I’ve started a homelab a few months ago, and since then it looked more or less like this:

  • DNS server - with one wildcard record “*.srv.lan” pointing to my reverse proxy (I don’t have a proper domain yet)
  • Proxy (traefik) - forwards the requests to specific services (nas.srv.lan -> NAS, photos.srv.lan -> Immich etc.)

An issue showed up when I got around to setting up samba, where because I have a single wildcard DNS record, and the proxy runs on http(s), I cant forward SMB requests to the server, other than using its ip. The same issue arose when I wanted to get dns-based ssh working (even though I have nas.srv.lan set up, ssh-ing that gets me onto the proxy instead of the nas, which makes sense with the dns setup)

One solution that came to my mind would be making each service (I’m using vms, so each service is a different host) have a separate reverse proxy, as well as making the DNS server have all the records separately (nas.srv.lan -> NAS ip, photos.srv.lan -> Immich ip etc.) and then perform the proxying on the hosts. That would lead to me having a dozen different reverse proxies, wasting resources and making managment more difficult.

Are there any other things I could try?

  • jet@hackertalks.com
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    2 hours ago

    A central proxy adds a central point of failure.

    However, if you give each service its own DNS entry, your proxy can look at the incoming DNS of the request, and use that to proxy to the service. At least for http services

    I think it’d be much cleaner, to give each VM its own DNS entry, run the service on Port 80, or 443 so you don’t have to remember port numbers.

    I’m not sure the reverse proxy is buying you much ease of use for a totally internal system. If you like, you can have a central web page, that links to all your different services from one location.