Options, from simplest to most work
| Option | Open ports | Notes |
|---|---|---|
| Home Assistant Cloud | none | paid; Home Assistant's own recommendation for most people |
| VPN (e.g. Tailscale, ZeroTier, WireGuard) | none or one VPN port | only your devices get in |
| Reverse proxy with TLS (Caddy, nginx, Traefik) | 443 | needs trusted-proxy settings in Home Assistant |
| Port forwarding 8123 | 8123 | Home Assistant warns this alone is not secure; always encrypt |
Also watch for ISP limits: dynamic IPs and CG-NAT can make direct access impossible without extra services.
Reverse proxy: the "it doesn't work" step
Behind a proxy, Home Assistant blocks requests from the proxy until you tell it to trust it. In current versions these settings are in the UI: Settings → System → Network → HTTP server settings.
- Enable Trust X-Forwarded-For.
- Add the proxy's IP to Trusted proxies. For a subnet, use the network address, e.g.
192.168.1.0/24, not192.168.1.10/24. - Saving restarts Home Assistant.
The proxy must also pass WebSocket connections through (the frontend uses /api/websocket), otherwise the UI loads but stays "connecting". Most proxies need an explicit WebSocket/upgrade setting; Caddy handles it automatically.
These settings don't affect Home Assistant Cloud connections, so you don't need them for Cloud-based remote access.
Hardening regardless of method
- Enable multi-factor authentication for every user.
- Keep IP banning after failed logins enabled when the instance is reachable from the internet.
- Don't expose it at all if a VPN covers your needs.