so let's go ahe and update this and there we go go ahe and update this and there we go go ahe and update this and there we go it's running you can see it's starting it's running you can see it's starting it's running you can see it's starting up if we go ahead and check our logs up if we go ahead and check our logs up if we go ahead and check our logs here see it's offline ran authentication here see it's offline ran authentication here see it's offline ran authentication and now it's online so we could see that and now it's online so we could see that and now it's online so we could see that to be true right here I'm going to to be true right here I'm going to to be true right here I'm going to rename this say proxmox firm changes and rename this say proxmox firm changes and rename this say proxmox firm changes and then this connector sorry I'm doing some then this connector sorry I'm doing some then this connector sorry I'm doing some clean up here real quick this is unraid clean up here real quick this is unraid clean up here real quick this is unraid so now I do need to make an edit let's so now I do need to make an edit let's so now I do need to make an edit let's go over to to network and we need to go go over to to network and we need to go go over to to network and we need to go to our resources this is my proxy right to our resources this is my proxy right to our resources this is my proxy right here so I'm going to give this a quick here so I'm going to give this a quick here so I'm going to give this a quick edit so if I edit this this is on the edit so if I edit this this is on the edit so if I edit this this is on the port 203 so you're going to want to put port 203 so you're going to want to put port 203 so you're going to want to put your IP address for the machine that's your IP address for the machine that's your IP address for the machine that's running engine X proxy manager and I'm running engine X proxy manager and I'm running engine X proxy manager and I'm aliasing it so if I didn't have this
-
aliasing it so if I didn't have this aliasing it so if I didn't have this already you just click on Alias and do already you just click on Alias and do already you just click on Alias and do this to the root of the domain name that this to the root of the domain name that this to the root of the domain name that you added is hopkey and here if you you added is hopkey and here if you you added is hopkey and here if you really wanted to you can set up certain really wanted to you can set up certain really wanted to you can set up certain ports right now I just have it allow all ports right now I just have it allow all ports right now I just have it allow all I'm the only one that has access to this I'm the only one that has access to this I'm the only one that has access to this but if you had a machine or IP with but if you had a machine or IP with but if you had a machine or IP with multiple services and you wanted certain multiple services and you wanted certain multiple services and you wanted certain groups of users to be able to only groups of users to be able to only groups of users to be able to only access specific Services you could set access specific Services you could set access specific Services you could set Port restrictions to specific groups Port restrictions to specific groups Port restrictions to specific groups it's beautiful so I'm going to hit it's beautiful so I'm going to hit it's beautiful so I'm going to hit update resource and there we go we could update resource and there we go we could update resource and there we go we could see it's online with uh twin gate see it's online with uh twin gate see it's online with uh twin gate connected here you can see the Alias of connected here you can see the Alias of connected here you can see the Alias of hopkey Donnet and I head on over to hopkey Donnet and I head on over to hopkey Donnet and I head on over to proxmox hop. net you can see I'm not proxmox hop. net you can see I'm not proxmox hop. net you can see I'm not currently connecting to any network it currently connecting to any network it currently connecting to any network it is working great we can see the little is working great we can see the little is working great we can see the little lock there it's encrypted let's just log lock there it's encrypted let's just log lock there it's encrypted let's just log in real fast log in real fast log in real fast log in and there we go we are now on the in and there we go we are now on the in and there we go we are now on the external web uh navigating my local IP external web uh navigating my local IP external web uh navigating my local IP address absolutely beautiful and just address absolutely beautiful and just address absolutely beautiful and just like that it is the next day I have had like that it is the next day I have had like that it is the next day I have had some time to go through and add some time to go through and add some time to go through and add basically all the services that I basically all the services that I basically all the services that I currently have spun up to this engine X currently have spun up to this engine X currently have spun up to this engine X proxy manager right here and I have proxy manager right here and I have proxy manager right here and I have quite a few of them you can see 19 quite a few of them you can see 19 quite a few of them you can see 19 different proxy hosts for example I have different proxy hosts for example I have different proxy hosts for example I have Docker hop. net which this links to the Docker hop. net which this links to the Docker hop. net which this links to the actual uh protainer or painer instance actual uh protainer or painer instance actual uh protainer or painer instance that the uh proxy is running on as that that the uh proxy is running on as that that the uh proxy is running on as that is our local but I went ahead and added is our local but I went ahead and added is our local but I went ahead and added the um instances of porer of all my the um instances of porer of all my the um instances of porer of all my other Docker machines or virtual other Docker machines or virtual other Docker machines or virtual machines here so then I can manage a machines here so then I can manage a machines here so then I can manage a wide variety of containers you can see
-
wide variety of containers you can see wide variety of containers you can see 18 here 7 5 11 five I have a lot of 18 here 7 5 11 five I have a lot of 18 here 7 5 11 five I have a lot of different things running I also got home different things running I also got home different things running I also got home assistant here working and again a lot assistant here working and again a lot assistant here working and again a lot of these do require some special little of these do require some special little of these do require some special little configurations to get it to work so for configurations to get it to work so for configurations to get it to work so for example if I do head over to home example if I do head over to home example if I do head over to home assistant within the file editor I assistant within the file editor I assistant within the file editor I needed to go over to the configuration needed to go over to the configuration needed to go over to the configuration yaml file and add HTTP use x Ford for yaml file and add HTTP use x Ford for yaml file and add HTTP use x Ford for True trusted proxies and then the actual True trusted proxies and then the actual True trusted proxies and then the actual IP of that proxy you see we have fret IP of that proxy you see we have fret IP of that proxy you see we have fret that's the home assistant we have image that's the home assistant we have image that's the home assistant we have image we have the jelly one we just created we have the jelly one we just created we have the jelly one we just created lar NC nzb get udoo which I'm kind of lar NC nzb get udoo which I'm kind of lar NC nzb get udoo which I'm kind of testing and playing around with here you testing and playing around with here you testing and playing around with here you could see it's working fine a lot of could see it's working fine a lot of could see it's working fine a lot of these didn't require any special these didn't require any special these didn't require any special configurations one thing I will note is configurations one thing I will note is configurations one thing I will note is with these uh sonar radar and all those with these uh sonar radar and all those with these uh sonar radar and all those I really wanted to set it up in a scheme I really wanted to set it up in a scheme I really wanted to set it up in a scheme where it was r. hop. net radar and put where it was r. hop. net radar and put where it was r. hop. net radar and put all of those under the same subdomain all of those under the same subdomain all of those under the same subdomain but it just wasn't working for me that but it just wasn't working for me that but it just wasn't working for me that would have been really nice to use the would have been really nice to use the would have been really nice to use the custom location for all of those so I custom location for all of those so I custom location for all of those so I didn't have 19 proxy hosts so if you do didn't have 19 proxy hosts so if you do didn't have 19 proxy hosts so if you do know how to get that working I would know how to get that working I would know how to get that working I would absolutely love to know I think torrent absolutely love to know I think torrent absolutely love to know I think torrent hopkey was another one I needed to add hopkey was another one I needed to add hopkey was another one I needed to add some custom variables here just Googling some custom variables here just Googling some custom variables here just Googling found these proxy read timeout 120 found these proxy read timeout 120 found these proxy read timeout 120 redirect off Max size 100 and redirect off Max size 100 and redirect off Max size 100 and beautifully all these hopkey Donnet beautifully all these hopkey Donnet beautifully all these hopkey Donnet domains are accessible if I travel over domains are accessible if I travel over domains are accessible if I travel over uh to it via twin gate if I'm on some uh to it via twin gate if I'm on some uh to it via twin gate if I'm on some remote connection so that is great for remote connection so that is great for remote connection so that is great for the public domains I am going to work on
-
the public domains I am going to work on the public domains I am going to work on trying to find a way to hide my IP I trying to find a way to hide my IP I trying to find a way to hide my IP I know there are various different methods know there are various different methods know there are various different methods to go ahead and do that because for the to go ahead and do that because for the to go ahead and do that because for the file and media streaming um Cloud flare file and media streaming um Cloud flare file and media streaming um Cloud flare is not a fan of that so if you know of a is not a fan of that so if you know of a is not a fan of that so if you know of a good way please also let me know down good way please also let me know down good way please also let me know down below or any other tips and tricks or below or any other tips and tricks or below or any other tips and tricks or anything I could have missed so with all anything I could have missed so with all anything I could have missed so with all that I do hope you have an absolutely that I do hope you have an absolutely that I do hope you have an absolutely beautiful day and goodbye
Summary
This tech analysis details how to securely access home lab services from the internet using Docker, Nginx Proxy Manager, and Cloudflare, with a focus on setting up both public and private top-level domains with SSL certificates. The practical takeaway is to implement a zero-trust networking solution like TwinGate for remote access without traditional VPNs, offering a free tier for initial users.