{"id":423,"date":"2026-08-29T08:30:00","date_gmt":"2026-08-29T06:30:00","guid":{"rendered":"https:\/\/www.lukaswojcik.com\/?p=423"},"modified":"2026-08-13T14:27:42","modified_gmt":"2026-08-13T12:27:42","slug":"wireguard-tailscale-dmz-secure-access-home-assistant-en","status":"publish","type":"post","link":"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/","title":{"rendered":"WireGuard &#038; Tailscale DMZ: Secure External Access to Home Assistant and Self-Hosted Servers"},"content":{"rendered":"\r\n<p class=\"wp-block-paragraph\">Traditional remote access architectures for home automation platforms like Home Assistant and self-hosted servers have long relied on exposing ports 80 and 443 to the public internet via NAT port forwarding. However, public-facing endpoints attract continuous automated vulnerability scanners, brute-force attacks, and zero-day exploitation attempts against reverse proxies and web applications. Modern network design eliminates public port exposure entirely by transitioning to encrypted point-to-point VPN tunnels using WireGuard or Tailscale.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\">1. The Security Risks of NAT Port Forwarding and Reverse Proxies<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Opening external firewall ports directs untrusted internet ingress traffic directly into the local network perimeter. Even with automated SSL certificate renewal and reverse proxy authentication, several structural vulnerabilities remain:<\/p>\r\n\r\n\r\n\r\n<ul class=\"wp-block-list\">\r\n<li><strong>Automated Scanning &amp; Exploitation:<\/strong> Public IPv4 addresses are scanned continuously. Unpatched CVEs in web servers, authentication daemons, or IoT dashboards can lead to immediate compromise without prior authentication.<\/li>\r\n<li><strong>Credential Brute-Forcing:<\/strong> Login interfaces exposed via port 443 remain accessible to automated dictionary attacks from global botnets.<\/li>\r\n<li><strong>DDoS &amp; Bandwidth Saturation:<\/strong> Public endpoints lack native protection against application-layer denial-of-service floods, which can degrade residential internet connectivity.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<figure class=\"lw-diagram\">\n<img loading=\"lazy\" src=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/diagrams\/wireguard-tailscale-dmz-secure-external-access-to-home-ass-en.png\" width=\"1120\" height=\"429\" decoding=\"async\"\n     alt=\"Diagram for the article: Automated Scanning &amp; Exploitation, Credential Brute-Forcing, DDoS &amp; Bandwidth Saturation \u2026\">\n<figcaption>The 6 building blocks of the article at a glance: Automated Scanning &amp; Exploitation, Credential Brute-Forcing, DDoS &amp; Bandwidth Saturation, Granular Firewall Policies \u2026.<\/figcaption>\n<\/figure>\n\n<h2 class=\"wp-block-heading\">2. Point-to-Point VPNs: WireGuard vs. Tailscale<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Replacing traditional inbound NAT rules with encrypted overlay networks enforces a Zero-Trust approach. Remote access requires cryptographic key exchange before any application-layer data is transmitted.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">WireGuard (Kernel-Space Raw Performance)<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">WireGuard operates as a lightweight, kernel-space VPN protocol utilizing state-of-the-art cryptography (ChaCha20, Curve25519, BLAKE2s). Its primary architectural advantage is stealth: a WireGuard interface drops all unauthenticated packets silently without responding, making the host invisible to network scanners. It requires a single UDP port to be reachable or benefits from direct integration into perimeter routers.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">Tailscale (Zero-Config Mesh Overlay with DERP Relays)<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Tailscale builds a mesh overlay network (Tailnet) on top of the WireGuard protocol without requiring any open firewall ports or static public IPs. Utilizing advanced NAT traversal techniques (STUN\/ICE) and encrypted DERP relay servers as fallbacks, Tailscale connects devices point-to-point regardless of Carrier-Grade NAT (CGNAT) restrictions or dynamic residential IP changes.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\">3. DMZ Architecture and Restricted Access Rules<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Establishing an encrypted VPN tunnel should not grant remote devices unrestricted access to every internal LAN subnet. Proper network hygiene requires deploying the VPN termination endpoint inside a restricted DMZ or VLAN:<\/p>\r\n\r\n\r\n\r\n<ul class=\"wp-block-list\">\r\n<li><strong>Granular Firewall Policies:<\/strong> Ingress traffic from the VPN subnet must be restricted strictly to the IP addresses and port numbers of the target services (e.g., TCP port 8123 for Home Assistant).<\/li>\r\n<li><strong>Access Control Lists (ACLs):<\/strong> In Tailscale deployments, server-side ACL rules ensure that specific identities or devices can only communicate with designated servers, preventing lateral movement across the network.<\/li>\r\n<li><strong>WAN Ingress Prohibition:<\/strong> All standard inbound NAT forwarding rules on the edge router can be permanently deleted, reducing the external attack surface to zero.<\/li>\r\n<\/ul>\r\n\n\n<div class=\"lw-quellen\">\n<h2>Sources<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.wireguard.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">WireGuard documentation<\/a><\/li>\n<\/ul>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Why eliminating public port forwarding (80\/443) and NAT exposure in favor of encrypted point-to-point WireGuard or Tailscale VPN tunnels is essential for modern home server security.<\/p>\n","protected":false},"author":1,"featured_media":11542,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[91318,91365,91321,91237,91121,91141],"class_list":["post-423","post","type-post","status-publish","format-standard","hentry","category-smart-home","tag-firewall","tag-home-assistant","tag-network-security","tag-self-hosting","tag-vpn","tag-wireguard"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>WireGuard &amp; Tailscale DMZ: Secure External Access to Home Assistant and Self-Hosted Servers - Lukas Wojcik - Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"WireGuard &amp; Tailscale DMZ: Secure External Access to Home Assistant and Self-Hosted Servers - Lukas Wojcik - Blog\" \/>\n<meta property=\"og:description\" content=\"Why eliminating public port forwarding (80\/443) and NAT exposure in favor of encrypted point-to-point WireGuard or Tailscale VPN tunnels is essential for modern home server security.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/\" \/>\n<meta property=\"og:site_name\" content=\"Lukas Wojcik - Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-29T06:30:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/hero-423-wireguard-tailscale-dmz-secure-acces-c.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"luky\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"luky\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/smart-home\\\/wireguard-tailscale-dmz-secure-access-home-assistant-en\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/smart-home\\\/wireguard-tailscale-dmz-secure-access-home-assistant-en\\\/\"},\"author\":{\"name\":\"luky\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"headline\":\"WireGuard &#038; Tailscale DMZ: Secure External Access to Home Assistant and Self-Hosted Servers\",\"datePublished\":\"2026-08-29T06:30:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/smart-home\\\/wireguard-tailscale-dmz-secure-access-home-assistant-en\\\/\"},\"wordCount\":476,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/smart-home\\\/wireguard-tailscale-dmz-secure-access-home-assistant-en\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hero-423-wireguard-tailscale-dmz-secure-acces-c.png\",\"keywords\":[\"Firewall\",\"Home Assistant\",\"Network Security\",\"Self-Hosting\",\"VPN\",\"WireGuard\"],\"articleSection\":[\"Smart Home\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/smart-home\\\/wireguard-tailscale-dmz-secure-access-home-assistant-en\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/smart-home\\\/wireguard-tailscale-dmz-secure-access-home-assistant-en\\\/\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/smart-home\\\/wireguard-tailscale-dmz-secure-access-home-assistant-en\\\/\",\"name\":\"WireGuard & Tailscale DMZ: Secure External Access to Home Assistant and Self-Hosted Servers - Lukas Wojcik - Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/smart-home\\\/wireguard-tailscale-dmz-secure-access-home-assistant-en\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/smart-home\\\/wireguard-tailscale-dmz-secure-access-home-assistant-en\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hero-423-wireguard-tailscale-dmz-secure-acces-c.png\",\"datePublished\":\"2026-08-29T06:30:00+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/smart-home\\\/wireguard-tailscale-dmz-secure-access-home-assistant-en\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/smart-home\\\/wireguard-tailscale-dmz-secure-access-home-assistant-en\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/smart-home\\\/wireguard-tailscale-dmz-secure-access-home-assistant-en\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hero-423-wireguard-tailscale-dmz-secure-acces-c.png\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hero-423-wireguard-tailscale-dmz-secure-acces-c.png\",\"width\":1200,\"height\":630,\"caption\":\"WireGuard & Tailscale DMZ: Secure External Access to Home Assistant and Self-Hosted Servers\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/smart-home\\\/wireguard-tailscale-dmz-secure-access-home-assistant-en\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"WireGuard &#038; Tailscale DMZ: Secure External Access to Home Assistant and Self-Hosted Servers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\",\"name\":\"Lukas Wojcik - Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\",\"name\":\"luky\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"width\":424,\"height\":636,\"caption\":\"luky\"},\"logo\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\"},\"sameAs\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\"],\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/author\\\/luky\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"WireGuard & Tailscale DMZ: Secure External Access to Home Assistant and Self-Hosted Servers - Lukas Wojcik - Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/","og_locale":"en_US","og_type":"article","og_title":"WireGuard & Tailscale DMZ: Secure External Access to Home Assistant and Self-Hosted Servers - Lukas Wojcik - Blog","og_description":"Why eliminating public port forwarding (80\/443) and NAT exposure in favor of encrypted point-to-point WireGuard or Tailscale VPN tunnels is essential for modern home server security.","og_url":"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/","og_site_name":"Lukas Wojcik - Blog","article_published_time":"2026-08-29T06:30:00+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/hero-423-wireguard-tailscale-dmz-secure-acces-c.png","type":"image\/png"}],"author":"luky","twitter_card":"summary_large_image","twitter_misc":{"Written by":"luky","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/#article","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/"},"author":{"name":"luky","@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"headline":"WireGuard &#038; Tailscale DMZ: Secure External Access to Home Assistant and Self-Hosted Servers","datePublished":"2026-08-29T06:30:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/"},"wordCount":476,"commentCount":0,"publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"image":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/#primaryimage"},"thumbnailUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/hero-423-wireguard-tailscale-dmz-secure-acces-c.png","keywords":["Firewall","Home Assistant","Network Security","Self-Hosting","VPN","WireGuard"],"articleSection":["Smart Home"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/","url":"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/","name":"WireGuard & Tailscale DMZ: Secure External Access to Home Assistant and Self-Hosted Servers - Lukas Wojcik - Blog","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/#primaryimage"},"image":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/#primaryimage"},"thumbnailUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/hero-423-wireguard-tailscale-dmz-secure-acces-c.png","datePublished":"2026-08-29T06:30:00+00:00","breadcrumb":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/#primaryimage","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/hero-423-wireguard-tailscale-dmz-secure-acces-c.png","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/hero-423-wireguard-tailscale-dmz-secure-acces-c.png","width":1200,"height":630,"caption":"WireGuard & Tailscale DMZ: Secure External Access to Home Assistant and Self-Hosted Servers"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/smart-home\/wireguard-tailscale-dmz-secure-access-home-assistant-en\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.lukaswojcik.com\/blog\/"},{"@type":"ListItem","position":2,"name":"WireGuard &#038; Tailscale DMZ: Secure External Access to Home Assistant and Self-Hosted Servers"}]},{"@type":"WebSite","@id":"https:\/\/www.lukaswojcik.com\/blog\/#website","url":"https:\/\/www.lukaswojcik.com\/blog\/","name":"Lukas Wojcik - Blog","description":"","publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.lukaswojcik.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9","name":"luky","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","width":424,"height":636,"caption":"luky"},"logo":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg"},"sameAs":["https:\/\/www.lukaswojcik.com\/blog"],"url":"https:\/\/www.lukaswojcik.com\/blog\/author\/luky\/"}]}},"_links":{"self":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/423","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/comments?post=423"}],"version-history":[{"count":2,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/423\/revisions"}],"predecessor-version":[{"id":9886,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/423\/revisions\/9886"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media\/11542"}],"wp:attachment":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media?parent=423"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/categories?post=423"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/tags?post=423"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}