Post #3395937
2026-06-11 20:39 UTC
Yeah, maybe it's because I run public sites on kubernetes at work that I'm not as scared but a good locked down network is fine. Thousands or businesses run public URLs, as long as you configure it right you are mostly good. There is always a risk of vulnerabilities in the software for immich, your proxy, your auth provider so doing it that way increases your attack surface than just the VPN.
Replies (1)
-
@curbstickle@anarchist.nexus 2026-06-11 21:12
> Thousands or businesses run public URLs, as long as you configure it right you are mostly good. Part of "configuring it right" for companies is generally having the public-side be pretty well walled off from anything internal though, there isn't anything wrong with taking the same approach at home, too