I would secure it behind a good reverse proxy with letsancrypt https certificates...
Check here https://wiki.gardiol.org/doku.php?id=services%3Ajellyfin the NGINX section.
I would secure it behind a good reverse proxy with letsancrypt https certificates...
Check here https://wiki.gardiol.org/doku.php?id=services%3Ajellyfin the NGINX section.
Yes, you need TLS
If it's on the Internet, yes.
Given the state of the Internet, you should keep a healthy level of paranoia. I always recommend exposing as little as possible, and that means using only a VPN and not putting jellyfin itself on the Internet.
Oh, the healthy paranoia isn’t the issue haha
I just want to be able to figure out how to configure my system to be able to safely expose a single service for my use away from home. Because I’d like to eventually expand from Jellyfin to Nextcloud and Vaultwarden as well, but I know I’m not there yet
Remote access doesn't mean opening it up to everyone
Correct. I’d like to make it available to myself and any family members or friends I share it with, but not the wider world
Have you checked out Netbird?
I have not. What is it?
Don't expose Jellyfin to the internet
Instead, add some sort of additional security layer like a Mesh VPN
I would only expose a port to the Internet if users other than myself would be needing access to it. Otherwise, I just keep everything inside a tailscale network so I can access remotely. Usually I believe people put a reverse proxy in front of the Jellyfin server and configure your certificates from there. So Jellyfin to proxy is insecure and then proxy to internet is secure. Lets Encrypt is an easy way to do that. And if you are going to expose a port you definitely want fail2ban monitoring that port.
If using tailscale funnels, you can technically skip the certificate part as that's done for you, but that would take away from the learning experience of setting up a proxy.
To add to the idea of using tailscale. I've been using tsdproxy for a while now and it's outrageously easy to set up.
The reason I've gone this route is that I feel like it gives me a bit more control over who is in my network and what they can get to.
Each service gets a funny name address and I get to share that specific service with other people who also have tailscale. Then if they get on my nerves or something, I can stop sharing that specific service and they can figure it out on their own.
I would also recommend a VPN. However, if this doesn't work or you want to share it with friends I would recommend something like a VPS relay: https://codeberg.org/skjalli/jellyfin-vps-setup
all 21 comments