Homelab
Public Tier HTTPS
A Public Tier for the Homelab: frp Transport, Opt-In Exposure, and TLS That Terminates at Home
Overview
The public tier exposes internet-reachable services under <public-label>.<domain>, each over a self-hosted frp tunnel the homelab dials out to, with TLS terminating at home on a wildcard from the certificate foundation. The edge relays ciphertext it can never read: no certificate lives there, and the home network's address appears in no DNS record. A vendor tunnel puts the traffic in someone else's hands. A self-hosted tunnel that still terminated TLS at its own edge kept the plaintext one hop too far out. Here the homelab owns the DNS, the tunnel, and the termination.
Having trouble? See v2.3.0 for what your setup should look like after completing this article.
This article isn't ready yet
Check back soon for the full article.