6. Publishing Shapps Safely
It is great that you can use all of your apps locally, but you are simply not always at home. Also if you have other users outside of your home then they need to be able to talk to your server from outside. In this book we discuss the different methods you can possibly publish your apps to the outside world. Each come with their own pros and cons and in the end it all depends on the situation which method would be best. Enjoy the read and hopefully you learn something ;)
- 1. Wireguard VPN
- 2. Reverse Proxy with Public IP
- 3. Reverse Proxy with CGNAT
- 4. What not to Publish
- 5. Prevention
1. Wireguard VPN
1. Introduction
2. Installation
2. Reverse Proxy with Public IP
3. Reverse Proxy with CGNAT
4. What not to Publish
1. Can it stay local-only?
2. Can it be reachable only over VPN?
3. Can it use private DNS/internal TLS?
4. If it must have public DNS, can Caddy restrict it strongly?
5. Does the app still require authentication?
5. Prevention
Prevention Strategies
To mitigate these risks, consider implementing the following security measures:
- Keep Software Updated: Regularly update your application and its components to patch vulnerabilities.
- Use Strong Passwords: Encourage users to create complex passwords and consider implementing multi-factor authentication (MFA).
- Limit Login Attempts: Use tools to restrict the number of failed login attempts to prevent brute-force attacks.
- Monitor Activity: Enable logging and monitoring to detect suspicious activities and respond promptly.