Nupplo starts out reachable only on your own network. If you want to check at the flea market whether you already have a figure, you need a way in from outside. Two of them lead there safely – and one is worth not taking in the first place.
No port forwarding on the router. It is the obvious route and the worst one: it puts your server in front of the entire internet, and every flaw in any layer underneath is reachable from anywhere. The two routes here manage without a single opening inwards.
A second small container runs next to Nupplo and builds a connection from the inside out to Cloudflare. Everything on the router stays shut. Three reasons why this is the recommended route:
What you need for it: a free Cloudflare account and a domain managed by Cloudflare. Either you register a cheap one there, or you move an existing one over. Without a domain of your own this route is closed – then the VPN remains.
In the Cloudflare Zero Trust dashboard under Networks → Tunnels, create a tunnel. Cloudflare shows you a token while you do – copy that.
On the same tunnel, enter a public hostname, for example
nupplo.your-domain.com. As the service it takes:
http://nupplo:8300
That is the container name from your
docker-compose.yml and the port Nupplo listens on –
not the address of your NAS.
In Nupplo under More → External access, enter
the address and the token. The app turns them into the finished
docker-compose block for you to copy.
The token stays in your browser. The app does not store it and does not send it anywhere – it could not start the tunnel itself either, because it has no access to Docker. All it does is write the configuration out for you.
Put the block next to the nupplo service in your
docker-compose.yml:
cloudflared:
image: cloudflare/cloudflared:latest
container_name: nupplo-tunnel
restart: unless-stopped
command: tunnel run
environment:
TUNNEL_TOKEN: "your-token"
Both containers are then on the same
Compose network – which is why cloudflared reaches the app
at http://nupplo:8300. Then
docker compose up -d.
Nupplo is now reachable at
https://nupplo.your-domain.com – from anywhere,
encrypted, without anything standing open on the router.
One more lock, if you like: in the Zero Trust dashboard you can put an access policy in front. Cloudflare then asks for a sign-in before anyone even gets to see the Nupplo login page.
If you already use WireGuard,
Tailscale or your router’s VPN function, there is nothing
further to do: inside the VPN the NAS is reachable exactly as it is at
home, so under the same address http://<NAS-IP>:8300.
There is nothing to set up that is not running anyway.
The difference from the tunnel: you have to switch the VPN on on every device before you use it. In exchange, not a single packet leaves your network through somebody else’s service.
Recording things works without access from outside too: whatever you find at the flea market, you add at home. And if all you want to do while you are out is look something up – whether a figure is already there – take the collection with you, as a CSV on your phone or as a printed list in your pocket. Nupplo produces both for you under More.
This is not a fallback but, for many people, the right answer: a way in from outside is a door that has to be maintained. If you do not need one, you are better off not building it.