For context: I have 0 programming, coding, etc. related knowledge.
For some months I’ve been dedicating time into setting up a Homelab that hosts music, movies, maybe home security (Frigate, I suppose), minecraft servers (or maybe other games too) and maaaaybe local AIs (if I get a better system), in that order, from more to less important. Some of the caractheristics that I prioritize are: privacy first, Zero third-party exposure, disk data encryption, self-hosting, FOSS priority perspective, trying not to compromise in any way my home network-using devices through all the process. Since, as I said, I have 0 programing or even Linux experience, I’ve done all this process guided by a local ran AI (Qwen 3.6), YouTube videos and forums (not the perfect formula for a cybersecurity safe environment, I know).
In an old laptop (Acer Aspire ES15-… with AMD A6-6310 / 16GB RAM) I’ve installed Linux Debian Trixie 13 (GNOME) with Docker and CasaOS with Jellyfin (for movies, it worked), Navidrome (for music, also worked) and recently Netbird, this one to connect into the local network from outside my home net, which kinda worked, but not as I expected it to work.
And this is where I feel I’m stuck. My main absolute priority the whole time setting this all up was being able to stream music from my homelab in my phone from everywhere in the world as long as I had internet connection, but when I managed to achieve that connection after soooo many hours and even stream music from my phone only with mobile data, it needed like 1 minute to load 3 seconds of a song, so it’s not enough at all. After seeing this, I’ve reseted all netbird data so I can do a clean install.
I need help with the process of setting this (I believe it’s a VPN) up in a way that it is Self-hosted, secure and fast enough so I can make it all achieve my expectations. Any video, forum thread or personal recomendation that you can give me will be so much appreciated.
Summarizing it a little, this is what I was trying to achieve:
CasaOS Architecture: Netbird (FOSS WireGuard mesh) + (maybe) Caddy Reverse Proxy + (maybe) Internal PKI + (maybe) LUKS Encryption Security Model: Zero port forwarding, outbound-only private tunnels, device-by-device approval, end-to-end HTTPS, full data-at-rest encryption.
Let me know if I’m missing any important information and I will do my best to share it.
Thank you so so much in advance!!


Sounds ambitious! Good for you for diving right in.
I’m no expert but I would look at your home internet speeds/capabilities. Most home packages are optimized for download, and if you are self-hosting a streaming server you may a differently provisioned service to support that. If the download to upload ratio is heavily tilted towards download then I would look there first. It sounds like you are able to stream outside your home network, just slowly.
Everything else is waaay beyond me in terms of establishing a secure perimeter and allowing in only desired traffic. I self host a few servers on proxmox, but it’s strictly limited to my home network.
Maybe I’ve been to fast deleting the NetBird data hahahah. I just tried doing a “speedtest-cli --simple” and I got: “Ping: 152.186 ms Download: 9.35 Mbit/s Upload: 18.69 Mbit/s”
I’ll try connecting my laptop from ethernet directly to the router since I haven’t yet tried it and been working in wireless WiFi (I know it might sound pretty dumb not having tried that before xddd)
If I see that it improves highly, I’ll try resetting-up NetBird just using Ethernet for the server to see if it works and solves it all. Thanksss
Edit: Seems that, for some reason, it got worse. Gives me results worse than when working wireless in the same room as my client PC.