Kind of a quick off the cuff question.... but is it difficult to get a docker hosted jellyfin server accessible outside of lan safely?
I have tailscale and a VPN I can use for my own devices but would like to be able to access it safely without needing those.
19 Comments
SheeEttin@lemmy.world · 18 pts · 2y
Stick with the VPN. No point in exposing more services with possible security vulnerabilities.
doeknius_gloek@feddit.de · 18 pts · 2y
I love Jellyfin but I would absolutely not make it accessible over the public internet. A VPN is the way to go.
iHUNTcriminals@lemm.ee · 5 pts · 2y
Yeah I'm thinking maybe just have family sign up for tailscale.
manwichmakesameal@lemmy.world · 3 pts · 2y
Why not just run your own WireGuard instance? I have a pivpn vm for it and it works great. You could also just put jellyfin behind a TLS terminating reverse proxy.
dinosaurdynasty@lemmy.world · 2 pts · 2y
Sounds like a pain to get non technical family members to use. If you're willing to break the non web app you could always put it behind an authenticating proxy (which is what I do for myself outside of VPN, setting up a VPN on a phone is obnoxious and I only look at metadata anyway on my phone)
Gooey0210@sh.itjust.works · 1 pts · 2y
Or headscale, works like a charm
kratoz29@lemm.ee · 1 pts · 2y
CGNAT is a big reason.
SuddenlyBlowGreen@lemmy.world · 1 pts · 2y
Yep, that way you can set ACLs, you they can only access the jellyfin ports + the ports you allow them to.
Also, tailacale DNS.
The fact that tailscale has google/apple/etc logon integration will also help.
Gooey0210@sh.itjust.works · 1 pts · 2y
Why "absolutely" not?
doeknius_gloek@feddit.de · 2 pts · 2y
Have you seen the link?
Gooey0210@sh.itjust.works · 2 pts · 2y
Oh, sorry, sorry, sorry, i didn't think this is a link 😅😅😅
doeknius_gloek@feddit.de · 1 pts · 2y
Haha, no problem!
eluvatar@programming.dev · 0 pts · 2y
Oof, that's bad... And lazy
PulsarSkate@lemmy.sdf.org · 5 pts · 2y
Unfortunately a lot of these issues are architectural issues inherited from Emby
darkan15@lemmy.world · 11 pts · 2y
If you are not behind a CGNAT, it should be as easy as opening the necessary ports.
I have a reverse proxy running in ports 80, 443 and can safely access Jellyfin on a subdomain without issues from outside my LAN.
Strit@lemmy.linuxuserspace.show · 4 pts · 2y
To get it outside the LAN, you just need to forward the port it uses in your router. Example 8096 for regular http requests. I would highly recommend getting at least a reverse proxy with an SSL cert.
Decronym@lemmy.decronym.xyz · 4 pts · 2y
Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:
5 acronyms in this thread; the most compressed thread commented on today has 8 acronyms.
[Thread #204 for this sub, first seen 9th Oct 2023, 21:05] [FAQ] [Full list] [Contact] [Source code]
Boring@lemmy.ml · 2 pts · 2y
Depends on your definition of safe.
If you do a public port forward and set up basic security and proper SSL its safe from the majority of people.
possiblylinux127@lemmy.zip · 1 pts · 2y
You can but it will cause security issues. You will need to buy a domain and setup a SSL proxy with https to proxy traffic in. After than I would lock down you firewall rules and make sure that a compromise can't escape the isolated environment.
Also make sure you docker container is hardened against excaping as it will improve security when a security hole is discovered in jellyfin