A few months ago, I wrote about setting up redundant monitoring with Healthchecks.io and completely overhauling my backup strategy. Once you have a homelab running smoothly and reliably, the next logical step is figuring out how to access your services when you aren't connected to your home network.
For a long time, the standard advice was to set up a dynamic DNS provider, port-forward 80 and 443 on your router, and point everything to a reverse proxy like Nginx or Traefik.
While that method still works, exposing your home IP address directly to the open internet in 2026 is asking for trouble. Automated scanners will find your open ports within minutes, and a single vulnerability in one of your self-hosted apps could compromise your entire local network.
This post walks through how I handle external access today, favouring secure tunnels and identity verification over open ports.
Closing the Ports
The first rule of my current setup is simple: no open inbound ports on the router.
Instead of opening a path from the internet into my network, I use outbound tunnels. The software running inside my homelab reaches out to a secure edge network, creating a continuous connection. When I request a web page, the traffic is routed through that established tunnel.
There are a few ways to achieve this, but I primarily split my access into two categories: Admin access and Web access.
1. Admin Access: Tailscale
For services that only I should ever have access to—like Proxmox management interfaces, SSH access to VMs, or internal file shares; I don't expose them to the web at all, not even behind any type of login screen.
Instead, I use Tailscale. Tailscale is a zero-config VPN built on top of WireGuard. By installing the Tailscale client on my phone and laptop, and running a Tailscale subnet router in my homelab, I can access my local IP addresses (like 192.168.1.x) from anywhere in the world as if I were sitting at my desk.
It requires no port forwarding, handles NAT traversal automatically, and ensures that my infrastructure management is completely invisible to the public internet.
2. Web Access: Cloudflare Tunnels
For services that I want to access easily from any web browser without needing a VPN client—such as Nextcloud, Uptime Kuma, or media servers—I use Cloudflare Tunnels (formerly Argo Tunnel).
Cloudflare Tunnels run a lightweight daemon (cloudflared) inside your network. It creates an encrypted outbound connection to Cloudflare's edge. You then configure your DNS records to route traffic for your domain (e.g., services.yourdomain.com) through that tunnel.
Here is a stripped-down example of the docker-compose.yml I use to run the connector alongside my apps:
version: '3.8'
services:
cloudflared:
image: cloudflare/cloudflared:latest
container_name: cloudflare-tunnel
restart: unless-stopped
command: tunnel run
environment:
- TUNNEL_TOKEN=your_generated_token_here
networks:
- proxy_network
networks:
proxy_network:
external: true
By placing cloudflared on the same Docker network as my reverse proxy or applications, it can route traffic directly to them without anything being exposed to the host machine's network.
Adding an Identity Layer
Just routing traffic through Cloudflare isn't enough; the applications still need to be secured. While most self-hosted apps have their own login screens, I prefer not to rely on them as the only line of defence.
To solve this, I use Cloudflare Access to put an identity provider in front of my web-facing tunnels. Before a request even reaches my home network, Cloudflare intercepts it and asks for authentication. I have mine tied to a single sign-on provider, but you can easily set it up to send a one-time PIN to your email address or use GitHub/Google OAuth.
If an attacker tries to access my Uptime Kuma dashboard, they are stopped at Cloudflare's edge servers. My home internet connection doesn't even see the traffic.
Final Thoughts
Moving away from traditional port forwarding took a bit of a mindset shift, but the peace of mind is worth the initial setup time. I no longer have to worry about maintaining fail2ban rules, managing Let's Encrypt certificates locally, or stressing over a zero-day exploit in a self-hosted app.
If you are still running open ports on your router, I highly recommend spending a weekend looking into Tailscale or Cloudflare Tunnels. It makes managing a homelab significantly less stressful.