Looks like I could use some combination of Caddy, Nginx Proxy Manager, Tailscale? What's the simplest setup?
Looks like I could use some combination of Caddy, Nginx Proxy Manager, Tailscale? What's the simplest setup?
# cat /root/.cloudflared/fbsd0_tunnel.yml
tunnel: <redacted UUID>
credentials-file: /root/.cloudflared/<different UUID>.json
ingress:
# Example of an HTTP request over a Unix socket:
- hostname: <redacted full cloudflare URL, no port appended>
service: http://localhost:8096 #this is where jellyfin would normally run
# Example of a rule responding to traffic with an HTTP status:
- service: http_status:404The end result is a valid HTTPS experience inside the network and outside (as long as tailscale is active on whatever device I'm using). And if I decide to ditch tailscale it's just a matter of mapping ports 80 and 443.
https://github.com/mikew/homelab/tree/public/services/revers...
https://github.com/mikew/homelab/tree/public/services/dns
https://github.com/mikew/homelab/tree/public/services/tailsc...
I’ve got pihole running so that’s my home dns server, I have custom domains with a home-only TLD (I think “.internal” is cleared for use now?). So something like https://plex.homecloud.internal can load up plex, I can only assume jellyfin could do the same.
I’ve actually been using ZeroTier instead of tailscale for external access and I’ve been very happy with it, but I know lots of people love tailscale and I’m sure it’s great too
Again there are probably easier options to get it running but in my case most of it runs on docker so (in theory since I had no major outages just a few times I migrated hardware) moving/restoring from backup is relatively easy - copy all the files and run `docker compose` in each directory.
The Kuma example here is decent. Replace kuma image and ports with jellyfin. https://www.elliotblackburn.com/how-to-use-tailscale-serve-w...
Personally I don't muck about with any of that and just have a link in my bookmarks bar that takes me to http://<tailscaleip>:port :D
$HTTP["host"] == "jellyfin.dc" { proxy.server = ( "" => ( ( "host" => "192.168.1.99", "port" => "8096" ) ) ) }
# kijkbuis.example.org
server {
listen 80;
listen [::]:80;
server_name kijkbuis.example.org;
include /etc/nginx/snippets/enforcehttps.conf;
}
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
server_name kijkbuis.example.org;
ssl_certificate /etc/letsencrypt/live/kijkbuis.example.org/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/kijkbuis.example.org/privkey.pem;
set $jellyfin 192.168.1.51;
resolver 192.168.1.1 valid=30;
add_header X-Frame-Options "SAMEORIGIN";
add_header X-XSS-Protection "1; mode=block";
add_header X-Content-Type-Options "nosniff";
# the google-related domains are there to enable chromecast support
add_header Content-Security-Policy "default-src https: data: blob: http://image.tmdb.org; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' https://www.gstatic.com/cv/js/sender/v1/cast_sender.js https://www.gstatic.com/eureka/clank/108/cast_sender.js https://www.gstatic.com/eureka/clank/107/cast_sender.js https://www.gstatic.com/eureka/clank/cast_sender.js https://www.youtube.com blob:; worker-src 'self' blob:; connect-src 'self'; object-src 'none'; frame-ancestors 'self'";
location = / {
return 302 https://$host/web/;
}
location / {
# Proxy main Jellyfin traffic
proxy_pass http://$jellyfin:8096;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Protocol $scheme;
proxy_set_header X-Forwarded-Host $http_host;
# Disable buffering when the nginx proxy gets very resource heavy upon streaming
proxy_buffering off;
}
# location block for /web - This is purely for aesthetics so /web/#!/ works instead of having to go to /web/index.html/#!/
location = /web/ {
# Proxy main Jellyfin traffic
proxy_pass http://$jellyfin:8096/web/index.html;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Protocol $scheme;
proxy_set_header X-Forwarded-Host $http_host;
}
location /socket {
# Proxy Jellyfin Websockets traffic
proxy_pass http://$jellyfin:8096;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Protocol $scheme;
proxy_set_header X-Forwarded-Host $http_host;
}
}