You can keep your current setup but make it more secure by using the VPS as a full proxy for your Homelab, so all traffic goes through the WireGuard tunnel and your home IP stays hidden. Instead of opening all TCP/UDP ports, only open the Minecraft port on the VPS and use a TCP proxy like HAProxy or Nginx to forward connections. To make the server easier to access, you can use your own domain and set up a SRV record in Cloudflare so players connect via the domain instead of the VPS IP, hiding the real server IP. Add firewall rules, rate limiting, and optionally Cloudflare Spectrum to protect the VPS from DDoS, or use a service like Playit.gg to handle tunneling and IP hiding automatically.
Loading community...

1 comment