DEEN

Reaching it from outside

Nupplo starts out reachable only on your own network. If you want to check at the flea market whether you already have a figure, you need a way in from outside. Two of them lead there safely – and one is worth not taking in the first place.

No port forwarding on the router. It is the obvious route and the worst one: it puts your server in front of the entire internet, and every flaw in any layer underneath is reachable from anywhere. The two routes here manage without a single opening inwards.

Cloudflare Tunnel

A second small container runs next to Nupplo and builds a connection from the inside out to Cloudflare. Everything on the router stays shut. Three reasons why this is the recommended route:

What you need for it: a free Cloudflare account and a domain managed by Cloudflare. Either you register a cheap one there, or you move an existing one over. Without a domain of your own this route is closed – then the VPN remains.

1

Create a tunnel and copy the token

In the Cloudflare Zero Trust dashboard under Networks → Tunnels, create a tunnel. Cloudflare shows you a token while you do – copy that.

2

Set the address

On the same tunnel, enter a public hostname, for example nupplo.your-domain.com. As the service it takes:

http://nupplo:8300

That is the container name from your docker-compose.yml and the port Nupplo listens on – not the address of your NAS.

3

Let the app build the block

In Nupplo under More → External access, enter the address and the token. The app turns them into the finished docker-compose block for you to copy.

The token stays in your browser. The app does not store it and does not send it anywhere – it could not start the tunnel itself either, because it has no access to Docker. All it does is write the configuration out for you.

4

Add the container

Put the block next to the nupplo service in your docker-compose.yml:

  cloudflared:
    image: cloudflare/cloudflared:latest
    container_name: nupplo-tunnel
    restart: unless-stopped
    command: tunnel run
    environment:
      TUNNEL_TOKEN: "your-token"

Both containers are then on the same Compose network – which is why cloudflared reaches the app at http://nupplo:8300. Then docker compose up -d.

Done

Nupplo is now reachable at https://nupplo.your-domain.com – from anywhere, encrypted, without anything standing open on the router.

One more lock, if you like: in the Zero Trust dashboard you can put an access policy in front. Cloudflare then asks for a sign-in before anyone even gets to see the Nupplo login page.

A VPN into your own network

If you already use WireGuard, Tailscale or your router’s VPN function, there is nothing further to do: inside the VPN the NAS is reachable exactly as it is at home, so under the same address http://<NAS-IP>:8300. There is nothing to set up that is not running anyway.

The difference from the tunnel: you have to switch the VPN on on every device before you use it. In exchange, not a single packet leaves your network through somebody else’s service.

Not at all – and that is often enough

Recording things works without access from outside too: whatever you find at the flea market, you add at home. And if all you want to do while you are out is look something up – whether a figure is already there – take the collection with you, as a CSV on your phone or as a printed list in your pocket. Nupplo produces both for you under More.

This is not a fallback but, for many people, the right answer: a way in from outside is a door that has to be maintained. If you do not need one, you are better off not building it.

To the installation guide Manual