Design, Implement, and Troubleshoot Robust Self-Hosted Infrastructure on the Real Internet
Introduction: Why Self-Hosting Is a Networking Problem
Chapter 1: The Self-Hosting Connectivity Problem
- The Promise and the Gap: Why Self-Hosting Is Harder Now Than Five Years Ago
- Residential Internet Topologies: What Your ISP Actually Gives You
- The Three Core Problems: No Inbound IPv4, Unstable IPv6, Broken DNS Assumptions
- What This Book Will Not Assume
- How to Use This Book
Chapter 2: How the Internet Connects to Your Home
- The ISP Edge: Broadband Network Gateways, DSLAMs, OLTs, and Cable Modems
- Customer Premises Equipment: Routers, Modems, and the Home Gateway Problem
- Your LAN Topology: Single Router, Multiple Routers, and Double NAT
- Packet Path from Your Server to the Internet and Back
- Where Restrictions Happen: ISP-Imposed Constraints on Inbound Traffic
- Identifying Your Actual Topology: Discovery Techniques
Chapter 3: IP Addressing, IPv4 Exhaustion, and CGNAT
- Public vs Private IP Addresses and RFC 1918
- IPv4 Exhaustion: Timeline, Impact, and Why It Matters to You
- Carrier-Grade NAT: How It Works and What It Hides
- CGNAT vs Double NAT: How to Tell the Difference
- The Self-Hosting Impact: Why Port Forwarding Fails Under CGNAT
- Living With CGNAT: Options and Trade-Offs
Chapter 4: Linux Networking Fundamentals
- Network Interfaces: Physical, Virtual, Loopback, and Tunnel Interfaces
- IP Address Configuration: Interfaces, Addresses, and Scope
- The Routing Table: How Linux Decides Where to Send Packets
- Forwarding, Connection Tracking, and the Netfilter Stack
- Network Namespaces: Isolation, VRFs, and Virtual Routers
- Inspecting State: ip, ss, route, and the /proc/net Interface
Chapter 5: DNS as Infrastructure
- Recursive vs Authoritative DNS and the Resolution Chain
- Local DNS Resolution on Linux: systemd-resolved, NetworkManager, and resolv.conf
- DNS Record Types That Matter: A, AAAA, CNAME, SRV, TXT, PTR
- Caching, TTLs, and Stale DNS Problems
- Split-Horizon DNS: Resolving Internally and Externally Differently
- DNSSEC: Concepts and Practical Reality for Self-Hosters
- DNS, Certificates, and SNI: The Trust Chain
Chapter 6: Firewalls, nftables, and Connection Tracking
- Netfilter: Hooks, Chains, and the Packet Path Through the Kernel
- nftables Syntax: Tables, Chains, Sets, Maps, and Rules
- Connection Tracking: States, Expectations, and Stateful Filtering
- Default Policies: Deny, Allow, and Reasonable Middle Ground
- NAT in nftables: SNAT, DNAT, Masquerade, and Hairpin
- Logging, Rate Limiting, and Detecting Reconnaissance
- Firewall Design for Self-Hosted Environments
Chapter 7: Linux Routing Engineering
- Route Selection: Longest Prefix Match and Route Metrics
- Multiple Routing Tables: Main, Local, and Custom Tables
- Policy-Based Routing: fwmark, Sources, and Destinations
- Asymmetric Routing: Causes, Symptoms, and Solutions
- VRFs and Network Namespaces for Traffic Separation
- Debugging Routing Problems: tracepath, traceroute, and tcpdump Correlation
- Common Routing Mistakes in Self-Hosting
Chapter 8: IPv6 for Self-Hosting
- IPv6 Addressing: Global Unicast, Link-Local, Unique Local, and Special Ranges
- SLAAC, Router Advertisements, and Stateless Address Assignment
- DHCPv6 and Stateful IPv6 Configuration
- IPv6 Prefix Delegation: How It Works and Why It Matters
- Stable Addresses: DHCPv6-PD with Static Lease, Stable SLAAC, and Trade-Offs
- Firewalling IPv6: Common Mistakes and Complete Policies
- IPv6, DNS, and Certificates: AAAA Records and SNI
- When Your ISP Changes the Prefix: Detection, Reaction, and Automation
Chapter 9: NAT and Port Forwarding Mechanics
- How NAT Works: Packet Rewriting, State Tables, and Port Mapping
- Port Forwarding: Configuration, Topology, and Packet Flow
- Hairpin NAT and NAT Loopback: Why It Fails by Default
- NAT Traversal Assumptions: Cone NAT, Symmetric NAT, and Endpoint Independence
- When Port Forwarding Fails: CGNAT, ISP Blocking, and Port Conflicts
- NAT and IPv6: The Fundamental Incompatibility
Chapter 10: WireGuard Fundamentals
- WireGuard Protocol: Noise Framework, Encryption, and Handshake
- Key Generation and Identity: The Public-Key Model
- Configuration Semantics: ListenPort, Endpoint, and AllowedIPs
- How AllowedIPs Works: Routing Decisions and Traffic Selection
- WireGuard and the Linux Kernel: Tunnel Interfaces and Routing
- Persistent Keepalives: Why They Exist and When You Need Them
- Common Configuration Mistakes and Their Symptoms
- WireGuard Monitoring with wg and wg-queue
Chapter 11: VPN Architectures for Self-Hosting
- Road-Warrior Access: Remote Client to Home Network
- Full-Tunnel vs Split-Tunnel: Security, Performance, and Convenience
- Site-to-Site VPNs: Connecting Segments and Branches
- Hub-and-Spoke vs Mesh Topologies
- Subnet Routing Through WireGuard: AllowedIPs as Route Control
- WireGuard with NAT Behind the VPN: Client and Server Considerations
- Comparing WireGuard, IPsec, and OpenVPN for Self-Hosting
Chapter 12: Reverse Tunnels and Outbound-Only Connectivity
- The Outbound-Only Strategy: Why Tunnel Out Instead of Waiting Inbound
- SSH Reverse Tunnels: Local Port Forwarding in Reverse
- Reverse WireGuard: Client-Initiated Connections to a VPS Server
- Relay Architectures: VPS as Public Ingress, Tunnel Back Home
- Rendezvous and Hole Punching: When and Why They Work
- Managed Reverse Tunnel Services: Tailscale, ZeroTier, Cloudflare Tunnel, and Alternatives
- Designing a CGNAT-Safe Architecture Using Reverse Tunnels
Chapter 13: Dynamic DNS and Name Resolution for Self-Hosters
- Dynamic DNS: How It Works and Provider Options
- Self-Hosted Authoritative DNS: BIND, CoreDNS, and dnsmasq
- Split-Horizon DNS Implementations: Internal vs External Records
- Service Discovery in Homelabs: mDNS, DNS-SD, and Simple DNS-Based Approaches
- Wildcard Certificates and Dynamic DNS: Combining Them
- Handling IPv6 Prefix Changes with DNS: Automation and Scripting
- DNS over TLS and DNS over HTTPS for Resolver Privacy
Chapter 14: Reverse Proxies as Internet Ingress
- The Reverse Proxy Role: Ingress Control, TLS Termination, and Backend Routing
- HTTP Reverse Proxying: Host Headers, Paths, and Upstream Routing
- TCP Proxying: Exposing Non-HTTP Services Through a Single Ingress
- SNI and Multi-Domain TLS Termination
- TLS Certificates: ACME, Certbot, Let’s Encrypt, and Automation
- Authentication, Headers, and Trust: Forwarding Auth and Preserving Client Info
- Rate Limiting, Access Control, and Protection at the Edge
- Comparing nginx, Caddy, and HAProxy for Self-Hosting Ingress
Chapter 15: Container Networking for Self-Hosted Services
- Docker Networking Drivers: Bridge, Host, None, and Overlay
- Docker Bridge Networks: NAT, Port Publishing, and Packet Flow
- Container-to-Host Communication and Host Firewall Interactions
- Docker Compose Networking: Services, Internal Networks, and DNS
- Network Policies and Container Isolation
- Running WireGuard and Tunnels in Containers
- Container Networking Best Practices for Self-Hosting
Chapter 16: Reference Architecture One: Single Machine Home Server
- Requirements and Design Decisions
- Network Topology and Addressing
- Base System: Interfaces, Routing, and nftables Firewall
- DNS Configuration: Domain, Records, and Resolution
- Reverse Proxy: nginx or Caddy with TLS Automation
- Service Deployment: Example Services and Exposure
- Security Hardening: SSH, User Accounts, and Least Privilege
- Operational Checklist and Troubleshooting Hints
Chapter 17: Reference Architecture Two: Multi-Host Homelab with VPN Access
- Requirements: Segmentation, Remote Access, and Internal Communication
- Network Topology: Subnets, Gateways, and Addressing Plan
- WireGuard VPN: Road-Warrior and Hub-and-Spoke Configuration
- Internal DNS: Authoritative Resolution Across Subnets
- Inter-Subnet Routing and Firewall Policy
- Reverse Proxy Across Multiple Backend Servers
- Container Host Integration: Docker on the Homelab Network
- Complete Working Configuration: All Components Integrated
Chapter 18: Reference Architecture Three: CGNAT Survival With VPS Relay
- Requirements: No Inbound IPv4, Unreliable IPv6, Full Public Access
- VPS Selection and Cost Considerations
- Reverse WireGuard Tunnel: Server on VPS, Client at Home
- Route Propagation: Which Traffic Goes Through the Tunnel
- DNS and Dynamic DNS With the VPS as Authoritative Edge
- Reverse Proxy on VPS: Terminating TLS and Forwarding Through Tunnel
- IPv6 as Primary When Available: Failover and Dual-Stack Strategy
- Security Model: Trust Boundaries, Tunnel as Perimeter, and Risk Assessment
- Complete Working Configuration
Chapter 19: Reference Architecture Four: IPv6-Enabled Homelab With Dynamic Prefix
- Requirements: Stable Self-Hosting With a Changing Delegated Prefix
- Prefix Delegation Configuration: systemd-networkd, radvd, and DHCPv6
- Stable Address Assignment: DHCPv6-PD With Static Leases
- DNS Automation: Updating Records When the Prefix Changes
- nftables Policies for IPv6: Matching Both Families
- Reverse Proxy With IPv6 and AAAA Records
- IPv6 Firewalling Mistakes to Avoid
- Complete Working Configuration
Chapter 20: Security Architecture for Self-Hosted Infrastructure
- Threat Modeling for Self-Hosters: What You Are Protecting Against
- Attack Surfaces: Internet-Facing Services, VPNs, and Internal Services
- Network Segmentation as Defense: Isolating Critical Services
- Least Privilege: Services, Users, Containers, and Tunnels
- SSH Hardening: Keys, Configuration, and Access Patterns
- VPN Key Management: Rotation, Revocation, and Multi-Peer Policies
- TLS Lifecycle: Certificate Renewal, Revocation, and Monitoring
- Secrets Management in Self-Hosting: Avoiding Hardcoded Credentials
- Logging, Monitoring, and Intrusion Detection
- IPv6 Exposure: The Forgotten Attack Surface
- Supply Chain and Container Image Security
- The Difference Between Being Reachable and Being Secure
Chapter 21: Observability and Systematic Troubleshooting
- Troubleshooting Methodology: From Symptom to Packet Path
- Essential Tools: ip, ss, tcpdump, dig, nft, conntrack, traceroute, curl, openssl
- Reading tcpdump Output: Filtering, Decoding, and Following Connections
- Diagnosing DNS Problems: dig, resolvectl, and Cache Issues
- Diagnosing Firewall Blocks: nft Logs, conntrack State, and Rule Tracing
- Diagnosing Routing Problems: ip route, Policy Routing Checks, and Asymmetry
- Diagnosing WireGuard Problems: wg Show, Endpoint Reachability, and AllowedIPs
- Diagnosing Reverse Proxy Issues: Upstream Failures, SNI, and Protocol Mismatch
- Common Failure Scenarios and Their Diagnoses
- Building Observability: Logging, Metrics, and Alerting for Self-Hosted Networks
Chapter 22: Operations, Reliability, and Future-Proofing
- System Updates: Patching Without Downtime for Critical Services
- Configuration Management: Git, Ansible, or Script-Based Approaches
- Backups: Configuration, Data, Keys, and Recovery Procedures
- Monitoring: Uptime Checks, Service Health, and Alerting
- Handling ISP Changes: Address Changes, Prefix Changes, and Topology Changes
- Disaster Recovery: When the Home Server Is Unreachable
- Documentation: Documenting Your Architecture While It Is Fresh
- Future Trends: What Self-Hosters Should Watch