I’ve started a homelab a few months ago, and since then it looked more or less like this:
- DNS server - with one wildcard record “*.srv.lan” pointing to my reverse proxy (I don’t have a proper domain yet)
- Proxy (traefik) - forwards the requests to specific services (nas.srv.lan -> NAS, photos.srv.lan -> Immich etc.)
An issue showed up when I got around to setting up samba, where because I have a single wildcard DNS record, and the proxy runs on http(s), I cant forward SMB requests to the server, other than using its ip. The same issue arose when I wanted to get dns-based ssh working (even though I have nas.srv.lan set up, ssh-ing that gets me onto the proxy instead of the nas, which makes sense with the dns setup)
One solution that came to my mind would be making each service (I’m using vms, so each service is a different host) have a separate reverse proxy, as well as making the DNS server have all the records separately (nas.srv.lan -> NAS ip, photos.srv.lan -> Immich ip etc.) and then perform the proxying on the hosts. That would lead to me having a dozen different reverse proxies, wasting resources and making managment more difficult.
Are there any other things I could try?

For me, it’s all boils down to not having to type the port number in the url + centralized ssl certs. Instead of having the users type, say, https://nas.srv.lan:1234/ into their browser I can just make the proxy forward https://nas.srv.lan/ to http://some-nas-ip:1234/. It saves me from having to configure ssl/https and port configs for each service on each host, and as long as I pretend my homelab network is secure (it’s not), using http internaly (between the proxy and service hosts), while keeping stuff encrypted externally (between the users and the proxy), is relatively ok and much easier to configure. I know that there’s more to it, load balancing etc but for me that’s it.
Hope I was of some help