Homelab
Public Tier via frp
A Public Tier for the Homelab: Self-Hosted frp Tunnel, Opt-In Exposure, and HTTPS at the Edge
Overview
This article names the pattern that the Plex remote access guide built: a public tier. Every internet-reachable service in the homelab lives under via.<domain> and travels one route — a self-hosted frp tunnel from a small cloud cluster down to home — with TLS terminated at the edge and every exposed port an explicit, server-side decision. Nothing about the home network is visible: no port forwarding, no home IP in DNS, and no way for a workload to become public by accident.
Having trouble? See v1.13.0 for what your setup should look like after the worked example.
This article isn't ready yet
Check back soon for the full article.