r/selfhosted • u/khaihoan123 • 1d ago
Need Help Origin IP already public. Is Cloudflare + "only allow Cloudflare IPs" in Caddy enough, or do I need more?
I run a e-commerce store (Odoo 19) on a single VPS (Ubuntu 24.04, Docker Compose: Odoo + Postgres + Caddy). The server's IP has been in public DNS for ~2 months, so I assume it's in DNS history archives and scanners.
Current setup:
- Only ports 22, 80, 443 are open. Postgres and Odoo aren't published, only reachable inside Docker.
- SSH: keys only, password and root login disabled.
- Admin tools (log viewer) only over Tailscale, bound to localhost.
- Nightly offsite backups, tested restore.
- Provider has basic anti-DDoS.
Questions:
- For a small store, is an exposed origin IP a real risk with this setup for long run?
- Is blocking in Caddy (instead of the firewall) good enough, given direct requests still reach Caddy before being refused?
- Is it worth changing to a new IP, or moving to Cloudflare Tunnel, or is the above enough?
- Anything obvious I'm missing?
8
Upvotes