End-to-end chain works

This page is served from the NAS at home, not from the cloud VM. It reached you through a WireGuard tunnel that punches out through O2's CGNAT.

your browser
   -> oci-test.vesmil.com  (DNS-only, Cloudflare bypassed)
   -> Oracle gw-oci, Frankfurt  (Caddy, Let's Encrypt TLS)
   -> WireGuard 10.8.0.1 -> 10.8.0.2
   -> NAS at home, behind CGNAT, zero inbound ports open
   -> this nginx container
originUGREEN NAS (Prague)
inbound ports at homenone — NAS dials out
tunnel RTT~15 ms
gateway cost0.00 EUR / month
Jellyfinstill not published