Secure Homelab Access: Remote Browser Isolation with KASM & Authentik

Want to share your homelab services with friends or family without giving them direct access to your network? In this video, we flip the script on Remote Browser Isolation (RBI). Instead of protecting ourselves from the open internet, we're using KASM workspaces to protect our homelab from external users. By combining KASM, Docker networks, iptables, and Authentik, we can serve users a containerized, disposable browser locked in "kiosk mode" that can only route traffic to a single specific application. No exposed ports, no direct network paths, and no lingering session data! ⏳ Timestamps 00:00 Intro: Inverting Remote Browser Isolation 02:32 Demo: What we’re Building 04:45 Solution diagram 06:14 Installing KASM 07:31 Building the Guest Workspace 09:29 Network Isolation With Docker + iptables 12:35 Building the Power User Workspace 15:15 Why Use an External Identity Provider? 16:17 Exposing KASM via Cloudflare Tunnel 17:09 Connecting KASM to Authentik via OIDC 20:04 Mapping Groups Between Authentik and KASM 22:57 Controlling Workspace Visibility 24:40 Tradeoffs: When This Approach Shines (and Doesn't) 29:02 Outro 🔗 Resources & Links Github repo with configuration: [https://github.com/filip-lebiecki/kasm] KASM Workspaces: [https://docs.kasm.com/docs] Authentik (Identity Provider): [https://docs.goauthentik.io/] Cloudflare Tunnels: [https://developers.cloudflare.com/clo...] Tags: #Homelab #SelfHosted #KASM #CyberSecurity #Docker #Authentik #Cloudflare #RemoteBrowserIsolation #ReverseProxy #LinuxServer

Expose Self-Hosted Apps Securely — Cloudflare Tunnel + Authentik + SSO
▶︎

Expose Self-Hosted Apps Securely — Cloudflare Tunnel + Authentik + SSO

Your Browser Is Exposing You — Even Over HTTPS. Here's the Proof (XRAY , ShadowSocks)
▶︎

Your Browser Is Exposing You — Even Over HTTPS. Here's the Proof (XRAY , ShadowSocks)

Docker Full Course for Beginners (2026) | Build & Deploy Real-World Projects
▶︎

Docker Full Course for Beginners (2026) | Build & Deploy Real-World Projects

The ULTIMATE Guide to Enterprise Wi-Fi Security (HashiCorp Vault + EAP-TLS)
▶︎

The ULTIMATE Guide to Enterprise Wi-Fi Security (HashiCorp Vault + EAP-TLS)

Don't Just Hide. Blend In. (Xray Routing Explained)
▶︎

Don't Just Hide. Blend In. (Xray Routing Explained)

Your Fancy DNS Tricks Won’t Give You Privacy
▶︎

Your Fancy DNS Tricks Won’t Give You Privacy

ASMR Best Triggers For Sleep Collection (No Talking) 3 Hours of Tapping & Scratching
▶︎

ASMR Best Triggers For Sleep Collection (No Talking) 3 Hours of Tapping & Scratching

Crash Course, Active Directory, DHCP & DNS for Entry Level Tech Support
▶︎

Crash Course, Active Directory, DHCP & DNS for Entry Level Tech Support

How to Actually Build Mobile Apps with AI in 2026 | A Complete Beginner's Tutorial
▶︎

How to Actually Build Mobile Apps with AI in 2026 | A Complete Beginner's Tutorial

263 DIOS TE DICE HOY: ESA ANGUSTIA QUE TE ROBA LA PAZ SERÁ CAMBIADA POR DESCANSO
▶︎

263 DIOS TE DICE HOY: ESA ANGUSTIA QUE TE ROBA LA PAZ SERÁ CAMBIADA POR DESCANSO

Aesthetic Aura Background 3 hours
▶︎

Aesthetic Aura Background 3 hours

n8n Tutorial – Zero to Hero Course
▶︎

n8n Tutorial – Zero to Hero Course

The Ultimate Guide to Linux Wi-Fi: WPA3, EAP-PEAP, and EAP-TLS
▶︎

The Ultimate Guide to Linux Wi-Fi: WPA3, EAP-PEAP, and EAP-TLS

How Xray REALITY Masks Traffic Metadata: A Deep Dive into TLS Obfuscation
▶︎

How Xray REALITY Masks Traffic Metadata: A Deep Dive into TLS Obfuscation

Abstract Black and White wave pattern| Height Map Footage| 3 hours Topographic 4k  Background
▶︎

Abstract Black and White wave pattern| Height Map Footage| 3 hours Topographic 4k Background

5 DNS Servers Every Home Lab Should Know About (2026 Guide)
▶︎

5 DNS Servers Every Home Lab Should Know About (2026 Guide)

'I Warn You - Don't Provoke Russia': Jeffrey Sachs ROARS At EU & US In European Parliament | VIRAL
▶︎

'I Warn You - Don't Provoke Russia': Jeffrey Sachs ROARS At EU & US In European Parliament | VIRAL

Replace Google with SearXNG - a privacy respecting, self-hosted search engine
▶︎

Replace Google with SearXNG - a privacy respecting, self-hosted search engine

Termix - Server Management has never been this easy! On Zima OS/Windows and Linux SSH/Remote Desktop
▶︎

Termix - Server Management has never been this easy! On Zima OS/Windows and Linux SSH/Remote Desktop

Pink Ombre Aura Screen | 3 Hours and 1 Second | No Sound
▶︎

Pink Ombre Aura Screen | 3 Hours and 1 Second | No Sound