I would like to host my own web server with a domain name I purchased but my public IP isn’t static.

  • SleepyBear
    link
    fedilink
    English
    1711 months ago

    I run ddclient on a local machine and it updates my Cloudflare DNS records if my IP changes.

    OPNSense has it built in too, if you use it. So does PFSense, I think. Been a while, might be misremembering.

  • @[email protected]
    link
    fedilink
    English
    1611 months ago

    I use duckdns.org , but if you are trying to host a webpage I totally recommend using Cloudflare, Cloudflare tunnels and a reverse proxy like nginx.

    Setting it up may be a bit tricky, but it is a gamechanger. I followed Ibracorp’s guides and I had no problem.

    • @[email protected]
      link
      fedilink
      English
      211 months ago

      I’ve also been on freedns.afraid.org for many years. Back when I switched from dyndns, it wasn’t possible to get Let’s Encrypt certificates on afraid.org’s domains, but that might have changed. I worked around it by taking a domain I already owned and using a CNAME to point it at my afraid.org domain.

      • Sam
        link
        fedilink
        English
        211 months ago

        I use Let’s Encrypt on my domains, but they’re domains that my afraid.org subdomains point to.

  • BetterNotBigger
    link
    English
    911 months ago

    If you only need public access to things like HTTP or SSH you don’t necessarily need to run dynamic ip and just setup Cloudflare Tunnels. So far I haven’t needed to put anything public that doesn’t run on the provided tunnels.

    • @starkcommandoOP
      link
      English
      311 months ago

      Where are the settings for these tunnels located in Cloudflare? I was looking around the website last night but didn’t have any luck.

      • BetterNotBigger
        link
        English
        111 months ago

        Look under the Zero Trust category and then once there you’ll see another menu item called Access. There you’ll find Tunnels, in addition to Tunnels you can add an Application in the same Access menu to create policies that only allow certain clients to connect.

    • @[email protected]
      link
      fedilink
      English
      011 months ago

      Cloudflare tunnels is the way to go for small self hosted content. You’re hiding behind their ddos protection and your IP / location remains hidden from end users.

    • @[email protected]
      cake
      link
      fedilink
      English
      211 months ago

      2nd, but with just a bash script. Also, I’m forwarding http & https to different IPs and the best thing about cloudflare is that you can restrict those ports to only be open when coming from cloudflare’s proxy. I like the extra layer of security, and dislike that they can see all traffic…

  • @hagerman
    link
    English
    811 months ago

    I use a Cloudflare tunnel rather than a dynamic DNS provider. Some in the self hosting community are opposed to Cloudflare, but I appreciate the tools they provide (especially Zero Trust so I can put my self hosted apps behind Okta).

    • Entropy
      link
      English
      211 months ago

      +1 for tunnels, easy to use and no port forwarding required

  • @[email protected]
    link
    fedilink
    English
    711 months ago

    your domain provider probably has an api to update dns records i use cloudflare with their api because then i can hide my ip behind their proxy or if i don’t have a public ip i can use their tunnels

    • KairuByte
      link
      English
      111 months ago

      Tunneling is one of the better options out there tbh.

  • @theghostoutside_
    link
    English
    711 months ago

    I use DuckDNS. There’s been only one outage for the ~2 years I’ve been using it and it’s free. I also use DuckDNS to acquire the SSL certificates for the reverse proxy.

    • @[email protected]
      link
      fedilink
      English
      211 months ago

      I also use duckdns, but in the last year it went down like twice or something. Its good but not really reliable.

      • @axzxc1236
        link
        English
        3
        edit-2
        11 months ago

        If you mean automatically update IP part, duckdns website has a very comprehensive guide.

        If you mean getting a free SSL certificate, you can use acme.sh (this is what I used) which has integrated support for duckddns (To use let’s encrypt you need to use --server letsencrypt in your command)

    • @nieceandtows
      link
      English
      111 months ago

      I used duckdns for my jellyfin server, but after a week or so I started getting malicious site warnings from Firefox, and had to ‘accept the risk and continue’ every time. Ended up going back to noip. It’s a pain to renew every month, but I haven’t had any other problems with it.

      • @[email protected]
        link
        fedilink
        English
        211 months ago

        I use noip as well, but because I only have an IP camera on that network, and the camera has built-in DDNS support for noip. But I hate it having to renew monthly.

      • @Bork
        link
        English
        211 months ago

        What do you mean renew every month?

        • @nieceandtows
          link
          English
          111 months ago

          You need to confirm each month that you’re still using that url if you’re in free tier. Otherwise it won’t be registered to you

  • @[email protected]
    link
    fedilink
    English
    5
    edit-2
    11 months ago

    Does your domain provider have a DDNS service? I buy my domains from namecheap.com and use their DDNS service for exactly what you’re describing.

    • @starkcommandoOP
      link
      English
      211 months ago

      I have NameCheap as well. I found their Windows client after I made this post. I’m still curious is there are better services out there. It seems Cloudflare may have the best tools for security for a webserver, i.e. hiding the real IP address.

      • @[email protected]
        link
        fedilink
        English
        111 months ago

        Cloudflare has a lot of great tools and provides service to most of the internet. Some folks don’t like how much of internet traffic is routed though Cloudflare… sort of like Google and if that’s not a bother then it may be a good choice.

      • PorkSoda
        link
        English
        111 months ago

        I use namecheap and dd client. Happy to share my config file if you need if.

  • beigeoat
    link
    fedilink
    English
    411 months ago

    First step would be to ensure that you can do port forwarding.

    1. Check if your IP address isn’t a private one or CGNAT.
    2. Now set up reverse proxy and try connecting to your service. If it connects, you are okay.
    3. Now this is something i didn’t know could happen but it did end up happening to me. I was happily port forwarding for a few months, until suddenly my port forwarding stopped working. Now I called my ISP, they said they did nothing(my ISP is a few guys who have no Idea about what they are doing, the other option to them is 512kbps DSL connection) at this point all my ingress ports are blocked and even outgoing ssh is blocked. Then the new month starts and everything is working again. I looked at my ISP website to get an idea of what may have caused this and the case seems to be that it was the first time I crossed 100GB in uploading. So my ISP has configured things such a way that port forwarding only works for the first 100GB of uploading.

    This is why I strongly recommend cloudfare tunnel or any other similar solution.

  • DunkinCoder
    link
    English
    411 months ago

    I use this container, favonia/cloudflare-ddns, for Cloudflare and my domain.

  • @[email protected]
    cake
    link
    fedilink
    English
    411 months ago

    My IP isn’t technically static but it hasn’t changed in the 3 years I’ve been with this ISP.

    • @[email protected]
      link
      fedilink
      English
      411 months ago

      This. But I use namecheap and the built in tool on pfsense to keep an A record up to date if it ever changed.

      • @starkcommandoOP
        link
        English
        111 months ago

        I have NameCheap as well. I was trying to set this up with the ddclient on OPNSense but the logs suggested it couldn’t connect to NameCheap. What do you need to authenticate other than the DDNS passcode supplied by NameCheap?

        • @[email protected]
          link
          fedilink
          English
          111 months ago

          Oof. Set this up years ago now…

          Add the hostname IE public Add the domain name IE starkcommando.com

          This will be public.starkcommando.com

          Leave username blank (this was a gotchya for me, if I recall correctly)

          Then put the generated namecheap ddns password (not your account password) that matches the record in.

          All set.

      • @[email protected]
        cake
        link
        fedilink
        English
        111 months ago

        I should automate something like that too. I just have one A record pointing to my IP and all my subdomains CNAME’d to that so that if it ever changes, I just have to update that one record.