docker compose up -d
Self-Hosted VPNs, Proxies, and Remote Access
The plumbing that gets you back into your own network: WireGuard-based VPNs and mesh networks, reverse proxies that terminate TLS and route by hostname, dynamic DNS updaters, and browser-based remote desktop gateways.
38 apps in this category
Caddy: Web Server With Automatic HTTPS A modern web server and reverse proxy that obtains and renews TLS certificates automatically, configured in a few lines rather than a few dozen.
Cloudflared: Tunneling daemon for proxying traffic from the Cloudflare network Tunneling daemon for proxying traffic from the Cloudflare network.
Coder: Provision remote development environments via Terraform Provision remote development environments via Terraform.
ddclient: Update dynamic DNS entries for accounts on a wide Update dynamic DNS entries for accounts on a wide range of dynamic DNS services.
DDNS Updater: Periodic DNS record updates across a number of DNS Periodic DNS record updates across a number of DNS providers.
Firezone: Zero-Trust Remote Access Built on WireGuard A remote access platform using WireGuard tunnels with identity-based policies, device verification, and audit logs, with clients for every major platform. The source is public, but production self-hosting of the control plane is not officially supported.
FlareSolverr: Proxy server to bypass Cloudflare protection Proxy server to bypass Cloudflare protection.
frp: Expose Services Behind NAT With a Fast Reverse Proxy Tunnel A reverse tunnel that exposes services on a home network or behind CGNAT through a server with a public IP, supporting TCP, UDP, HTTP, HTTPS, secret STCP tunnels, and P2P XTCP. Configured in TOML. Apache 2.0.
GoProxy: Automatic Docker Reverse Proxy A lightweight reverse proxy written in Go that discovers Docker containers automatically and routes traffic to them without manual configuration.
Guacamole: Clientless remote desktop gateway Clientless remote desktop gateway.
HAProxy: Fast and reliable reverse-proxy offering high availability, load balancing, and proxying for TCP and HTTP-based applications Fast and reliable reverse-proxy offering high availability, load balancing, and proxying for TCP and HTTP-based applications.
Headscale: Open-source implementation of the Tailscale Open-source implementation of the Tailscale control server.
MeshCentral: complete web-based remote monitoring and management web site A complete web-based remote monitoring and management web site.
Neko: Self-hosted virtual browser Self-hosted virtual browser.
NetAlertX: Scans for devices connected to your network and alerts you if new and unknown devices are found Scans for devices connected to your network and alerts you if new and unknown devices are found.
NetBird: Combines a configuration-free peer-to-peer private network and a centralized access control system into a single platform Combines a configuration-free peer-to-peer private network and a centralized access control system into a single platform.
NetBox: Network Source of Truth for IPAM and DCIM The standard open-source source of truth for network infrastructure, modeling IP addresses, VLANs, racks, devices, circuits, and cabling for documentation and automation.
Nginx Proxy Manager: Reverse Proxy With a Web UI A web interface over nginx that handles reverse proxy hosts, automatic Let's Encrypt certificates, and access control without editing configuration files.
OPNsense: Open-source, FreeBSD-based firewall and routing Open-source, FreeBSD-based firewall and routing software.
Pangolin: Identity-Aware Tunneled Reverse Proxy A self-hosted, identity-aware tunneled reverse proxy built on WireGuard, for securely exposing private services without opening ports.
pfSense: FreeBSD-Based Firewall and Router A mature open-source firewall and router distribution built on FreeBSD and pf, providing enterprise routing, VPN, and traffic filtering from a web interface.
phpIPAM: Open Source IP Address Management A web-based IPAM for tracking subnets, IP addresses, VLANs, and VRFs, with network scanning, a REST API, and PowerDNS integration. Replaces the spreadsheet of IP addresses. GPL-3.0.
RustDesk: Self-Hosted Remote Desktop An open-source remote desktop application and TeamViewer alternative that can run entirely on your own relay and ID servers, with clients for every major platform.
SearXNG: A Private Metasearch Engine You Run Yourself Aggregates results from many search engines without profiling you, tracking queries, or serving ads, and provides the search backend that several self-hosted AI tools depend on.
Secure ShellFish: SSH Terminal and File Access for iOS An iOS and macOS SSH client that also mounts remote servers in the Files app, bringing terminal access and file browsing to Apple devices.
Self-Hosted Gateway: What You Need to Know: Self-hosted Docker native tunneling to localhost Self-hosted Docker native tunneling to localhost.
ShellHub: Centralized SSH gateway that allows users to remotely access and manage their services from anywhere Centralized SSH gateway that allows users to remotely access and manage their services from anywhere.
Sshwifty: Web SSH & Telnet client Web SSH & Telnet client.
SWAG: NGINX webserver and reverse proxy with built-in Certbot and Fail2Ban NGINX webserver and reverse proxy with built-in Certbot and Fail2Ban.
Tailscale: Private WireGuard networks made easy Private WireGuard networks made easy.
Termius: Cross-Platform SSH Client A modern SSH client for desktop and mobile with synced hosts, saved snippets, and SFTP, used to reach servers you host yourself.
Traefik: Dynamic Reverse Proxy for Containers A cloud-native reverse proxy and load balancer that configures itself from Docker labels and other service registries, with automatic HTTPS.
Unbound: Validating, recursive, and caching DNS resolver Validating, recursive, and caching DNS resolver.
WatchYourLAN: Lightweight network IP scanner with web GUI Lightweight network IP scanner with web GUI.
WeTTY: Terminal access in browser over HTTP/HTTPS Terminal access in browser over HTTP/HTTPS.
wg-easy: WireGuard VPN With a Web Interface The simplest way to run WireGuard, combining the VPN server with a web UI for creating clients and displaying QR codes for mobile setup.
Zoraxy: A Reverse Proxy With a Web UI, Stream Proxying, and GeoIP Blocking A general-purpose reverse proxy written in Go with automatic ACME certificates, TCP and UDP stream proxying, GeoIP allow and block lists, uptime monitoring, a web SSH terminal, and plugins.
ZTNET: Self-hosted ZeroTier network controller Self-hosted ZeroTier network controller.
Browse other categories
Notes & Wikis (47) Media Servers (56) Reading & RSS (51) Music (32) Communication (54) Downloads (28) Monitoring (34) Productivity (45) Photos (21) Containers (36) File Sync (31) CMS & Websites (23) Recipes & Health (20) Home Automation (17) Development (30) Passwords (11) Auth & SSO (14) Analytics (12) Databases (16) Ad Blocking (10) Dashboards (14) Backup (10) Finance (16) Automation (8) Security (19) Games (9) AI & ML (28)