Running apps like Jellyfin or Bookstack on your home server? Don’t expose them directly, protect them with a secure Nginx reverse proxy. In this video, I’ll show you step-by-step how to set up Nginx on Ubuntu Server 24.04, configure multiple domains, enable free HTTPS with Let’s Encrypt, and even add Cloudflare Tunnel for extra protection. By the end, you’ll have a production-ready setup you can trust for your homelab or self-hosted services. https://wiki.kitpro.us/en/articles/nginx-reverse-proxy Rocky Linux Supported by CIQ: https://ciq.com/products/rocky-linux/ CompTIA Linux+ Certifcation Course https://youtu.be/qNxuTRCRjoQ Remember to Like, Share, and Subscribe if you enjoyed the video! Also, if you are interested in more Linux content, please consider becoming a channel member so I can continue to produce great content! ✔️RECOMMENDED LINUX BOOKLIST ------------------------------- Linux Pocket Guide: Essential Commands: https://amzn.to/3xGPvsK CompTIA Linux+ Certification All-in-One Exam Guide: Exam XK0-004 https://amzn.to/3uQ3wmh 101 Labs - CompTIA Linux+ https://amzn.to/3vtj7rb How Linux Works: What Every Superuser Should Know https://amzn.to/3vrLkOO Linux Bible https://amzn.to/3rwEkPH ✔️SOCIAL NETWORKS ------------------------------- KeepItTechie: https://keepittechie.com/ Facebook: https://www.facebook.com/KeepItTechie Twitter: https://twitter.com/keepittechie Instagram: https://www.instagram.com/keepittechie/ Discord: https://discord.gg/RjZWuyd -------------------------------- ✔️RECORDING EQUIPMENT ------------------------------- Insta360 4K Webcam - https://amzn.to/3RddfgZ Rode Procaster Microphone - https://amzn.to/42RSInF RØDE RØDECaster Duo - https://amzn.to/4ct1T1X Cloudlifter CL-1 Mic Activator - https://amzn.to/4ic7BXv Logitech LED Streaming Light - https://amzn.to/4j7Z8FT -------------------------------- #Linux #SelfHosting #Nginx #Cloudflare #homelab 0:00 Intro – What we’re building & why it matters 0:45 Like the video! Quick support shoutout 0:58 Setup overview – Nginx reverse proxy + Jellyfin demo + Cloudflare tunnel plan 1:53 Step 1 – Install Nginx and Certbot 3:00 Verify Nginx is running 3:18 Check server IP and test in browser 3:42 Firewall setup with UFW (open 80/443/22) 6:29 Sponsor break – Rocky Linux mention 7:14 Install Certbot + Nginx plugin 8:31 Test Nginx config 9:16 Create Nginx snippets for security headers, proxy tuning, and rate limiting 13:50 Back up and modify nginx.conf (global config includes, websocket map) 15:12 Reload Nginx and confirm no errors 15:45 Step 2 – Create Jellyfin reverse proxy config 16:22 Confirm backend IP/port (10.0.0.112:8096) 17:14 Create site config in sites-available/jelly.conf 18:50 Enable site with symlink to sites-enabled 19:16 Prepare ACME challenge directory (/var/www/letsencrypt) 20:31 Step 3 – Install Cloudflared and set up tunnel 22:13 Cloudflared install fix (permissions & temp dir move) 23:52 Login to Cloudflare account from terminal 25:22 Create Cloudflare tunnel and JSON credentials 26:20 Create /etc/cloudflared config.yaml for tunnel 27:22 Edit config with credentials file, hostname, and Jellyfin backend 28:20 Cloudflare dashboard check – verify tunnel 29:20 Add CNAME DNS record for jelly.keepittechie.com 30:23 Route DNS through tunnel 33:04 Enable and start cloudflared systemd service 33:47 Step 4 – Test Jellyfin domain with HTTPS 34:22 First Certbot attempt fails (proxy/SSL mismatch) 35:01 Fix jelly.conf by removing SSL block 36:02 Another Certbot attempt – fails on HTTP-01 37:24 Switch to DNS-01 with Cloudflare plugin 38:12 Install python3-certbot-dns-cloudflare plugin 38:48 Create Cloudflare API credentials file (/root/secrets/cloudflare.ini) 39:18 Secure credentials with chmod 600 39:37 Run Certbot again with DNS plugin – success! Certs issued 40:42 Copy cert/key paths for nginx config 41:12 Update jelly.conf with SSL block and cert paths 42:27 Test and reload Nginx (fix “map directive” error by moving map to global config) 43:01 Step 5 – Final success test 43:13 Visit https://jelly.keepittechie.com – valid SSL cert works! 43:59 Step 6 – Auto-renewal setup 44:17 Check certbot systemd timer 44:40 Run dry-run renewal test 45:42 Troubleshooting logs & multiple vhost notes 46:00 Recap – What we set up (advanced Nginx reverse proxy with SSL, Cloudflare tunnel, Jellyfin backend) 47:38 ISP rant – why port 80/443 blocking is outdated 47:46 Plan to split into two videos (Nginx vs Cloudflare tunnel) 47:52 Outro – Like, subscribe, KeepItTechie sign-off

This 252W USB Charger Replaced Half My Desk Setup
244 views

Local AI on Linux: Run Your Own AI Without Big Tech
2.5K views

Your Home Server Is Probably a Security Risk
1.2K views

Stop Paying for Cloud Storage: Build Your Own Private Cloud
1.2K views

Your Ubuntu Server Needs a Static IP Address
445 views

AI Knows Exactly What You Want To Hear
783 views