Hello from S4-F3.

If you are reading this at https://bielefeldt.berlin/, the whole path works:

  1. your browser reached the IONOS VPS over the public internet,
  2. nginx there proxied the request into a WireGuard tunnel,
  3. the Fritz!Box at home decrypted it and handed it to the LAN,
  4. and nginx on S4-F3 — a machine with no public address at all — answered.

WIREGUARD-TUNNEL-PROOF-S4-F3