The Concept

Home / Homelab (CGNAT)

No inbound ports. Everything starts outbound.

Services Jellyfin · NAS · VMs CGNAT Constraints Why inbound traffic can’t reach home

Home → Tunnel → VPS

WireGuard Tunnel Encrypted link across CGNAT

Public Access ⇄ Encrypted Tunnel

Idea: The homelab stays behind CGNAT. The VPS is the public entry point. WireGuard connects both securely.