I have wireguard and caddy set up with docker on my server:
version: "3.7"
x-common-variables: &common-variables
PGID: 1000
PUID: 1000
TZ: America/New_York
services:
caddy:
container_name: caddy
image: caddy:2.6.4
restart: unless-stopped
environment:
<<: *common-variables
HOST: "redacted"
LOCAL_IP: 192.168.1.2
ports:
- "80:80"
- "443:443"
- "443:443/udp"
volumes:
- ./appdata/caddy/Caddyfile:/etc/caddy/Caddyfile
- ./appdata/caddy/site:/srv
- ./appdata/caddy/data:/data
- ./appdata/caddy/config:/config
wireguard:
image: lscr.io/linuxserver/wireguard:latest
container_name: wireguard
cap_add:
- NET_ADMIN
- SYS_MODULE #optional
environment:
<<: *common-variables
PEERS: myPhone,myLaptop
ALLOWEDIPS: 0.0.0.0/0,::/0
volumes:
- ./appdata/wireguard:/config
- /lib/modules:/lib/modules #optional
ports:
- 51820:51820/udp
sysctls:
- net.ipv4.conf.all.src_valid_mark=1
restart: unless-stopped
Then in ./appdata/caddy/Caddyfile:
(config) {
@internal {
remote_ip 192.168.1.0/24
}
handle @internal {
reverse_proxy {args.0}
}
respond 404
}
mySecretService.{$HOST} {
import config "{$LOCAL_IP}:5678"
}
So if I'm not on my VPN (or at home) nothing is shown. Other considerations:
- You may want a VLAN or separate guest network depending on if you allow guests on your network, what type of services you're running, etc.
- Many of the things I run at home have password authentication and I use them in addition to the VPN restriction.
- This was the first thing I thought of and may be insecure for reasons outside of my expertise.
- The nice thing about this is that I run pihole in the same compose file so when my phone is on my VPN I get remote ad-blocking "for free".
- Tailscale is easier and nicer (UI-wise) to set up, but I stopped using it because it's a battery hog on iOS. The "trusting someone else's server" thing is also an issue, but if not for the battery issue, I would probably still be trading the added risk for the convenience. This was not too bad to set up, though, and I'm happy with it for my simple needs. The Tailscale app also doesn't have a convenience feature that the Wireguard app does: I can tell Wireguard specific networks that I don't want it to run on (i.e. when I'm home) so that it enables automatically when I leave and turns off when I'm home.