One gateway, many self-hosted services
Route separate subdomains to your NAS and apps while managing sign-in, TLS, and access policies in one place.
Put your NAS, photo library, download stack, and self-hosted apps behind one gateway. Authenticate first, then connect—directly over a public IP or through FRP and Cloudflare Tunnel when you are behind CGNAT.

Bring one service online in this order. Verify the complete path before onboarding the rest of your stack:
Do not leave a route that bypasses the gateway
fn-knock can protect only traffic that passes through it. If your router, container platform, or cloud firewall still exposes the NAS admin UI or an application's original port, those requests bypass fn-knock authentication, WAF rules, and request logging.