Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
view the rest of the comments
There is no safe manner of exposing jellyfin.
Again, I do not run Jellyfin, but what you're saying seems contradictory to what the devs are implying: here and here. Since I lack the hands on experience, I will leave the issue with the experts.
That first page says exposing it to the Internet is "not recommended". Putting a reverse proxy in front of it does not meaningfully change the security posture. A malicious request to
http://jellyfin.homelab.com/exploitable-pagewill be sent to jellyfin in effectively the same way, whether through a reverse proxy or not. You would need a WAF set up specifically to look for relevant exploit attempts.https://github.com/jellyfin/jellyfin/issues/5415
Those are some outstanding known vulnerabilities, most of them unfixed. They are not particularly severe, but it shows that thorough security is not a priority for the jellyfin devs.
It says exposing a port directly to the internet is not recommended; do you know of any project that would recommend directly exposing a port? What is meaningfully different here?
Sure, any project designed to be exposed to the Internet. Web servers would be the most obvious.
Probably the number one recommendation I see in self hosting communities is to not open ports directly (other than for a reverse proxy). It seems like a common recommendation no matter the service. To be clear: I am a beginner. I know very little about this, but I've spent months learning. I can't say you're wrong, but I don't think you've made a convincing argument for me to actually understand why Jellyfin is unsafe to expose to the internet compared to any other service.
You are welcome to expose it at your own risk. Assess you own tolerance for compromise (personal data compromise, becoming part of a botnet, becoming a host for spam or CSAM) and proceed accordingly.
Yes, that's exactly what I've done. You still haven't shown me why it's unsafe. If you can't, that's fine. At some threshold or another, nothing is secure. The one thing I know for sure is that that first page, that says it doesn't recommend exposing a port, does not say what you said it does.