this post was submitted on 30 Jul 2026
400 points (97.4% liked)

Selfhosted

61168 readers
481 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

I've been trying to upgrade from 10.10 to 10.11 for a while now, as the Android TV app keeps nagging me, and every attempt ended with impossibly long library scan times.

After some thorough investigation, it appeared that a Home Videos type collection causes unending scan (yet to be solved), but also that Jellyfin does a lot of writes to the config directory (either database or metadata or both). Mine's on spinning media part of a ZFS pool. I tried a few performance tuning options, such as testing the config dir with recordsize (similar to block size) of 4K, 8K, 64K, 128K and library scans fell from 30-40 minutes down to 8-13min with 4K-64K. The ZFS tuning wiki suggest 64K recordsize with LZ4 compression for SQLite workloads such as Jellyfin. That seems to work as well as 4K and 8K but likely is faster when reading thumbnails and such.

Note that upgrading to 12-rc3, which is supposed to speed up library scans did not improve scan times for me. Optimizing config/database write speed did. I cross-checked the culprit by experimenting with moving the config dir to NVMe and RAM. Both of those got the scan times down to 8-9 minutes compared to the optimized spinning media's 12-13.

So if you had upgraded (or about to) to 10.11 your library scans are (about to get) dog slow and your Jellyfin's config dir resides on spinning media, optimize its write performance for SQLite.

you are viewing a single comment's thread
view the rest of the comments
[–] LodeMike@lemmy.today 10 points 4 days ago (1 children)

Yes you do. It just does it for you including handling SSL.

[–] fuckwit_mcbumcrumble@lemmy.dbzer0.com -1 points 4 days ago (2 children)

Inside the network you do, but not for remote access outside the network.

[–] ragebutt@lemmy.dbzer0.com 10 points 4 days ago (2 children)

Outside the network you still have to open your server to allow plex cloud to access it and potentially tunnel your traffic through plex.tv if a direct connection doesn’t work. This happens automatically but it does happen

With Jellyfin you just have to supply your own relay, like Tailscale or wireguard, which does require more setup but is completely free, means that you can stop your media traffic from being funneled through services that harvest your data (which plex absolutely does), and doesn’t go to shit if plex.tv goes down

[–] chisel@piefed.social 4 points 4 days ago (1 children)

You can do the exact same thing with Plex, you just don't need to since automatic remote streaming is built in. In fact, the article's solution is literally Tailscale.

You can also bypass plex authentication on any ip range you choose, so if you add your local network and plex's auth service goes down, it's no big deal.

[–] ragebutt@lemmy.dbzer0.com 10 points 4 days ago

Yeah obviously, you can also use Tailscale to tunnel to whatever service you want (including just to the server itself). But if you’re bothering to override remote plex access with all this I don’t know why you wouldn’t just pick the option that doesn’t harvest your data and increasingly treat its customers as hostile

[–] fuckwit_mcbumcrumble@lemmy.dbzer0.com 0 points 4 days ago* (last edited 4 days ago) (3 children)

This happens automatically but it does happen

And that's the key, it happens automatically and it just works. With jellyfin you have to expose the web server to the internet, or point an app to something else exposed on the internet. With plex you don't. If you don't want to (or can't) a direct connection from your server to their servers, then their servers to your device is established. No VPNs, no reverse proxies, no port forwarding, nothing exposed to the rest of the internet.

What I'm praying for is for Jellyfin to add a tailscale like direct peer to peer system. They can skip the backup funneling traffic through their servers. But just have something that coordinates a direct connection with just basic NAT.

[–] ragebutt@lemmy.dbzer0.com 7 points 4 days ago (1 children)

They won’t do that because it’s expensive and free software generally doesn’t have the budget to do this

I don’t know why you think the “just works” is any different from tunneling with a service. Your server is still opened to the internet through upnp with direct connections and through a tunnel to plex.tv when a direct connection is not possible. In fact plex is inherently less secure because their infra is both the encryption endpoint (as opposed to your client with Jellyfin and Tailscale or whatever) and their infra has been vulnerable in the past (like the massive breach in 2022).

Jellyfin with something like nginx and a vpn is open to the internet, yes, but a service that tunnels (like wireguard, Tailscale) bypasses this issue and it’s up to you to set it up as to your level of comfort

Plex is just easier but as with all things tech (especially those infected with VC dollars) “ease” translates to less secure and far more likely to exploit your data

[–] avidamoeba@lemmy.ca 1 points 4 days ago (2 children)

I came up with a funny strategy I use to lock it down a bit. What's exposed to the internet for me is Apache2 reverse proxy. The proxy is locked down to reject all connections EXCEPT for the ones coming from a special subdomain which is something like a 64-character long random string. This prevents pretty any unwanted connections. Obviously the special subdomain must remain as secret as a shared password among the Jellyfin users. It works for trusted users.

What I want ideally is an "authenticated firewall." OpenWrt rejecting all connections on the open port except for an allowlist of IPs. Then there must be a system where users can authenticate and their IP is added to the allowlist. I haven't found an off-the-shelf solution like this but I'll make it some day. Too bad I figured this random string subdomain trick cause it seems good enough for now. :D

[–] left_is_best@feddit.online 1 points 4 days ago

A semi-automated whitelist solution would be nice. I've settled for Crowdsec with very strict automatic banning behavior.

[–] KairuByte@lemmy.dbzer0.com 1 points 4 days ago (1 children)

How is your DNS set up for that subdomain? Is it on a wildcard DNS record?

[–] avidamoeba@lemmy.ca 1 points 4 days ago* (last edited 4 days ago) (1 children)

Do you mean the SSL cert? Yes, that's wildcard on *.mydomain.com. Then the subdomain is kvtn4ftxfreurdcw7qtr21mcywxaqqm.mydomain.com.

[–] KairuByte@lemmy.dbzer0.com 1 points 4 days ago (1 children)

In this case I mean the DNS entry for the random string. The thing pointing that subdomain at your IP/proxy.

[–] avidamoeba@lemmy.ca 1 points 4 days ago (1 children)

It's just an A record pointing to my IP. IP's updated from my router via the DNS provider API.

[–] KairuByte@lemmy.dbzer0.com 1 points 4 days ago (1 children)

If that A record isn’t a wildcard, anyone can see it, is what I’m getting at.

[–] avidamoeba@lemmy.ca 1 points 4 days ago (1 children)

Hm. As far as I know that can only be done if AXFR is enabled (it's not), if the domain has entered some search engine that has remembered it, or through brute force lookup. Am I missing something?

[–] KairuByte@lemmy.dbzer0.com 2 points 4 days ago (1 children)

Give it a look on https://dnsdumpster.com/ or similar. Your dns records are inherently public, so anyone that works out the domain can work out the subdomain. In fact there are plenty of tools that just scan every domain/subdomain they can find.

[–] avidamoeba@lemmy.ca 1 points 3 days ago

Thanks for the pointer. Checked, tried a couple others - they don't know about it. They have some other non-random DNS records. AFAIK they can absolutely find it if they scan for all domains, but it'll take forever if the name is randomly-generated and sufficiently long. Someone has to be determined to spend the resources. This doesn't guard against that but against bots trying to fuck with the service at the port. I could move it to a wildcard though. There's an overlap with another subdomain (they're actually sub-subdomains and the first sub is common) but I could move that.

[–] JustEnoughDucks@feddit.nl 2 points 4 days ago (1 children)

It is literally a cloudflare tunnel/ tailscale type thing but contained in the app. The only real difference is that it is bundled in the app, so less setup and in exchange, Plex itself is free to harvest all of your data.

That’s the key. It just works. No extra setup necessary.

And more importantly, I do t have to have my 60 year old mom do some additional setup in her end. Just install the app, and go.

[–] NewNewAugustEast@lemmy.zip -1 points 4 days ago

Well except during the Plex outage today.

And last week.

[–] abcdqfr@lemmy.world 5 points 4 days ago (1 children)

Let'scrypt and port forward. Sprinkle on some free ddns with a sync script/job to keep ddns pointing to your real public IP. Can even roll in some headscale if you're feeling adventurous

[–] MaggiWuerze@feddit.org -1 points 4 days ago (1 children)

Feeling adventurous is exactly what you need if you decide to expose Jellyfin to the Internet (a reverse proxy adds nothing to security)

[–] Blue_Morpho@lemmy.world 0 points 4 days ago (1 children)

Jellyfin doesn't open up your network unless you specifically allow remote access exactly like Plex. The only difference is Jellyfin doesn't have the encrypted tunnel built in- you need to know it needs it and add it yourself.

Plex has had bugs that allowed remote access into your home's Plex server. https://nvd.nist.gov/vuln/detail/CVE-2025-34158

[–] GoatSynagogue@lemmy.world 0 points 4 days ago (2 children)

That poster specifically said if you open jellyfin up to the internet ……

[–] Blue_Morpho@lemmy.world -2 points 4 days ago (1 children)

Which Plex does by default. He doesn't understand that running Plex at home doesn't open itself up to the Internet. I specifically referenced a CVE that let hackers into your home if you ran Plex.

His claim that securing Jellyfin with an encrypted tunnel does nothing is false.

[–] GoatSynagogue@lemmy.world 1 points 3 days ago (1 children)

He never claimed that in the comment you replied to.

Plex doesn’t open a port to the internet at large, unsecured no less, like jellyfin does.

[–] Blue_Morpho@lemmy.world 1 points 3 days ago (1 children)

You obviously don't use Plex to claim it doesn't need an open port for remote access:

https://support.plex.tv/articles/201543147-what-network-ports-do-i-need-to-allow-through-my-firewall/

I already posted a CVE that allowed hackers access to a Plex server running at home.

[–] GoatSynagogue@lemmy.world 1 points 3 days ago (1 children)

OK so you don’t understand networking, don’t understand how Plex works, don’t understand how that CVE does nothing of the sort, and have poor reading comprehension skills.

I’d hate to be your poor server.

[–] Blue_Morpho@lemmy.world 0 points 3 days ago (1 children)

I quoted Plex documentation where it explains in detail that you need port 32400 OPEN for remote access. https://support.plex.tv/articles/200289506-remote-access/

I linked the CVE but here is the plain language version because you didn't read what I linked:

https://www.howtogeek.com/over-300k-plex-servers-are-still-vulnerable-to-attackers-despite-emails/

"The flaw has been assigned a CVSS score of 10.0, the highest possible level of severity. This score indicates that the vulnerability can be exploited remotely over the internet, is easy to execute, and requires no authentication or interaction from the server's owner. A successful attack could result in a total loss of confidentiality, integrity, and availability. An attacker could access, modify, or delete a user's private media files, or even disable the entire Plex server. "

What the fuck is wrong with you?

[–] GoatSynagogue@lemmy.world 0 points 3 days ago

You clearly don’t understand how Plex and port forwarding work if you think that is in any way the same as opening a port to the Internet for everyone to hit jellyfin with zero security on it.

The CVE has been exploited zero times that we know of, and at worst they can delete your media files and Plex server. It’s never been reported of happening, and we have no idea how difficult it is to do - but because it hasn’t happened, it’s probably extremely hard and requires a chain of very unlikely things to have happened first.

[–] MaggiWuerze@feddit.org 0 points 4 days ago (1 children)

Reading comprehension and Jellyfin stanning don't go well together

[–] Blue_Morpho@lemmy.world -2 points 4 days ago (1 children)

He said an encrypted tunnel does nothing. I don't even run Jellyfin but that statement is false.

[–] MaggiWuerze@feddit.org 3 points 4 days ago* (last edited 3 days ago) (1 children)

An encrypted tunnel and a reverse proxy are two very different things. He (I) never talked about a tunnel and neither did the comment I (he) responded to

[–] Blue_Morpho@lemmy.world -2 points 3 days ago (1 children)

The reason to run the reverse proxy with Jellyfin is for the encryption. It's written in the documentation that way. It's why I still run Plex. I never finished getting through their steps to get the reverse proxy setup for the encryption.

It's like I said you use a car to go to work and you reply AKSUALLY a car runs on TIRES. The OP didn't say CAR.

[–] MaggiWuerze@feddit.org 0 points 3 days ago

Having an https connection doesn't do shit if the Backend is insecure. The issue with exposing Jellyfin are not man in the middle attacks, but badly managed access controls and unsecured endpoints.

Thede issues and the unwillingness of the devs to fix them because they are hellbent on keeping a maximum of client compatibility is what makes it hard to trust the overall security of the project.

That's why basically everyone, including the devs, says to not do that and instead rely on a vpn to mitigate security risks.