You want to open your Home Assistant dashboard from the train. Your router says no: the ISP puts you behind carrier-grade NAT, or port forwarding is technically possible but you'd rather not hang your whole home network off the internet to toggle a light. A small VPS solves both. Your house dials out to it over WireGuard, and the VPS is the only public face — with a real domain, a real certificate, and nothing at home listening to the world.
How the setup works
phone ──HTTPS──> VPS (Caddy :443) ──WireGuard──> Home Assistant :8123 at home
▲
home box dials out on UDP 51820
The VPS runs two things: a WireGuard server and Caddy as a reverse proxy. At home, a WireGuard client (on the Home Assistant host, a Raspberry Pi or your router) keeps a tunnel open. When you visit https://ha.example.com, Caddy passes the request through the tunnel to 10.8.0.2:8123.
What you need
- A dedicated-IP plan. The VPS must accept inbound 443 and UDP 51820. Nano-IP at $8/month is more than enough — it moves a few kilobytes of dashboard traffic and never breaks a sweat. NAT plans don't accept inbound connections apart from your personal SSH port (how NAT works here).
- A domain pointing an A record at the VPS IP.
- A WireGuard client at home that can reach Home Assistant on the LAN.
1. WireGuard server on the VPS
apt update && apt install -y wireguard caddy
wg genkey | tee /etc/wireguard/server.key | wg pubkey > /etc/wireguard/server.pub
chmod 600 /etc/wireguard/server.key
cat > /etc/wireguard/wg0.conf <<EOF
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = $(cat /etc/wireguard/server.key)
[Peer]
# the home side
PublicKey = HOME_PUBLIC_KEY
AllowedIPs = 10.8.0.2/32
EOF
systemctl enable --now wg-quick@wg0
ufw allow 51820/udp && ufw allow 80,443/tcp
2. The home side
On any Linux box at home (or in a Home Assistant WireGuard client add-on), create the peer. The keepalive matters: it holds the tunnel open through your home router's NAT.
[Interface]
Address = 10.8.0.2/24
PrivateKey = HOME_PRIVATE_KEY
[Peer]
PublicKey = SERVER_PUBLIC_KEY
Endpoint = ha-vps.example.com:51820
AllowedIPs = 10.8.0.1/32
PersistentKeepalive = 25
If the WireGuard client runs on a different machine than Home Assistant, forward 10.8.0.2:8123 to the HA host on your LAN — or simpler, run the client on the HA host itself.
3. HTTPS with Caddy
cat > /etc/caddy/Caddyfile <<'EOF'
ha.example.com {
reverse_proxy 10.8.0.2:8123
}
EOF
systemctl reload caddy
Caddy fetches the certificate automatically and handles the WebSocket connection the Home Assistant app relies on.
4. Tell Home Assistant to trust the proxy
Without this, HA rejects proxied requests. In configuration.yaml:
http:
use_x_forwarded_for: true
trusted_proxies:
- 10.8.0.1
Restart Home Assistant, open https://ha.example.com, and set that URL as the external address in the mobile app.
The honest trade-offs
HTTPS ends on the VPS, so that server sees your dashboard traffic in the clear before it enters the tunnel. It's your server, which is the whole point — but treat it like part of your home network: SSH keys only, updates on, nothing else running on it. Keep Home Assistant's own password and two-factor login switched on; the proxy is not an authentication layer.
The paid official cloud service from the Home Assistant team does the same job with zero maintenance and funds the project. If you'd rather not run a server at all, that's a perfectly good answer. The VPS route wins when you're already self-hosting, want your own domain, or want to put other home services behind the same tunnel later.
Related guides
- Set up WireGuard VPN on a VPS — the full WireGuard walkthrough
- Nginx reverse proxy with HTTPS — if you prefer Nginx to Caddy
- Securing a new VPS — do this first on any box that faces the internet
Comments
No comments yet. Be the first.