I'm also tired of remembering ports, if there's a way of mapping those. Should I run a local proxy?
I'm also tired of remembering ports, if there's a way of mapping those. Should I run a local proxy?
If we're talking web-services - absolutely. I put Caddy in front of everything just to be able to simply use domains. You can also use it to map ports to either standard or more convenient ones if that suffices. Configuring reverse-proxy with Caddy [0] takes just a few lines:
http://some-service.internal {
reverse-proxy localhost:12345
}
After setting up a reverse-proxy or two you might want to expand your infrustructure with the following to to neaten thing up even more:- DNS-server: most routers can be that; another easy option would be PiHole.
- DHCP-server: same as above (PiHole does DHCP too).
- Reverse-proxie(s): you can have either just one for the entire network or a number closer to the amount of services if you choose to have HTTPS between everything. Wouldn't bother with Nginx for that unless there is a strong incentive.
- ACME-server: provides the certs for the local reverse-proxies if you choose to have HTTPS between everything. Caddy can also act as a very easy to set up ACME-server [1].
If you have all that set up, you can access all the local services securely and via readable URLs. Given all the services get their certs from the ACME-server, the consumers only need to trust (install) one root cert in order to consider all the local connections secure.
Might seem like a lot at first, but the configuration is fairly straightforward and I found it's worth the effort.
[0]: https://caddyserver.com/docs/caddyfile/directives/reverse_pr...
[1]: https://caddyserver.com/docs/caddyfile/directives/acme_serve...
For port mapping depends what specifically you’re aiming for. SVCB/HTTPS records are nice for having many https servers on a single system.
Theoretically SRV records can be set in dns to solve the port issue, realistically Nothing uses them so.... You are probably out of luck there. The way SRV records work is you are supposed to ask a network "Where is the foo service at?"(SRV _foo._tcp.my.network.) and dns sez "it's at these machines and ports" (SRV 1(pri) 1(weight) 9980(port) misc.my.network.(target))
https://www.rfc-editor.org/rfc/rfc2782
My personal low priority project is to put mac address in DNS, I am about as far as "I could fit them in an AAAA record"
As for specific software recomendations, I am probably not a good source. I run a couple of small openbsd machines(apu-2) that serve most of my home networking needs. But, I am a sys-admin by trade, while I like it, I am not sure how enjoyable others would find the setup.
There's the EUI48 rr type, but I don't know how widely supported it is
I even came up with the reverse record format apparently nobody wanted. 0.0.0.0.0.0.a.b.2.e.0.9.mac.arpa.
salutes
Depending on how one defines "nothing," they are honored by XMPP clients.
CoreDNS in Kubernetes also publishes SRV records, for any client in-cluster who wishes to look up the port number used by a named port on a v1.Service
For ports, anything that can just be run on 443 on its own VM, I do that. For things that either can’t be made to run on 443, or can’t do their own TLS, etc, I have a VM running nginx that handles certificates and reverse proxying.
I'm not aware of any DHCP change needed for that, since to the very best of my knowledge mDNS is a broadcast protocol. Involving DHCP would be pointing it at the copy of dnsmasq running on your router, such that the hostname that the devices present to DHCP are then resolved by dnsmasq, no mDNS required