Duck DNS
duckdns.org
duckdns.org
Now I use a combination of Tailscale[1] for private services only to me and Tailscale Funnels[2], and Cloudflare Tunnels[3] for public service exposure.
This accomplishes the same thing I was doing with DDNS and my ISP IP, but in a much more secure and stable manner.
2. https://tailscale.com/kb/1223/tailscale-funnel/
3. https://developers.cloudflare.com/cloudflare-one/connections...
How do you connect outside the network?
I am running DDNS to access my home services and it has been very error prone and frustrating. I moved some services back to the cloud because the bots were using all my DSL upload that we didn’t have enough bandwidth to work even with cloudflare firewalls.
There's an nginx reverse-proxy container in the stack that routes traffic to the individual service containers via the servername; eg nitter.tail.net goes to the nitter container, teddit.tail.net goes to the teddit container, etc.
The nginx proxy only listens on the Tailnet interface and only accepts connections from the Tailnet CIDR, therefore any device I have on my tailnet can access them. Letsencrypt is also setup so everything is over https.
This allows me to access them from my phone, laptop, whatever when connected using Tailscale.
Tailscale essentially let me completely remove any need for port forwarding on my router and still have global access. It's truly amazing.
https://github.com/ecliptik/tailscale-privacy-frontends
I've tested it out on a new Tailnet on a t3.medium EC2 instance and it works relatively well. Adding new services should be relatively easy.
I'm planning to write up a post about the more technical details on the stack still.
Basically all the services on nomad listen on the tailnet, and traefik straddles the tailnet and the public internet. It then loads the service configurations from nomad and exposes them using let’s encrypt certificates.
Combined with only allowing connections to hosts from the Tailnet and https, forgoing passwords makes them easier to manage and use.
Granted most these personal services are things like Audiobookshelf, Nitter, Plex, and Newsblur. While important to me, they're not exactly high value targets.
My internal Gitea is locked down more and has MFA enabled since I always see git as something to secure.
WARP is primarily used for long running services I have, like GotoSocial or Lemmy that need public ingress over https for federation.
Reddit's rationale for the C&D was that "Offering this login option misleads and confuses consumers by implying Reddit’s endorsement, association or sponsorship of your application", which is
1. complete bullshit; and
2. hypocritical, given that it's possible to log into reddit with one's Google and/or Apple account
- Persona is dead.
- Twitter has been rebranded and its future is uncertain.
- Reddit took them down
Github and Google are both reliable oauth providers. Though the github oauth is linked to a personal account, not an org, which is all kinds of awful for reliability of the app.
Since I use 1Password, I've started to always retain backup login+PW methods for every website I use oauth for anyway. And if I do use oauth, it's ALWAYS gonna be using Google (which is reliable and I pay for) or nothing except for very specific scenarios where oauth perms are relevant. I think the federated auth dream is just entirely dead at this point.
> I think the federated auth dream is just entirely dead at this point.
That you had to support individual auth providers, none of which were reliable, was a major issue. Had they been "oh here's my auth provider" and you stuck it into a site, that would have been grand. No need to have a bunch of "login with" providers up top.
That sort-of worked with OAuth 1.0, IIRC that protocol had issues which is why we had OAuth 2.0 which sorta worked (and I've never seen an easy impl, where you just "stand up" an oauth server and then clients easily use it). Back when you could use the likes of Yahoo to OAuth you around.
Duck DNS – About - https://news.ycombinator.com/item?id=33367767 - Oct 2022 (48 comments)
Duck DNS – free dynamic DNS hosted on AWS - https://news.ycombinator.com/item?id=30539059 - March 2022 (100 comments)
Duck DNS – free dynamic DNS hosted on AWS - https://news.ycombinator.com/item?id=28383113 - Sept 2021 (1 comment)
Free DNS from Duck DNS - https://news.ycombinator.com/item?id=6425925 - Sept 2013 (2 comments)
Am I missing something?
You tend to get a few echoes relating to popular posts (or comments from those posts that suggest alternatives and/or pros and cons)
DuckDNS just kinda sits there and does its thing. So it may be interesting for a HN audience to know that a decent usable dynamic DNS service is still around.
(Side note: Earlier this year, Freenom has temporarily stopped giving away free domains due to an ongoing cybersquatting lawsuit from facebook. Very sad.)
- It's really free instead of "annoyingly free" that requires you to confirm every month that you are still using it.
- It lets you update with a simple HTTP request + token (e.g. "curl ..." command), no login protocol, nor any special login protocol that good luck if it's supported by your router or DVR.
- Simple copy-paste instructions for dozens of systems, instead of others DNSs that have no docs and their only instructions is to make you install their adware/spyware app
- No ads. Just a simple donate button at the end of the admin page which I haven't visited in months/years
[1] https://joker.com/faq/content/11/427/en/what-is-dynamic-dns-... [2] https://www.namecheap.com/support/knowledgebase/subcategory/...
1. https://www.namecheap.com/support/knowledgebase/article.aspx...
I use DynDNS for a Wireguard VPN with WG Dashboard hosted behind my home firewall on a Proxmox CT (LXC). Works great for allowing me to tunnel traffic on untrusted Wifi, and of course, to hit LAN devices remotely. I'm lucky my home ISP (FIOS) doesn't cheap out and CGNAT me like so many seem to be doing now. In the past, I used to open 80/443 and self-host websites, but that's pretty silly nowadays.
It's all based on donation and there's not a ton of information, so there's really no way of knowing how reliable it is.
Edit: yes
> Unfortunately this service is often abused by phishers.
Not needing to click on a link to “renew” my host name every month is a huge plus.
The biggest issue however is that it doesn’t support CNAMEs so I can’t migrate to a Tailscale Funnel address without redoing the entire setup, since I have a VPS configured to reverse proxy Home Assistant from home, through Tailscale of course.
This is also similar to the old way the phone system used to work. If you move across the country now, you can keep your cell number no problem (and maybe even landline too?), but in the Bell monopoly days, you most certainly could not move out of an area code and keep your number, as the number itself reflect some sort of hierarchical structure of the network. There may have even been further restrictions on the number prefix (XXX in XXX-YYYY), but I don't know that for sure.
Actually, I prefer having a dynamic IP as it makes blacklisting individual IPs useless.
My ISP don’t hand them out and charge per IPv4 if you want static at a lovely $10 per month. And they don’t have IPv6 implemented..
At that point, the main consumers of IPv4 will be old devices and legacy clients that for whatever reason can't support IPv6. Nobody will be paying for ip's otherwise, so ISPs can continue selling their business plans as normal, the rest of us can just use IPv6 and not worry about rent-seeking behavior from the exhausted IPv4 space.
I would guess, around 50-60% penetration, you will start to see real "only works with ipv6" behavior, and the trend will accelerate...its already at 30% which is enough incentive to at least try to get on IPv6 now if possible...
I have never had mine change in the 10years I have been self hosting, and that included 2 address changes (same town, same ISP).