conv.

All stories
TechActive today · day 3

Developer publishes guide to self-hosting behind CGNAT using WireGuard tunnel

David Alvarez Rosa documents a workaround for carrier-grade NAT by bridging a home server through a cheap VPS.

What to know

  • CGNAT (carrier-grade NAT) blocks traditional port forwarding for self-hosted services; IPv4 address shortage means ISPs now share IPs across neighborhoods.
  • Alvarez Rosa's solution tunnels traffic through a cheap VPS bridge using WireGuard, eliminating the need for a static IP at home while keeping expensive compute local.
  • Developers debate whether VPS-bridging justifies its cost and complexity versus running services directly on a VPS, with security and storage needs as key factors.

The dispute Whether the hybrid approach of using a VPS bridge to avoid CGNAT limitations is economically or operationally justified compared to running services directly on a VPS. · positions read across 43 posts and comments

many voices

Home hosting with a VPS bridge can be worthwhile for workloads requiring significant compute or storage that cost more on a VPS.

  • “I asked myself that question years ago...and then i went to self-host Nextcloud on a VPS and realized that my storage needs outgrew what was reasonably cost-effective VPS storage…so then i moved my nextcloud instance to my homelab”

    mxuribe · Lobsters ↗
some voices

Running services directly on a VPS makes more sense than paying for both a bridge VPS and home hardware.

  • “If I have to pay for a VPS anyway, why not run my services on it?”

    singpolyma · Lobsters ↗
some voices

The security implications of bridging home networks require careful defense-in-depth measures to mitigate risks.

  • “But I don't really feel comfortable with a full connection between a bridge and home network. I suppose this isn't that different from exposing a server in your physical network to the internet. But it still does give people potential…”

    creesch · Lobsters ↗

David Alvarez Rosa Author, software engineer

Developer publishes guide to self-hosting behind CGNAT using WireGuard tunnel
linux,networking

How it unfolded 2 developments, newest first · click a bar or a number to jump postscomments

Peak 8 pieces in one hour at Sep 22, 2 AM; 46 pieces over 3 days (3 posts · 43 comments) Sep 21, 6 AM — 1 piece · 1 post — Hacker News 1Sep 21, 7 AM — quietSep 21, 8 AM — quietSep 21, 9 AM — quietSep 21, 10 AM — quietSep 21, 11 AM — quietSep 21, 12 PM — quietSep 21, 1 PM — 1 piece · 1 post — Lobsters 1Sep 21, 2 PM — quietSep 21, 3 PM — 2 pieces · 2 comments — Lobsters 2Sep 21, 4 PM — 1 piece · 1 comment — Lobsters 1Sep 21, 5 PM — quietSep 21, 6 PM — 3 pieces · 1 post · 2 comments — Lobsters 2, Hacker News 1Sep 21, 7 PM — 1 piece · 1 comment — Lobsters 1Sep 21, 8 PM — 1 piece · 1 comment — Lobsters 1Sep 21, 9 PM — 3 pieces · 3 comments — Lobsters 3Sep 21, 10 PM — quietSep 21, 11 PM — 1 piece · 1 comment — Lobsters 1Sep 22, 12 AM — 5 pieces · 5 comments — Lobsters 5Sep 22, 1 AM — quietSep 22, 2 AM — 8 pieces · 8 comments — Lobsters 8Sep 22, 3 AM — quietSep 22, 4 AM — 4 pieces · 4 comments — Lobsters 4Sep 22, 5 AM — 3 pieces · 3 comments — Lobsters 3Sep 22, 6 AM — quietSep 22, 7 AM — 1 piece · 1 comment — Lobsters 1Sep 22, 8 AM — 1 piece · 1 comment — Lobsters 1Sep 22, 9 AM — 2 pieces · 2 comments — Lobsters 2Sep 22, 10 AM — quietSep 22, 11 AM — quietSep 22, 12 PM — quietSep 22, 1 PM — quietSep 22, 2 PM — quietSep 22, 3 PM — quietSep 22, 4 PM — 1 piece · 1 comment — Lobsters 1Sep 22, 5 PM — 1 piece · 1 comment — Lobsters 1Sep 22, 6 PM — quietSep 22, 7 PM — quietSep 22, 8 PM — quietSep 22, 9 PM — quietSep 22, 10 PM — quietSep 22, 11 PM — quietYesterday, 12 AM — 1 piece · 1 comment — Lobsters 1Yesterday, 1 AM — quietYesterday, 2 AM — quietYesterday, 3 AM — quietYesterday, 4 AM — quietYesterday, 5 AM — quietYesterday, 6 AM — 1 piece · 1 comment — Lobsters 1Yesterday, 7 AM — quietYesterday, 8 AM — quietYesterday, 9 AM — 1 piece · 1 comment — Lobsters 1Yesterday, 10 AM — quietYesterday, 11 AM — 1 piece · 1 comment — Lobsters 1Yesterday, 12 PM — quietYesterday, 1 PM — quietYesterday, 2 PM — quietYesterday, 3 PM — quietYesterday, 4 PM — 1 piece · 1 comment — Lobsters 1Yesterday, 5 PM — quietYesterday, 6 PM — quietYesterday, 7 PM — quietYesterday, 8 PM — quietYesterday, 9 PM — quietYesterday, 10 PM — quietYesterday, 11 PM — quietToday, 12 AM — 1 piece · 1 comment — Lobsters 1Today, 1 AM — quietToday, 2 AM — quietToday, 3 AM — quietToday, 4 AM — quiet 12
Sep 22yesterdaynow · 5:51 AM ET
  1. 2

    Lobsters community discussion surfaces implementation concerns

    The post reached Lobsters where developers engaged with the technical approach, raising questions about security, cost trade-offs, and alternative solutions. Commenters discussed whether using a VPS for the bridge made sense versus running services directly on the VPS, and surfaced security concerns about full network connections between bridge and home.

    “If I have to pay for a VPS anyway, why not run my services on it?”
    — singpolyma, Lobsters commenter · source
    • You can pay for a very cheap VPS as a proxy and then run more expensive compute and storage locally.

      Helithumperlinux,networking2d ago34▲view on Lobsters ↗
    2 more of the top 3 · 43 posts in this stretch
    • If I have to pay for a VPS anyway, why not run my services on it?

      singpolymalinux,networking2d ago8▲view on Lobsters ↗
    • > But I don't really feel comfortable with a full connection between a bridge and home network. I suppose this isn't that different from exposing a server in your physical network to the internet. But it still does give people potential access to your entire network when something on the bridge is configured wrongly. You can practice defense in…

      ggpsvlinux,networking2d ago7▲view on Lobsters ↗
    all of them →
  2. 1

    Alvarez Rosa publishes CGNAT self-hosting guide

    David Alvarez Rosa published a technical article detailing how to run self-hosted services from behind carrier-grade NAT using a WireGuard tunnel to a VPS bridge. The setup uses a mid-range machine in his mother's basement in northern Spain, exposed through a cheap VPS in a French data center, with a 39 ms latency penalty.

    “There is nothing more satisfying than owning, end to end, the software and the hardware you use without relying on abusive cloud corporations.”
    — David Alvarez Rosa

What people are saying 21 voices from 1 site · best of 43 · verbatim