Reverse Proxy Best Practice -- Jail - VM - Separate Box

Reverse Proxy Best Practice -- Jail - VM - Separate Box

  • FreeNAS Jail

    Votes: 5 83.3%
  • FreeNAS VM

    Votes: 0 0.0%
  • Separate Box

    Votes: 1 16.7%

  • Total voters
    6

Simon Mackenzie

Dabbler
Joined
Aug 9, 2013
Messages
43
What are the pros and cons for setting up a reverse proxy in either a Jail, VM or separate box to service a number of sub domains in separate Jails and VM's?
Eg.
  • nextcloud.domain.world
  • moodle.domain.world
  • blog.domain.world
  • coppermine.domain.world
Etc. all serviced through a reverse proxy.

Would it be reasonable to use a jail for the reverse proxy?
Or should I use a VM?
Or is it just good practice to use a separate box setup for the reverse proxy?

Thanks in advance for your help.
 

adrianwi

Guru
Joined
Oct 15, 2013
Messages
1,231
I've got jail configured as a reverse proxy which also generates and auto renews the SSL certificates. It's redirecting to several other jails for Nextcloud, emby, WordPress, Home Assistant, and Calibre and a few docker containers in an Ubuntu VM.
 

Jailer

Not strong, but bad
Joined
Sep 12, 2014
Messages
4,977
I've got jail configured as a reverse proxy which also generates and auto renews the SSL certificates. It's redirecting to several other jails for Nextcloud, emby, WordPress, Home Assistant, and Calibre and a few docker containers in an Ubuntu VM.
Same here, works great for me.
 

Simon Mackenzie

Dabbler
Joined
Aug 9, 2013
Messages
43
So is it the case that running a reverse proxy in a jail is not going to be any significantly less secure on the WAN side than running a reverse proxy on a separate box to service subdomains residing in other jails and VMs?
 

ByteNick

Explorer
Joined
Jan 24, 2015
Messages
98
I've got jail configured as a reverse proxy which also generates and auto renews the SSL certificates. It's redirecting to several other jails for Nextcloud, emby, WordPress, Home Assistant, and Calibre and a few docker containers in an Ubuntu VM.
I have that as well, but I cannot make hassio.mydomain.com to work.
I installed Hass.io in a VM in FreeNAS 11.2-U3 running Ubuntu Server 18.04.
Any ideea how and what I should configure?
Please note that the rest (cloud.mydomain.com, plex.mydomain.com etc.) works.
 

adrianwi

Guru
Joined
Oct 15, 2013
Messages
1,231
Not sure, but if you're just running the Ubuntu VM for Hass.io have you considered running it in a jail?

There is a great guide here for getting it up and running using iocage.
 

ByteNick

Explorer
Joined
Jan 24, 2015
Messages
98
Not sure, but if you're just running the Ubuntu VM for Hass.io have you considered running it in a jail?

There is a great guide here for getting it up and running using iocage.
Hass.io in a jail?
I do not think it is possible.
 

sretalla

Powered by Neutrality
Moderator
Joined
Jan 1, 2016
Messages
9,703
Hass.io and Home Assistant are NOT exactly the same thing.

Just to clarify there... hass.io implies that you can run docker as all the add-ons (and indeed the home assistant main instance) are run on docker in that flavor of Home Assistant.

That option is very useful and worth having, but sadly, due to the docker requirement, not available in a jail as we all know.
 
Top