Back to articles
Technology Insight

Building an Automated Dynamic DNS & Reverse Proxy System for Homelabs via an Intermediate VPS

May 25, 2026

Introduction to Advanced Homelab Networking

For homelab enthusiasts and remote developers, hosting services from a home network offers unparalleled control and cost efficiency. However, two persistent challenges often hinder this experience: carrier-grade NAT (CGNAT) and dynamic public IP addresses. Most residential internet service providers (ISPs) do not provide a stable, static IP, and opening ports on a home router introduces severe security vulnerabilities.

To bypass these limitations professionally, architectural design must shift from direct port forwarding to an enterprise-grade tunneling topology. This blog post provides a comprehensive blueprint for deploying an automated Dynamic DNS (DDNS) and Reverse Proxy system utilizing an intermediate Virtual Private Server (VPS) acting as a secure public gateway.

The Architectural Blueprint

Before diving into the configuration, it is essential to understand the structural flow of network traffic in this architecture. Instead of exposing your home network directly to the public internet, we establish a secure, encrypted tunnel from the Homelab to a cloud-hosted VPS.

The traffic flow operates as follows:

  1. The Client: A user accesses your service via a custom domain name (e.g., app.yourdomain.com).
  2. DNS Resolution: Cloudflare or another DNS provider resolves the domain to the public IP of your cloud VPS.
  3. The Public Gateway (VPS): The VPS receives the HTTPS request. It hosts a reverse proxy (such as Nginx Proxy Manager) that handles SSL termination.
  4. The Secure Tunnel: The reverse proxy forwards the traffic through an encrypted WireGuard or Frp tunnel directly to the internal IP of your Homelab.
  5. The Destination: The target local service answers the request safely behind your home firewall.
Security Note: By implementing this topology, your home public IP address remains completely hidden from the internet, mitigating the risk of Distributed Denial of Service (DDoS) attacks.

Prerequisites and Infrastructure Setup

To follow this guide, ensure you have prepared the following infrastructure components:

  • A low-cost cloud VPS running a stable Linux distribution (Ubuntu 22.04 LTS or newer recommended) with a static public IP.
  • A registered domain name managed via Cloudflare for automated API integration.
  • A local machine or server inside your home network acting as the Homelab gateway.
  • Docker and Docker Compose installed on both the VPS and the Homelab server.

Step 1: Establishing the Secure Tunnel (WireGuard)

We will use WireGuard for its high performance and minimal overhead to link the VPS and the Homelab. Alternatively, you can use Frp (Fast Reverse Proxy) if you prefer application-level tunneling without virtual network interfaces.

VPS WireGuard Configuration

Create a Docker Compose configuration on the VPS to run the WireGuard server:

version: '3.8'
services:
  wireguard:
    image: lscr.io/linuxserver/wireguard:latest
    container_name: wireguard
    cap_add:
      - NET_ADMIN
      - SYS_MODULE
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=Etc/UTC
      - SERVERURL=YOUR_VPS_PUBLIC_IP
      - SERVERPORT=51820
      - PEERS=homelab_gateway
      - PEERDNS=auto
      - ALLOWEDIPS=0.0.0.0/0
    ports:
      - 51820:51820/udp
    volumes:
      - ./config:/config
      - /lib/modules:/lib/modules
    restart: always

Deploy the container and extract the client configuration file generated inside the ./config/peer_homelab_gateway/ directory. This file is required to connect your Homelab server.

Step 2: Deploying the Reverse Proxy on the VPS

Once the secure tunnel interface is established, we need a mechanism to route incoming HTTP/HTTPS traffic down the tunnel. Nginx Proxy Manager (NPM) offers a clean, web-based UI to manage these configurations seamlessly.

Create a separate docker-compose.yml file on the VPS for Nginx Proxy Manager:

version: '3.8'
services:
  app:
    image: 'jc21/nginx-proxy-manager:latest'
    restart: unless-stopped
    ports:
      - '80:80'
      - '81:81'
      - '443:443'
    volumes:
      - ./data:/data
      - ./letsencrypt:/etc/letsencrypt

After launching NPM, access the administration dashboard via port 81. You can now configure proxy hosts pointing to the internal WireGuard IP of your Homelab client.

Step 3: Automating Dynamic DNS via Cloudflare API

Although the VPS handles incoming traffic via its static IP, automating the DNS management of your subdomains keeps your network dynamic and adaptable. We use an automated DDNS script or a dedicated container like oznu/cloudflare-ddns to ensure your domain records always point correctly to your public cloud infrastructure.

If you choose to direct-connect specific secondary backends, deploy the container using the following configuration environment variables:

  • SUBDOMAIN: Set to your desired subdomain routing prefix.
  • API_KEY: Generated from your Cloudflare profile with Zone.DNS edit permissions.
  • PROXIED: Set to true to utilize Cloudflare's CDN protection layers.

Step 4: Configuring Homelab Routing and Target Validation

With the tunnel alive and the reverse proxy waiting for requests, configure the client side inside your Homelab. Ensure the WireGuard client container maps your local services appropriately. When adding a Proxy Host inside Nginx Proxy Manager on the VPS, use the WireGuard internal IP assigned to the Homelab peer (typically 10.13.13.2 or similar) as the Forward Host.

For example, to expose a local service running on port 8080:

  • Domain Names: dashboard.yourdomain.com
  • Scheme: http
  • Forward Hostname/IP: 10.13.13.2 (The Homelab's tunnel IP)
  • Forward Port: 8080
  • Block Common Exploits: Enabled
  • SSL: Request a new Let's Encrypt certificate with HTTP Challenge verification.

Best Practices for Security and Optimization

To ensure this infrastructure remains resilient and safe against unauthorized entry, implement the following security layers:

1. Firewall Hardening

On your VPS, use ufw or cloud security groups to restrict port entry. Only ports 80, 443, and 51820/UDP should be accessible globally. Keep port 81 (NPM admin panel) bound strictly to localhost or accessible exclusively via a secure management VPN.

2. Implement Access Control Lists (ACLs)

Nginx Proxy Manager allows administrators to define explicit Access Lists. For sensitive applications like local database managers, home security cameras, or storage dashboards, enforce HTTP Basic Authentication or restrict access entirely to trusted public IP ranges.

3. Automated SSL Renewal Lifecycle

Ensure that your reverse proxy configuration includes script automated cron jobs to check for Let’s Encrypt validation timeouts, preventing service disruptions due to expired security certificates.

Conclusion

By leveraging an intermediate cloud VPS alongside WireGuard and Nginx Proxy Manager, you build a resilient enterprise-ready bridge into your home network. This configuration completely eliminates the constraints of CGNAT and unstable home IPs while optimizing your perimeter defense. Your local Homelab remains invisible to public network scanners, yet accessible to you globally, securely, and seamlessly.

Building an Automated Dynamic DNS & Reverse Proxy System for Homelabs via an Intermediate VPS | DPTCloud