<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/lmuulnp4b" -->

---
title: You Were Right: Here&#x27;s the Better Way to Do Homelab HTTPS
description: A follow-up homelab tutorial showing how to set up HTTPS for local services using a purchased domain, Nginx Proxy Manager, and a DNS challenge with Let&#x27;s...
canonical: https://daily.dev/posts/lmuulnp4b
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: You Were Right: Here&#x27;s the Better Way to Do Homelab HTTPS | daily.dev
og:description: A follow-up homelab tutorial showing how to set up HTTPS for local services using a purchased domain, Nginx Proxy Manager, and a DNS challenge with Let&#x27;s...
og:url: https://daily.dev/posts/lmuulnp4b
og:image: https://api.daily.dev/og/posts/lMuULnp4B.png
og:image:alt: Post cover image
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# You Were Right: Here's the Better Way to Do Homelab HTTPS

**[NetDevOps](https://daily.dev/sources/netdevops)** · [@cjbaccus](https://daily.dev/cjbaccus) · 0 upvotes · 0 comments

## Summary

A follow-up homelab tutorial showing how to set up HTTPS for local services using a purchased domain, Nginx Proxy Manager, and a DNS challenge with Let's Encrypt via Cloudflare. The method uses a wildcard DNS record pointing to the local reverse proxy IP, a Cloudflare API token scoped to zone DNS editing, and automatic certificate renewal built into Nginx Proxy Manager. The result is valid SSL certificates for internal services accessible only on the local network, with no exposure to the public internet.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.youtube.com/watch?v=XEltHEZU6aE>

## Similar posts on daily.dev

- [TLS certificates for internal services done right](https://daily.dev/posts/tls-certificates-for-internal-services-done-right-yyfpvyhee) · Hacker News · 0 upvotes · 0 comments
- [The one Docker container that stopped me from exposing every service](https://daily.dev/posts/the-one-docker-container-that-stopped-me-from-exposing-every-service-i8van1j4d) · XDA Developers · 0 upvotes · 0 comments
- [I built a single dashboard for every service in my house, and now nobody needs to know what an IP address is](https://daily.dev/posts/i-built-a-single-dashboard-for-every-service-in-my-house-and-now-nobody-needs-to-know-what-an-ip-ad-of2atcnnd) · XDA Developers · 0 upvotes · 0 comments
- [Self-Hosting Behind CGNAT](https://daily.dev/posts/self-hosting-behind-cgnat-lrdls1bcr) · Lobsters · 1 upvotes · 0 comments

---

Tags: [#cloudflare](https://daily.dev/tags/cloudflare), [#self-hosting](https://daily.dev/tags/self-hosting), [#dns](https://daily.dev/tags/dns)

[View this post on daily.dev](https://daily.dev/posts/lmuulnp4b)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"DiscussionForumPosting","mainEntityOfPage":"https://daily.dev/posts/lmuulnp4b","headline":"You Were Right: Here's the Better Way to Do Homelab HTTPS","text":"Shared: You Were Right: Here's the Better Way to Do Homelab HTTPS","url":"https://daily.dev/posts/lmuulnp4b","datePublished":"2026-07-19T14:50:27.572Z","dateModified":"2026-09-14T06:49:50.262Z","author":{"@type":"Person","name":"Carl Baccus","url":"https://daily.dev/cjbaccus","image":"https://avatars.githubusercontent.com/u/1283307?v=4","description":"DevSecOps Engineer specializing in NetDevOps.","interactionStatistic":{"@type":"InteractionCounter","interactionType":{"@type":"EndorseAction"},"userInteractionCount":3160}},"image":"https://media.daily.dev/image/upload/s--foaA6JGU--/f_auto/v1722860399/public/Placeholder%2004","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"sharedContent":{"@type":"WebPage","url":"https://api.daily.dev/r/QocbRqYmh"},"isPartOf":{"@type":"WebPage","url":"https://daily.dev/squads/netdevops","name":"NetDevOps"}}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"NetDevOps","item":"https://daily.dev/squads/netdevops"},{"@type":"ListItem","position":3,"name":"You Were Right: Here's the Better Way to Do Homelab HTTPS"}]}
```

