Homelab behind DS-Lite
Reaching a TrueNAS homelab from outside without a public IPv4 address: split-horizon DNS, real certificates for internal services, and WireGuard over IPv6.
-
Part 1
Split-horizon DNS and a wildcard cert - real TLS for internal-only homelab services
How TrueNAS, Pi-hole and Nginx Proxy Manager work together with Cloudflare DNS to give internal-only admin panels a valid certificate without exposing them publicly.
-
Part 2
WireGuard behind DS-Lite - wg-easy on TrueNAS, reachable over IPv6
How I run WireGuard on my TrueNAS with wg-easy behind a DS-Lite connection: an IPv6-only endpoint on my own domain, a split tunnel with Pi-hole as DNS, and finding the right MTU.