Own Your Servers, Rent the Edge

Self-hosting Cloudflare nginx

Most small teams end up with the same setup: email at one provider, DNS at another, the website on a builder, monitoring on a SaaS dashboard. Each service is cheap and easy on its own. Together they leave your data, your configuration and your uptime with companies that can change prices, terms or features whenever they like.

The opposite extreme, doing everything yourself including DDoS protection and a global CDN, isn't realistic either. A single VPS can't absorb an attack or serve a static page from 300 cities.

The split that works: keep the state on servers you own, and rent the stateless edge. Your mail, your zones, your sites and your data live on your machine. Cloudflare sits in front of what benefits from a global network and costs nothing or very little to put there.

Why your own server

Your data stays yours. Mailboxes, DNS zones, access logs and databases sit on a disk you control. You know where they are, who can read them and how long they're kept. For a European business, knowing where personal data lives is also a GDPR requirement.

No lock-in, if you choose plain formats. An nginx config, a Maildir and a BIND zone file can be read on any Linux box. Moving to another provider means copying files, not exporting from a proprietary dashboard and hoping the import works.

Predictable cost. A 4 GB VPS costs the same whether you host one site or twenty, and whether you have five mailboxes or fifty. There's no per-seat pricing and no surprise "you've exceeded your plan".

You understand your stack. When something breaks, you can read the logs. The skills you build running your own server carry over to every job that touches Linux.

What it costs you

Self-hosting has a cost, and it should be named:

Most of these can be managed with good tools and a few habits. Some of them are exactly where the edge helps.

Where Cloudflare fits

Cloudflare's free and low-cost services cover the things a single server does badly. Each one solves a specific problem.

ServiceWhat it does for a self-hosted server
DNSFast authoritative DNS with a global anycast network
ProxyTLS at the edge, caching, WAF, DDoS absorption in front of your sites
TunnelPublishes sites with no open inbound ports, even from home or behind CGNAT
AccessA login page in front of admin panels, before traffic reaches your server
PagesHosting for static sites and landing pages, nothing to patch
WorkersSmall APIs and redirects that run at the edge
R2S3-compatible object storage with no egress fees, a good place for offsite backups

A sensible way to use them:

What must stay direct

Not everything can or should go through Cloudflare.

For DNS you can go one step further: run your own authoritative server as a hidden primary and let a secondary service answer the world. You edit the zone on your machine, the secondaries pull it with AXFR after each NOTIFY, and your server is never queried directly.

The detail everyone gets wrong: the real client IP

Put a proxy in front of nginx and every request appears to come from Cloudflare. Your access logs fill up with Cloudflare addresses, rate limits hit the edge instead of the client, and fail2ban starts banning Cloudflare, which takes your site offline for everyone.

nginx can restore the real address with the realip module, trusting the header only from Cloudflare's own ranges (published at cloudflare.com/ips-v4 and cloudflare.com/ips-v6):

# behind the Cloudflare proxy
set_real_ip_from 173.245.48.0/20;   # ...one line per published range
real_ip_header   CF-Connecting-IP;
# behind cloudflared on the same machine
set_real_ip_from 127.0.0.1;
set_real_ip_from ::1;
real_ip_header   CF-Connecting-IP;

Two mistakes to avoid:

The ranges change from time to time, so refresh them on a schedule rather than pasting them once.

A reference layout

The NetForge lab puts this together on one 4 GB VPS: static, PHP, reverse-proxied and load-balanced sites reached directly, through the proxy and through a tunnel; mail arriving directly on port 25; DNS served as a hidden primary with public secondaries; admin panels reachable only through the tunnel, and SSH kept direct as the emergency way in.

Checklist

Run it with NetForge

arx, missus and nomina are three panels for exactly this setup on a Debian VPS: web hosting with per-site edge trust (direct, Cloudflare proxy or tunnel), a mail server, and authoritative DNS with hidden-primary support. Their configuration lives in plain files on disk.

See the panels See the lab