casey@lemmy.wiuf.netOPtoSelfhosted@lemmy.world•Reddit Exodus: Welcoming the Selfhosted Community to Lemmy - Migrating to Freedom! (Crosspost)English
1·
1 year agoI would be curious if there might be a way to give some sort of “attribute of credibility” that we could come up with.
Yo - absolutely!
WG easy posts the GUI on a separate port than the primary Wireguard port you’d need to open in the firewall. I think it’s 51821 - but this can easily be changed depending on if you’re using docker-compose files or a gui like portainer to manage this.
In my case - I am using Nginx Proxy Manager - and it even has it’s own basic password requirement “Access List” availability. With NPM I’m routing that gui over vpn (local dns) but you could put it behind a password with limite security via Access List, or the step beyond look into “middleware” like Keycloak.