this post was submitted on 15 Apr 2025
22 points (92.3% liked)

Selfhosted

46118 readers
629 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I have a domain that requires HSTS preload. I want to self host a few things using that domain (and subdomains), like nextcloud, pihole, and vaultwarden. How much of an issue is HSTS preload going to be if I do that? Will I need to set up a wildcard cert for everything? Or will it just work™️ because it's internal or traffic is through a VPN?

I can't find much about this so any help would be appreciated!

you are viewing a single comment's thread
view the rest of the comments
[–] wraith@lemmy.ca 2 points 6 days ago* (last edited 6 days ago) (1 children)

Google is the registry that owns the rights to the TLD. They require all of the domains they control to have HSTS preload enabled.

[–] wildbus8979@sh.itjust.works 3 points 6 days ago* (last edited 6 days ago) (1 children)

Then yeah, VPN or not, you're going to need to enable TLS. What's the issue with giving your subdomains a certificate?

[–] wraith@lemmy.ca 1 points 6 days ago (1 children)

I am fairly new to self hosting and just wanted to know if this was a big enough deal that I should just get a domain that doesn't require HSTS preload. It's one thing to tinker with an IP address on a local network for some unimportant project; it's just intimidating to try it for real using a domain and hosting my own data.

I'm just a little nervous tbh. Thanks for the help!

[–] wildbus8979@sh.itjust.works 2 points 6 days ago

Not much to be nervous about, you can't fuck it up anymore than it already is since the HSTS is preloaded ;) ACME/Let'sEncrypt is pretty easy to setup