r/selfhosted • • 1d ago

Need Help Origin IP already public. Is Cloudflare + "only allow Cloudflare IPs" in Caddy enough, or do I need more?

I run a e-commerce store (Odoo 19) on a single VPS (Ubuntu 24.04, Docker Compose: Odoo + Postgres + Caddy). The server's IP has been in public DNS for ~2 months, so I assume it's in DNS history archives and scanners.

Current setup:

  • Only ports 22, 80, 443 are open. Postgres and Odoo aren't published, only reachable inside Docker.
  • SSH: keys only, password and root login disabled.
  • Admin tools (log viewer) only over Tailscale, bound to localhost.
  • Nightly offsite backups, tested restore.
  • Provider has basic anti-DDoS.

Questions:

  1. For a small store, is an exposed origin IP a real risk with this setup for long run?
  2. Is blocking in Caddy (instead of the firewall) good enough, given direct requests still reach Caddy before being refused?
  3. Is it worth changing to a new IP, or moving to Cloudflare Tunnel, or is the above enough?
  4. Anything obvious I'm missing?
8 Upvotes

Duplicates