−25%

on annual Windows plans, until 31 Oct. See plans

EQVPS

VPS for Home Assistant remote access

Reach Home Assistant from anywhere without opening ports at home: a small VPS runs WireGuard and HTTPS, your house dials out to it. Setup, cost, limits.

You want to open your Home Assistant dashboard from the train. Your router says no: the ISP puts you behind carrier-grade NAT, or port forwarding is technically possible but you'd rather not hang your whole home network off the internet to toggle a light. A small VPS solves both. Your house dials out to it over WireGuard, and the VPS is the only public face — with a real domain, a real certificate, and nothing at home listening to the world.

How the setup works

phone ──HTTPS──> VPS (Caddy :443) ──WireGuard──> Home Assistant :8123 at home
                       ▲
              home box dials out on UDP 51820

The VPS runs two things: a WireGuard server and Caddy as a reverse proxy. At home, a WireGuard client (on the Home Assistant host, a Raspberry Pi or your router) keeps a tunnel open. When you visit https://ha.example.com, Caddy passes the request through the tunnel to 10.8.0.2:8123.

What you need

1. WireGuard server on the VPS

apt update && apt install -y wireguard caddy
wg genkey | tee /etc/wireguard/server.key | wg pubkey > /etc/wireguard/server.pub
chmod 600 /etc/wireguard/server.key

cat > /etc/wireguard/wg0.conf <<EOF
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = $(cat /etc/wireguard/server.key)

[Peer]
# the home side
PublicKey = HOME_PUBLIC_KEY
AllowedIPs = 10.8.0.2/32
EOF

systemctl enable --now wg-quick@wg0
ufw allow 51820/udp && ufw allow 80,443/tcp

2. The home side

On any Linux box at home (or in a Home Assistant WireGuard client add-on), create the peer. The keepalive matters: it holds the tunnel open through your home router's NAT.

[Interface]
Address = 10.8.0.2/24
PrivateKey = HOME_PRIVATE_KEY

[Peer]
PublicKey = SERVER_PUBLIC_KEY
Endpoint = ha-vps.example.com:51820
AllowedIPs = 10.8.0.1/32
PersistentKeepalive = 25

If the WireGuard client runs on a different machine than Home Assistant, forward 10.8.0.2:8123 to the HA host on your LAN — or simpler, run the client on the HA host itself.

3. HTTPS with Caddy

cat > /etc/caddy/Caddyfile <<'EOF'
ha.example.com {
    reverse_proxy 10.8.0.2:8123
}
EOF
systemctl reload caddy

Caddy fetches the certificate automatically and handles the WebSocket connection the Home Assistant app relies on.

4. Tell Home Assistant to trust the proxy

Without this, HA rejects proxied requests. In configuration.yaml:

http:
  use_x_forwarded_for: true
  trusted_proxies:
    - 10.8.0.1

Restart Home Assistant, open https://ha.example.com, and set that URL as the external address in the mobile app.

The honest trade-offs

HTTPS ends on the VPS, so that server sees your dashboard traffic in the clear before it enters the tunnel. It's your server, which is the whole point — but treat it like part of your home network: SSH keys only, updates on, nothing else running on it. Keep Home Assistant's own password and two-factor login switched on; the proxy is not an authentication layer.

The paid official cloud service from the Home Assistant team does the same job with zero maintenance and funds the project. If you'd rather not run a server at all, that's a perfectly good answer. The VPS route wins when you're already self-hosting, want your own domain, or want to put other home services behind the same tunnel later.

Ready to deploy? Pay with crypto, no KYC — live in about a minute.

Deploy now →

FAQ

Why use a VPS instead of forwarding a port on my router?

Many home connections sit behind carrier-grade NAT, so there is no port to forward. Even when there is, exposing your home IP and router to the internet is a risk you don't need. With a VPS the house makes an outgoing WireGuard connection, and the only thing facing the internet is a small server you can rebuild in minutes.

Which plan do I need?

A Nano-IP ($8/mo) is plenty — it only forwards traffic and terminates HTTPS. You need a dedicated-IP plan because the VPS must accept inbound HTTPS and a WireGuard UDP port; NAT plans don't take inbound connections apart from your SSH port.

Does the VPS see my Home Assistant traffic?

HTTPS terminates on the VPS, so the server you control sees the decrypted requests before sending them down the tunnel. That's the same trust model as any reverse proxy — the difference is that it's your box. Keep Home Assistant's own login and two-factor authentication on regardless.

Will it add latency?

One extra hop. From a home in Europe to a VPS in Germany or Finland that's typically 10–40 ms round trip — unnoticeable for dashboards, switches and camera snapshots. Live video streams are the only thing where you might feel it.

What happens if the VPS goes down?

Remote access stops; your home automations keep running, because Home Assistant itself never depended on the VPS. Inside your house everything works as before on the local address.

Comments

No comments yet. Be the first.

Leave a comment

Comments are moderated before they appear.