Post #3395960
2026-06-12 13:08 UTC
I have many services that doesn't "need" to be public, as public facing for one specific reason. TLS.
A lot of the times android apps won't connect to http directions, not even local ones, and require a proper https connection with a well known CA.
For that I put the services behind a caddy reverse proxy to get a valid tls certificate.
And them I do the trick, and basically on caddy reject any connection that's not local. Thus, making the supposedly "public" site a practical "local" one.
Once there I just connect through wireguard.
Replies (1)
-
@nfms@lemmy.ml 2026-06-14 12:23
Clever. I'm just starting to mess with Caddy. Been struggling with Vaultwarden lately and your solution might fit my needs.