Quick and Easy Local SSL Certificates for Your Homelab!

  Рет қаралды 930,273

Wolfgang's Channel

Wolfgang's Channel

Күн бұрын

Пікірлер: 1 000
@WolfgangsChannel
@WolfgangsChannel Жыл бұрын
Text version of the video with all the commands: notthebe.ee/blog/easy-ssl-in-homelab-dns01/ To try everything Brilliant has to offer-free-for a full 30 days, visit brilliant.org/Wolfgang/ The first 200 of you will get 20% off Brilliant’s annual premium subscription
@SirWinnieThePooh
@SirWinnieThePooh Жыл бұрын
Not related but I love your content man, keep it up
@ripaire
@ripaire Жыл бұрын
hi can you please make a video about pterodactyl and it should be running the pannel and the wings in same docker-compose file if you do that i will be very gratefull and thanks for this amazing video
@oussamakarem5744
@oussamakarem5744 Жыл бұрын
Thanks for the share, but how about the npm network driver ? i can see no details about it thanks in advance (btw the npm never work for me)
@streambarhoum4464
@streambarhoum4464 Жыл бұрын
Hey Wolfgang!! 😊 what about accessing our home lab securely from the outside world without using third party CDN like cloudflare? Please provide us with a solution in a next video?😊🙏🎉
@ferasawwad71
@ferasawwad71 Жыл бұрын
Greetings to you. Do you have an explanation on how to replace the ip address of the carrier that is shown to the world to: domain HTTPS global. With its connection to a number: a computer.
@americanbagel
@americanbagel Жыл бұрын
This video could not have come at a better time! I've just started putting together my own home server and I've been driving myself insane with self-signed certificates. Thanks!
@giacomogagliano1526
@giacomogagliano1526 Жыл бұрын
same here =)
@MrMoogle
@MrMoogle 9 ай бұрын
My man! You are my hero. I've watched so many videos trying to figure out how to do this exact thing and you explained it all so perfectly. And the written guide to accompany it was an added bonus and very much appreciated. Thank you, sir!
@WolfgangsChannel
@WolfgangsChannel 9 ай бұрын
No problem 👍
@moritz22
@moritz22 Жыл бұрын
Very nice video, this setup is more convenient than my own dns server. For anyone using a fritzbox router: You have to add your full domain as an exception to the "DNS rebind protection", because the fritzbox does not allow DNS resolution of domain names that point to private ips to protect against DNS rebinding attacks
@saninnsalas
@saninnsalas Жыл бұрын
This is an excellent tip! Thanks!
@ivangogov7312
@ivangogov7312 Жыл бұрын
Thank you! Now it is working as expected.
@Izuna-
@Izuna- Жыл бұрын
I was looking for this comment. Thanks alot! :)
@RamiKattan
@RamiKattan Жыл бұрын
Fixed my issue after pulling my hair for an hour
@LKD70
@LKD70 Жыл бұрын
Hero, thank you for this comment.
@RaidOwl
@RaidOwl Жыл бұрын
NPM is freakin awesome. It's crazy how easy it is to get setup and going with it and boom...you've got proper SSL and routing.
@falxie_
@falxie_ Жыл бұрын
As (unfortunately) a JavaScript developer I was very confused by this statement for a moment
@pieteryts
@pieteryts Жыл бұрын
not quite for me... since I'm not a linux users 😂 mostly I used DNS domain record check for let's encrypt.
@RaidOwl
@RaidOwl Жыл бұрын
@@falxie_ haha yeah I have to think twice when seeing "NPM" now
@pavelperina7629
@pavelperina7629 Жыл бұрын
@@falxie_ nginx proxy manager. Yes, I barely touched JS and I had to ask chatgpt (which is suprisingly good for setting up simple stuff and writing simple shell script
@asandax6
@asandax6 Жыл бұрын
NPM is very confusing when you're not referring to Node Package Manager.
@thomasmiller4625
@thomasmiller4625 Жыл бұрын
"Don't worry about it! Not every bad thing in life is your fault." Thanks man I needed that.
@adrianmurillo2646
@adrianmurillo2646 Жыл бұрын
Thank you, sir! This is a great video. For anyone using pfsense on their home network -- with a different domain than your purchased domain for your home lab -- you are going to want to add DNS host overrides for your purchased domain and the hosts that you are going to be proxying, all pointing to the IP address of the nginx proxy manager.
@LeonRohr-xc4re
@LeonRohr-xc4re Жыл бұрын
could you please explain further? Im having trouble on setting this up using my pfsense
@EricKoehler-dc5or
@EricKoehler-dc5or Жыл бұрын
could you please show this step, maybe in a short video? pFsense drives me crazy :(
@ClassicCarOverhaul
@ClassicCarOverhaul Жыл бұрын
Thanks, was pulling my hair out until I did dns host ovreride and it worked!
@clabretro
@clabretro Жыл бұрын
This is the simplest way to tackle certs I've seen, definitely trying this! I've been putting it off in my homelab for ages.
@ryanmalone2681
@ryanmalone2681 9 ай бұрын
Doesn't work with Cloudflare.
@Luniii737
@Luniii737 Жыл бұрын
Wow, thank you for this video! I didn't know (or think of) that you could point a domain name to a private IP address. That makes creating SSL certificates super easy like this! Love you
@dj_odradeck
@dj_odradeck Жыл бұрын
I use exactly this setup for over a year and it just works flawlessly. Even auro-renewing the let's encrypt cert works without any issues.
@ryanmalone2681
@ryanmalone2681 9 ай бұрын
No it doesn't.
@chaejunhee
@chaejunhee Жыл бұрын
I was almost giving up, but I saw the video and the kind explanation was sweet rain for a beginner like me. Thank you so much
@mustafaozpay9031
@mustafaozpay9031 Ай бұрын
You are the man, I love when propagating the quote you said "Not every bad thing in life is your fault". video helped me a lot but there are still crazy questions in my mind.
@Andoresu96
@Andoresu96 Жыл бұрын
wait y'all are using an application to manage your nginx reverse proxy? I was editing config files like a madman here 😭
@sugoruyo
@sugoruyo Жыл бұрын
This is the way.
@rabahfdoul4844
@rabahfdoul4844 Жыл бұрын
@@sugoruyothis is the way.
@th3fallen
@th3fallen Жыл бұрын
Nginxproxmanager is really nice if you just want a gui and ssl rotation
@codewithlarsy
@codewithlarsy Жыл бұрын
😮
@AzarelHoward
@AzarelHoward Жыл бұрын
Me too... This is the way.
@revilo2208
@revilo2208 Жыл бұрын
Tausend Dank Wolfgang. This is exactly what I was looking for. I was this close to setting up my own CA and getting a headache trying to add the root certs to all the devices.
@brunosolothurnmann9205
@brunosolothurnmann9205 Жыл бұрын
Thank you - as I use Pi-hole, I had to add entries to the pi-hole local dns with the (sub-)domain names pointing to the proxy-manager. After that it run as you explained it.
@gibberingidiot
@gibberingidiot Жыл бұрын
Thank you - just saved me a lot of head scratching...
@richardrussell5165
@richardrussell5165 11 ай бұрын
you saved me soo much stress
@handaloo
@handaloo 4 ай бұрын
OMG you legend. I've followed this video twice and hit a brickwall everytime, until I found your comment. Thankyou!
@JeronimoStilton14
@JeronimoStilton14 3 ай бұрын
Was this to get the SSL cert approved or for the handling of the proxy hosts after? I ask because I am using Pi-hole and cannot get past the activation of the duckdns cert.
@g4ngr3l87
@g4ngr3l87 3 ай бұрын
@@JeronimoStilton14 same here. used LOCAL IP on the domain and increased the propagation time to 60. that fixed thee SSL part for me. could not access the hosts yet thought.
@ary2000
@ary2000 20 күн бұрын
Awesome tutorial, thanks. Just a quick note: if you want to proxy an app that is either a docker container or a non docker app, put in the IP address of the host machine, NOT 127.0.0.1. My npm container was attached to a network device in bridged mode, instead of host. So it didn't see any other containers. I was stuck on that for a while but maybe it helps someone else.
@mr.mentat.0x
@mr.mentat.0x Жыл бұрын
Dude... this intro speaks directly to my soul. Completely spot-on how it feels. The Blade Runner segment is perfect. Going to do this on my home lab, that's turned into something I'd see in the field, at work. Too funny man 😂😂 *joined* 😂😂❤
@Nahga
@Nahga 10 ай бұрын
This was just fantastic. I didn’t know I needed something like this in my life until I saw the video. Very well done thanks a lot.
@jdfmovil
@jdfmovil Жыл бұрын
Add portainer to this and you have an easy way to manage all your containers. :)
@electricz3045
@electricz3045 Жыл бұрын
Easy it might be defently not efficient. Running shell commands is just faster then navigating around in an GUI to do the same thing.
@fabiandrinksmilk6205
@fabiandrinksmilk6205 Жыл бұрын
​@@electricz3045 This is where we come to the whole CLI vs GUI discussion again. The right answer is of course your personal preference!
@varunaeeriyaulla
@varunaeeriyaulla Жыл бұрын
@@fabiandrinksmilk6205 I agree with you. I have multiple docker servers, including HA. It's much easier to manage with Portainer and portainer agents.
@4crafters597
@4crafters597 Жыл бұрын
Yacht for a smaller yet lighter system that still works for basic setups!
@JohnDoe1999-lg7mh
@JohnDoe1999-lg7mh 2 ай бұрын
Thanks so much. Just what I needed. I don't expose anything to the internet and nice to know that I can do all this local.
@newaira333
@newaira333 Жыл бұрын
Makes sense, though the traffic between the proxy and the service that is being accessed is still unencrypted correct? This gives the appearance like local traffic is encrypted, but really local traffic passes unencrypted to the reverse proxy before it is encrypted. I think it would have made sense to take an extra step and create a self-signed certificate that would be installed on the service and validated by the reverse proxy to ensure end-to-end encryption. Unless I'm missing something?
@WolfgangsChannel
@WolfgangsChannel Жыл бұрын
This is not for security, it's for convenience
@rapha5586
@rapha5586 2 ай бұрын
Do you have some starting point you can redirect me to set this up? I don't care for the convenience since I can just bookmark local ips but I care for a fully encrypted connection.
@jan5310
@jan5310 Ай бұрын
Just wanted to thank you, this was precise what I was looking for. Thanks for the clear explanation. You got yourself a new subscriber.
@brokenicelight
@brokenicelight Жыл бұрын
Your Video is like a rescue ring. I had trouble understanding this concept with the traefik guides from Techno Tim but now that you've implementet a sceamtic drawing it helped alot. Thanks! Again a Video to exact right time :D My instructor wanted me to get the basic of dns and teach myself but i was only stuck at this internal external stuff so you safed me :D
@AinzOoalG0wn
@AinzOoalG0wn Жыл бұрын
did you get this to work for traefik? i need help for that x-x;
@brokenicelight
@brokenicelight Жыл бұрын
@@AinzOoalG0wn Sadly not now since i haven't had much time yet. But i want to get it working with traefik. Maybe we could stay connected?
@AinzOoalG0wn
@AinzOoalG0wn Жыл бұрын
@@brokenicelight i came up with a solution. i shutdown traefik and started up nginx proxy manager instead 🤣 i got it to work kinda. even authentik works with it. just, it only works when my vpn is active. when its turned off, it no longer works 🥲
@AinzOoalG0wn
@AinzOoalG0wn Жыл бұрын
@@brokenicelight well if u find out a solution plz do share. i had to go back to traefik cause there were some issues in npm i could not resolve 🥲
@malteneuss8058
@malteneuss8058 8 ай бұрын
This is such a great feature for self-hosting. Thanks for sharing. It's worth noting that some routers like Fritzboxes have a "DNS rebind protection" where you must add an exception. Otherwise you will bang your head against the wall why it doesn't work, like i did.
@ChazBword
@ChazBword Жыл бұрын
Yet another great video Wolfgang. Outstanding work. I've been wanting to do this for a while for my homelab and this video is the push I needed. Thank you.
@MartinKL
@MartinKL Жыл бұрын
Lots of information in this video, thank you. The text-blog was very helpful to see the commands without copying them from the video.
@rodrimora
@rodrimora Жыл бұрын
I’ve found that some services require some special headers and if not configured correctly they break, that’s the hardest part for me, as finding the nginx headers needed for each services can be difficult
@WolfgangsChannel
@WolfgangsChannel Жыл бұрын
Take a look at SWAG's reverse proxy conf repository - they have examples for pretty much every popular web application: github.com/linuxserver/reverse-proxy-confs
@MrEric377
@MrEric377 11 ай бұрын
Thank you so much for this video, 1 thing I don't think anyone ran into is I had to wait almost a day for my registrar to reflect the IP changes. 🤦Now that I found you I'm going to look through your other video's Thanks again.
@pousoupoux
@pousoupoux Жыл бұрын
you skipped the cloudflare api token, but with some extensive google search i found that you need to create your own API token with edit dns zones permissions set to all zones
@noor_codes
@noor_codes 5 ай бұрын
Wow, Thank you soooooooo much, You have no idea how much headache I went through just to land here and it worked.
@adryanobrum
@adryanobrum Жыл бұрын
Another great video. Clean and simple. Please, you need to teach us how to configure a home assistant dashboard like yours! 🤟
@DrathVader
@DrathVader 10 ай бұрын
I finally got to set this up after watching the video months ago. I should have set up proxies long ago, much more convenient. One thing to mention is that this method works well with tailscale as well. I just put my server's tailscale IP instead of local network IP and it works perfectly. Really useful for privately sharing linux isos with friends.
@seanys
@seanys Жыл бұрын
Good to see a well done tutorial on the exact thing I’ve been trying to achieve for ages!
@vamshikrishnaanandesi1642
@vamshikrishnaanandesi1642 Жыл бұрын
Thank you for this video, have always been wanting to access all my services through https rather than typing in my IP every time but couldn't as I thought it will take some time for me to study the nuances of the process. This has been an easy and fast setup.
@HeyDrianTV
@HeyDrianTV 11 ай бұрын
I can't get this to work with my Cloudflare domain. Any pointers?
@andersonlemes9927
@andersonlemes9927 3 ай бұрын
Posso emitir o certificado, mas o domínio não é público.
@elikelik3574
@elikelik3574 Ай бұрын
Did you figure it out? I'm note sure what I'm doing wrong but still getting untrusted website. I tried on Docker Windows 10/11, Linux , even on Synology Nas docker. But still getting same error. I have my own domain name and useing cloudflare for DNS.
@Piolaso
@Piolaso Ай бұрын
What issue are you having? In case your root domain if being use it for something else (like my case) I created an A record with .local that points to my reverse proxy (NPM in my case too) Then created a CNAME like this *.local. that points to the A from before local.
@elikelik3574
@elikelik3574 Ай бұрын
@@Piolaso I tried it but unfortunately it did not help as well.
@SuperWolfkin
@SuperWolfkin Жыл бұрын
holy snap.. 20 seconds from 1:00 and my mind is blown. Of course that would work. It's so easy and it solves EVERYTHING.
@BallerBubi
@BallerBubi Жыл бұрын
This solution is simply brilliant. I was searching for years for such an amazing and simple solution. Thank you.
@ankkitraj2625
@ankkitraj2625 9 ай бұрын
I have been following this channel for years and did not realized I am not subscribed.
@marceldavis3628
@marceldavis3628 Жыл бұрын
Even if i turn off the certificate and i set the ip to the ip of an other of my homeservers, the forwarding does not work . I get a connection refused error. What is the best way to debug that?
@kecske_gaming
@kecske_gaming 3 ай бұрын
same
@JmonteroArg
@JmonteroArg Жыл бұрын
This video was right on time! I was exploring how could I deploy things locally without deal with IPs and cert issues. Very valuable info, thanks for sharing.
@Knufle
@Knufle Жыл бұрын
Btw, great video! Thanks for explaining everything in such a concise and easy to understand manner. Just a heads up, apparently this method doesn't fully work on Chrome if you have Safe Browsing Standard or Enhanced protection enabled, for me I get the "Deceptive site ahead" warning for some of my local apps, like Jellyfin for example, but I don't get the warning for other apps like Code Server, so idk, just wanted to let you know. On Firefox I don't get warnings no matter what though, so that works just fine.
@dannysung3397
@dannysung3397 Жыл бұрын
Pretty awesome and relatively easy to setup! One issue I noticed is that Safari password autofill treats everything under the proxy as the same site... meaning it will suggest passwords for services with different hostnames. This can get a bit unwieldy if you have a lot of services with their own username/passwords.
@NicolaSelenu
@NicolaSelenu Жыл бұрын
this is EXACTLY what I was looking for. You are a lifesaver! (I know I know.. first world problems)
@s1mbolik
@s1mbolik 6 ай бұрын
I'm so excited that I hit the like and subscribed at 1:37. Now continuing with the video! SSL freedom.
@solidus1983
@solidus1983 Жыл бұрын
Thank You, I had been using an SSL per domain, didn't know you could create just one SSL cert. Now i do an have it set up thanks.
@senthilrajanr1
@senthilrajanr1 11 ай бұрын
I can not thank enough for this video. I was struggling to figure this out and your video helped me. Thank you
@EdwardGrabiel
@EdwardGrabiel 3 ай бұрын
hi, it seems is not working anymore, the certificate is added to the domain (using duckdns) but when you try to add it to your proxy host is in red state and it doesn't work. Does it work for anyone at this moment? (october 20. 2024). Also another domain I have with godaddy doesn't work because they have limited their API usage
@elikelik3574
@elikelik3574 Ай бұрын
Unfortunately does not work for aswell. I use goddady domain name and cloudflare for dns. I tireid this a few monthes ago and can confirm does not work.
@chnoack
@chnoack 17 күн бұрын
To make the DNS resolution of the new domain name work in my LAN I had to add an exception for that domain to the "DNS rebind protection" configuration of my Fritzbox.
@trbk_watch666
@trbk_watch666 Жыл бұрын
One minor correction about setting proxy hosts. Setting the forward hostname as localhost for any containers other than the Nginx Proxy Manager container leads to a 502 Bad Gateway error, even if all containers are running on the same network. I resolved it by using the IP address instead of localhost.
@Cookie-ey1vr
@Cookie-ey1vr 8 ай бұрын
where would you find the IP address in the docker container?
@mattmallow
@mattmallow 4 ай бұрын
@@Cookie-ey1vr For me I used the IP address of my server. Both localhost and 127.0.0.1 spits 502. Then when I changed it to the IP of server it worked.
@Noir1234
@Noir1234 10 ай бұрын
Hey, very nice video, but i got an issue, i already use the nginx proxy manager in combination with a domain and cloudflare to expose some stuff to the outside world. is it also possible to use the same nginx pm and domain for the local ssl stuff?
@gabrielrechy
@gabrielrechy Жыл бұрын
Gracias por este valioso contenido, hace tiempo que no encontraba como asignarle certificados válidos a un servicio que estuviera fuera Docker, pero ahora ya me di la idea de como poder solucionarlo gracias a tu vídeo ✌️
@EconaelGaming
@EconaelGaming Жыл бұрын
Danke Wolfgang! I find it absurd that we need to jump through these hoops, just to have valid SSL in our home networks, but you made those hoops much easier to jump through :)
@nullnill
@nullnill 10 ай бұрын
pro tip: mine even with 120 didnt work, but 240 did!
@user-co9be5eu7e
@user-co9be5eu7e Жыл бұрын
Thank you for this video. I have set it up at home, no longer public visibility for some services. Combined with Tailscale router (to access your local networks), it rocks !
@Knufle
@Knufle Жыл бұрын
Hey, your comment is exactly what I was looking for, I'm trying to also setup Tailscale alongside Nginx like in the video, but Tailscale also uses port 80, how did you manage it?
@Knufle
@Knufle Жыл бұрын
Nvm, I got it working, for some reason when I had CasaOS installed as a container before installing NPM, I'd get trouble installing NPM's container, however if I install NPM, configure it and only afterwards install Tailscale then it works just fine.
@Knufle
@Knufle Жыл бұрын
Although, on a separate note, how do you access your local environment using Tailscale when you're outside of your local network? Since duckdns points to a local IP, it doesn't really work for me outside of my local network, could you explain what you did?
@user-co9be5eu7e
@user-co9be5eu7e Жыл бұрын
@@Knufle I use Tailscale router to expose the network where the DNS entry resolves.
@user-co9be5eu7e
@user-co9be5eu7e Жыл бұрын
@@jims888 You have to use tailscale subnets to reach your ip addresses.
@Lucavon
@Lucavon Жыл бұрын
Nice video! I've been doing something similar: wildcard certificates and wildcard dns pointing at my home's public IP. Then I have an nginx reverse proxy + SSL terminator and configs for my services. If I want a service to be publicly reachable, all I do is add an nginx config and boom, done. If I want something to be available only locally, I simply add an override into my pihole dns server or just add an ip-based allow/deny block to the nginx config. Simple, and the wildcards add a bit of security by obscurity - no more bots finding services by reading the DNS or certificate data. I'm getting my certs using dns-01 with the lego acme client.
@mayurbn230
@mayurbn230 Жыл бұрын
But this setup he did in the video is only for local right? You will need a tunnel for public access!! That is if u have a static public ip!
@mayurbn230
@mayurbn230 Жыл бұрын
Is your IP public or CGNATted?
@mayurbn230
@mayurbn230 Жыл бұрын
This wont work for remote access if im cgnatted right?
@Lucavon
@Lucavon Жыл бұрын
@@mayurbn230 I don't have any tunnel or anything. I just forward the port in my router to my server. My IPv4 is a public, static IP shared with noone
@mayurbn230
@mayurbn230 Жыл бұрын
@@Lucavon Oh makes sense then, mine is cgnatted, so i have to use a tunnel
@aravind3626
@aravind3626 Жыл бұрын
I've been waiting for this for years...Thank you!!!!!!!!
@AarshMajmudar
@AarshMajmudar 7 ай бұрын
Does this have auto renewals of certs ?
@nixxblikka
@nixxblikka 4 ай бұрын
Not by default
@sumukhas5418
@sumukhas5418 11 ай бұрын
Please make a video on how to setup pihole as DNS server on docker...
@mavchb
@mavchb Жыл бұрын
Hi, thank you for that vdieo I built an Unraid server two years ago and I have been trying to fix that certificate issue since then. Unfortunately it does not work like described. After setting it up like you did with duckdns and nginx I can open the NGinx WEBUI like you butr any other proxy host gives me a 502 bad gateway error (tried vaultwarden and jellyfin) any idea what I could do wrong?
@chrgeorgeson
@chrgeorgeson 9 ай бұрын
Simialr issues on my end. Did you ever get this working?
@mavchb
@mavchb 9 ай бұрын
@@chrgeorgeson I did. I had a knot in my brain. I alwys wnated to point nginx to the https address of the service (e.g.: vaultwarden) but the whole point is that nginx is the https endpoint so you need to tell nginx to open the http (no S) URL. Then it works.
@TheQwenton
@TheQwenton 5 ай бұрын
@@chrgeorgeson HA same thing for me , just commeneted. Guessing it has to do with the way unraid builds its docker network and uses the same IP... Not sure..
@TheQwenton
@TheQwenton 5 ай бұрын
figure anything out?
@mavchb
@mavchb 5 ай бұрын
@@TheQwenton yes, I made the mistake to add the URL with httpS to nginx. That of course will not work as the connection between nginx and the actual website is regular http.
@MrXana91
@MrXana91 Жыл бұрын
Omg this is EXACTLY what i've been looking for for months! Thank you so much! That's a sub
@cerealthree
@cerealthree Жыл бұрын
en-jinx one minute, engine-x the next! this is calculated trolling to stir up as much grumbling on both sides as possible
@gorillaau
@gorillaau Жыл бұрын
Trolling both sides, maybe. Or a case of ruffling both sides, rather than antagonizing one side only. You can win regardless, especially with the spread of audience by Wolfgang.
@bjarnuhuh
@bjarnuhuh 9 ай бұрын
You are an absolute legend for this video! I've been trying to fix my reverse proxy and could not get it to work. The "Propagation Seconds" change was an absolute saver! Thanks!
@ryanmalone2681
@ryanmalone2681 9 ай бұрын
Doesn't work for Cloudflare. There is no way of mapping an IP address for a challenge and when you add your name servers after the domain it fails. I don't want to use Duck DNS though. Maybe a video on how to do this using Cloudflare would be cool.
@Skyluxe
@Skyluxe 4 ай бұрын
For me actually it does work with cloudflare. You have to deactivate the proxy (only DNS via cloudflare).
@MoviesFlaFla
@MoviesFlaFla 2 ай бұрын
@@Skyluxe Hello, did you do something else ? On my end, I was able to map on cloudflare to my internal IP, and to create a ssl cert with the API. But when I try to redirect to the correct service in NGINX it doesn't work. I know that my port interal_IP:80 was already mapped (outside of NGINX), and my guess is that my network is not taking the info given by NGINX to go to the correct service. Thanks ;)
@somedude5353
@somedude5353 Жыл бұрын
This doesn't work for me. I didn't use duckdns, instead my own domain. I have the SSL certificate setup, I've likewise added in the * subdomain, and it doesn't route.
@thebigt42
@thebigt42 2 ай бұрын
The is NOT a video about Easy Local SSL Certs.
@xellaz
@xellaz Жыл бұрын
This worked great on putting https secure connection locally on my new Raspberry Pi 5 running CasaOS! I just had to do a few modification on the ports and IP addresses but everything worked correctly at the end! Thanks! 👍
@PunkrockNoir-ss2pq
@PunkrockNoir-ss2pq 2 ай бұрын
what a waste of time
@BooleanDev
@BooleanDev 6 ай бұрын
man i spent so long looking for a video like this, and it shows up right after i got it working. wouldve been nice to get this recommendation first lol
@yerunski
@yerunski Жыл бұрын
I'm only 1 min. 20 secs in the video and already hit the like button. I'm sure this will be better then my self signed certificates :)
@ayoubthegreat
@ayoubthegreat Жыл бұрын
Thank you for this! It seemed complicated but after following along I got everything working perfectly.
@nightyeve
@nightyeve Жыл бұрын
Thankss ! Love how clear and fast you explain everything
@FireStriker_
@FireStriker_ Жыл бұрын
are you telling me i have been messing with the config file all this time while this existed? well im glad i found this now lol
@aliaghil1
@aliaghil1 Жыл бұрын
Great video as always. Thank you for sharing it with us. I am using pfSense in my environment and having HAProxy, however I needed a second proxy manager, your video helped me a lot with setting up the second one. 👍
@rayzerx
@rayzerx Жыл бұрын
I didn't know I needed this video until it was recommended to me. Amazing video and great explanations. Thanks for the caption. Greetings from Brazil. ✌🏽
@wukerplank
@wukerplank Жыл бұрын
Learned something new, I wasn't aware that Letsencrypt can do wildcard certificates by now 🙌
@cookingmake
@cookingmake 11 күн бұрын
Very concise tutorial, thanks for sharing. But I deployed npm instead of docker-compose on truenas scale and I'm experiencing `ERR_CONNECTION_REFUSED` issue, I tried many tutorials on the web but nothing worked, is it my home ISP or router that is blocking access? I also tried configuring a firewall on my router to pass the target port 80, 443
@JustHelixia
@JustHelixia 4 ай бұрын
Awesome! This was the exact video I needed to find. My local homelab is now secure and I can now use very long domainnames! Haha!
@MegaChiliMac
@MegaChiliMac Жыл бұрын
excellent. exactly what i was looking for. and thank you for having this info in blog post format too.
@jjolleta
@jjolleta Ай бұрын
Although I made it work, the only service I can access with the name:port is just the nginx proxy, all the others I have to use the server address, first I thought it was the ports beyond some point or numbers, but I see yours works fine. How did you do it ? Pihole or just the container name ? I saw the video but I didn´t get it right.....
@TheDmankl
@TheDmankl Жыл бұрын
Seriously thank you so much for this.... I have been trying to find something like this but no one had a solution for this !!!
@scotthewitt6047
@scotthewitt6047 Жыл бұрын
I set up passbolt last night and have the problem you just solved in this video thank you
@BoraHorzaGobuchul
@BoraHorzaGobuchul 11 ай бұрын
I hope there's a part 2 to this video describing how to set it up so it works from the outside. I suppose using tailscale would allow it, and it has been noted in the comments, but a walkthrough would be appreciated. Looks like I'm not alone with this question here.
@WolfgangsChannel
@WolfgangsChannel 11 ай бұрын
There are plenty of tutorials already showing how to make locally hosted services accessible from the outside. The point of this video is to set up a local-only access which still uses valid SSL certs
@BoraHorzaGobuchul
@BoraHorzaGobuchul 11 ай бұрын
@@WolfgangsChannel I understand that. However, many people generally prefer to access stuff both from the inside and from the outside - as proven by the comments to this video as well. I'm not asking how to setup tailscale. The question is how this topic meshes with it. What has to be done to make it work seamlessly. It's it enough to e.g. set tailscale as subnet router, or are any other steps necessary?
@AlexeiTetenov
@AlexeiTetenov 9 ай бұрын
@@BoraHorzaGobuchul? Setup your own dns server?
@z1g
@z1g 11 ай бұрын
This is an amazing video, thank you very much. SSL cert errors set me off. I followed this and it worked flawlessly. I think modified to use my Tailscale VPN IP addresses and now I can access my home lab services anywhere with a nice certificate, makes me happy. Time to touch grass, thanks again.
@yeastdonkey846
@yeastdonkey846 Жыл бұрын
Great video. Got me up and running when I first set up npm. I changed to custom certs from Cloudflare, which last for 15 years though.
@tooongs
@tooongs Жыл бұрын
Hey man, I'm curious. How is yours setup?
@yeastdonkey846
@yeastdonkey846 Жыл бұрын
@@tooongs in terms of the CloudFlare cert? I just setup all my dns records through cloudflare and set them to proxied. Then I generated a cloudflare origin cert and imported them into npm. I also set my encryption on cloudflare to strict mode.
@hfrox1
@hfrox1 Жыл бұрын
Man this video is exactly what I was looking for. Thank you
@sbx1
@sbx1 Жыл бұрын
Danke Wolfgang, dank deiner Anleitung war die Einrichtung sehr einfach! :)
@jayceroman6047
@jayceroman6047 Жыл бұрын
You uploaded this video at a weirdly perfect time for me.
@ChrisIsEditing
@ChrisIsEditing 13 күн бұрын
"not every bad thing in life i your fault". Thank you, I actually feel better now
@Technobasje
@Technobasje 3 күн бұрын
Ok this was easy to follow until I needed to add the trusted proxies in my home assistant configuration.yaml. Which IP's should I add there? My home assistant 192 IP? Or another one, and if so were do I find the IP to put in the config?
@philliii
@philliii Жыл бұрын
This is what i have been searching for. Thanks for the super easy to follow video. Saved me lots of pain. Great work. Cheeeeeeeeers!
@aiden9r
@aiden9r 2 ай бұрын
Still a hero video! Thank you very much!
@terjidjurhuus1917
@terjidjurhuus1917 Жыл бұрын
Great and to-the-point video! I have a domain already at GoDaddy, and I'm kind of confused how to get an API key for the DNS verification. Any inputs?
@MichaelJM
@MichaelJM 9 ай бұрын
I've been going mad trying to get step-ca to work. Had no idea you could put a private IP in the public DNS record. Very simple solution.
@enricoschiappa3643
@enricoschiappa3643 9 күн бұрын
Hello, tks very much for this video.One question: I have a Synology NAS running some Docker apps and I would like to know if you can also upload a video of how create local certificates for the Synology NAS running DSM 7.2 which includes its own NGINX proxy
@deandre1988
@deandre1988 Жыл бұрын
This is pretty nifty. I guess the logical next step is to setup and use a VPN, so that these url's can resove for devices on VPN when outside of LAN. As well as setup Dashy / Homer for all the services.
@user-vnjigcdrgg
@user-vnjigcdrgg Жыл бұрын
Have you tried to renew SSL certificate? I am able to add new Lets encrypt certificate via duckdns for different domain but I cannot renew the old one. I see the "Internal error" on the UI when I try to renew it manually and the message "Failed to renew certificate npm-2 with error: The DNS response does not contain an answer to the question: .. IN TXT" in the log.
@mspencerl87
@mspencerl87 Жыл бұрын
I had to add a *wildcard domain in my Local router via unbound DNS. To be able to resolve the domain and subdomains locally still. But after that everything worked
@spoilerkiller
@spoilerkiller Жыл бұрын
How did you do that?
@kanine9598
@kanine9598 Жыл бұрын
Works great on an Ubuntu VM instance running under proxmox. But I also like to torture myself trying to get these solutions to run under W11 > WSL2 > Docker > NPM, no luck so far no doubt some firewall issue. Thanks for the tutorial short and to the point.
@aers11
@aers11 6 ай бұрын
Great tutorial - worked like a charm!
@thefallenangel9544
@thefallenangel9544 Жыл бұрын
omg I was waiting for a tutorial using precisly docker and DuckDNS together and you just upload this perfect tutorial ! You save my time
What's On My Home Server? Storage, OS, Media, Provisioning, Automation
27:30
Wolfgang's Channel
Рет қаралды 1,2 МЛН
Your Remote Desktop SUCKS!! Try this instead (FREE + Open Source)
22:30
Tuna 🍣 ​⁠@patrickzeinali ​⁠@ChefRush
00:48
albert_cancook
Рет қаралды 148 МЛН
Sigma Kid Mistake #funny #sigma
00:17
CRAZY GREAPA
Рет қаралды 30 МЛН
Cat mode and a glass of water #family #humor #fun
00:22
Kotiki_Z
Рет қаралды 42 МЛН
Quilt Challenge, No Skills, Just Luck#Funnyfamily #Partygames #Funny
00:32
Family Games Media
Рет қаралды 55 МЛН
You're running Pi-Hole wrong! Setting up your own Recursive DNS Server!
18:02
Self-Hosting Security Guide for your HomeLab
18:43
Techno Tim
Рет қаралды 452 М.
HTTPS, SSL, TLS & Certificate Authority Explained
43:29
Laith Academy
Рет қаралды 160 М.
FREE Domain and SSL for Local Network | Nginx Proxy Manager on Docker - #13
16:22
Tech - The Lazy Automator
Рет қаралды 90 М.
Busting 8 Common Homelab Power Efficiency Myths
19:14
Wolfgang's Channel
Рет қаралды 143 М.
Secure Local Domains Easily with Pi-hole & Nginx Proxy
9:02
5 reasons EVERYONE needs a home server
12:05
TechHut
Рет қаралды 700 М.
Tuna 🍣 ​⁠@patrickzeinali ​⁠@ChefRush
00:48
albert_cancook
Рет қаралды 148 МЛН