Zero-trust in the home lab: ditch port forwarding forever
The oldest way to reach your home lab from outside is to forward a port, and it is also the one that exposes your home network to constant internet scanning. This explains why to stop, and the zero-trust tools that replace it.
A common early step in self-hosting is to forward port 443 to your server and watch the app load from your phone on mobile data. The problem is that this does the thing most security guidance warns against: it opens an inbound entrance in your home firewall, and automated scanners will find it quickly. There is a better approach, and it is the same one companies adopted over the last decade: zero trust.
01Why port forwarding is a real risk
A forwarded port is a permanent, publicly reachable entrance into your home network. The internet is scanned continuously — services like Shodan catalogue exposed devices around the clock — so an open port is not hidden until someone finds it; it is found quickly and probed repeatedly. Every service you expose this way is only as safe as its worst unpatched vulnerability and weakest password, and a single compromised app can become a foothold into the rest of your network, including the laptops and phones on it. This is the normal outcome of leaving ports open on the public internet, not a rare one.
02What zero trust means
Zero trust is not a product; it is a security model, defined by NIST in Special Publication 800-207. The core idea is that no user or device is trusted simply for being on a particular network: every access request is authenticated and authorised on its own, and trust is not granted just because a request came from inside.1 For a home lab, the practical version is straightforward: instead of exposing a service to the network and hoping the network is safe, you make every connection prove who it is first. That shift is what lets you close every inbound port and still reach everything.
03Reverse proxy plus Cloudflare Tunnel
The first replacement for port forwarding is an outbound-only tunnel. Cloudflare Tunnel runs a small daemon (cloudflared) inside your network that makes an outbound connection to Cloudflare; inbound traffic then reaches your services through that connection, so you never open an inbound port on your router.2 Your firewall stays closed to the internet, your home IP address is hidden behind Cloudflare, and you can add Cloudflare Access policies to require a login before anyone reaches the app. Pair the tunnel with a local reverse proxy (Traefik, Caddy, or Nginx Proxy Manager) and each service gets a clean HTTPS hostname with no port number.
# The key idea: the connection goes out, not in.
cloudflared tunnel run my-homelab
# cloudflared dials Cloudflare from inside your network.
# Your router's inbound ports stay closed. Nothing is forwarded.04ZTNA with Tailscale and Twingate
The second replacement is a zero-trust network access overlay: a private mesh that only your authenticated devices can join. Tailscale builds a mesh VPN between your devices on top of the WireGuard protocol,5 where each device authenticates through your identity provider and they connect directly and encrypted, with no public ports and no central VPN box to expose.3 Twingate offers a similar model built around least-privilege, per-resource access.4 The model is different from a traditional VPN: rather than letting a device onto the network, you grant a specific authenticated device access to specific resources, which is what NIST 800-207 describes.1
Port forwarding trusts the whole internet to behave and your weakest service to hold. Zero trust asks every connection to prove itself and trusts nothing by default.
05Reaching your apps from your phone
The result is that remote access gets easier, not harder. With Tailscale on your phone, your self-hosted apps are reachable over the encrypted mesh from anywhere, as if you were at home, with no port forwarding and nothing exposed for a scanner to find.3 With a Cloudflare Tunnel plus Access, you open the app's hostname in a browser and authenticate at Cloudflare's edge before the request reaches your network.2 In both cases the internet sees nothing pointing at your house, and you can still reach your dashboards from anywhere. That is what zero trust looks like in practice: less exposure and more convenience at once.
06Where OcxlyDev lands
We do not forward ports, and we do not recommend it. The zero-trust tools are free or inexpensive, take an evening to set up, and remove an entire category of risk — the standing, public, inbound entrance — from your home network. Start with Tailscale for your own device access, since it is the quickest win, and add a Cloudflare Tunnel when you need to share a service with someone who is not on your mesh. Close every inbound port, make every connection authenticate, and treat your home network the way a company treats its own: nothing is trusted just for showing up.1