I have docker installed, but only have a vague idea of how it works.

Back in the day, I would just port forward, but even then, I would need a static IP somehow.

I have heard a reverse proxy is an option, but that is an entirely new topic to me.

Surely there is an easy way to access Jellyfin outside of my home network that I’m just missing.

*Edit: I am blown away by all the help and support! I currently have tailscale running, and I’m in the process of purchasing a domain.

Thanks everyone!

  • Wilmo@programming.dev
    link
    fedilink
    English
    arrow-up
    106
    arrow-down
    2
    ·
    28 days ago

    Tailscale. It’s free. Insanely easy to set up.

    Just install on your devices and connect via the given tailscale ip for the jellyfin server.

    • sakphul@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      31
      ·
      28 days ago

      I would also propose going with Tailscale instead If a VPN + DynDNS solution. Imho it is a lot easier to Setup compared to VPN + DynDNS If you are a beginner and just starting out.

      If at some point you need more and then is available in the free Tier of Tailscale and you do not want to pay for it (and you have built up some knowledge!) you can switch to something like Headscale or Netbird.

      • hoshikarakitaridia@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        28 days ago

        I forgot to mention that one because I kinda thought it belongs with radmin and hamachi, but it’s my choice as well currently.

        I am using it with my own Headscale though, so add a domain to that as well.

        And I finally need to switch my vaultwarden to work over tailscale & LAN finally, it’s a huge security risk to expose that one.

    • ragebutt@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      17
      ·
      28 days ago

      Or head scale if you don’t want something you don’t control that requires an account with google/apple/microsoft

      • pineapple@lemmy.ml
        link
        fedilink
        English
        arrow-up
        3
        ·
        27 days ago

        Headscale is great but requires port forwarding which, aside from having its own iasues, is something op wants to avoid.

    • Lka1988@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      2
      ·
      26 days ago

      Tailscale. It’s free.

      Something about Tailscale rubs me the wrong way. That “free” aspect, specifically. No company ever runs a free service without some sort of compromise somewhere.

  • hoshikarakitaridia@lemmy.world
    link
    fedilink
    English
    arrow-up
    41
    ·
    edit-2
    28 days ago

    That’s the whole point of a domain. Your IP changes every now and again you need people to know where to reach you. You give them a domain, and you configure the name records so that the domain always points to the right IP address.

    Your options:

    • dynamic IP - you keep your setup as is and just periodically tell them the new IP you’re on. Annoying and exposed
    • static IP - you buy a static IP (from your ISP) and share it with your friends once. A little bit less annoying and still exposed
    • you use a VPN like hamachi or radmin - your friends install the software, they look for you IP in there, you’re done - very secure but also very annoying
    • you buy a domain - you have to configure an IP updater like ddclient or similar, then you jellyfin should be reachable - least annoying for your friends but also slightly less secure

    Domain is the cleanest option.

    I am telling you how annoying it is because that’s how likely your friends are to adopt it and how secure it is because depending on your country you are doing something illegal and you really don’t want anyone to find out and you gotta keep it updated more often if you don’t want people to exploit it. There’s an endless supply of very smart people out there who use known bugs to target public services.

    Edit: I forgot DDNS, see below comments.

    • Vegan_Joe@anarchist.nexusOP
      link
      fedilink
      English
      arrow-up
      4
      ·
      28 days ago

      I appreciate your response!

      It looks like a VPN is the option I’m leaning towards, but I’ll definitely put the idea of buying a domain in my back pocket for a while.

              • Saapas@piefed.zip
                link
                fedilink
                English
                arrow-up
                6
                ·
                28 days ago

                You get to pick your numbers

                On June 1, 2017, .XYZ launched the 1.111B class .xyz domains, cheap domains priced at US$0.99 per year and renewed at the same price. The class of domains consists of six-, seven-, eight-, and nine-digit numeric combinations between 000000.xyz and 999999999.xyz. Daniel Negari, CEO of .XYZ, stated that it was meant to bring competition, choice, and innovation to the market

  • KairuByte@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    26
    ·
    28 days ago

    Personally I didn’t want to have to hand out VPN credentials to everyone, so I went with a cloudflare tunnel with Authelia as the method of authentication.

    • irmadlad@lemmy.world
      link
      fedilink
      English
      arrow-up
      15
      ·
      28 days ago

      +1 for Cloudflare Tunnels/Zero Trust. The free tier is more than generous for a homelab

      • KairuByte@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        9
        ·
        28 days ago

        Not to mention, the amount of data you can run through it is nuts. I’ve been running Stremio web through it for months without issue to watch content at work.

        • irmadlad@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          28 days ago

          Yup. OP was asking about bandwidth caps, I haven’t experienced any, nor can I find any documentation to support bandwidth caps. I stream Navidrome around the house from the time I get up to the time I go to bed and it has worked flawlessly.

      • happydoors@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        27 days ago

        While I have similar users here. I noticed that anything I watched on Jellyfin and was connected to cloudflare would give me recommended YouTube shorts on the movies/shows or similar ones I was watching. It is a great free service and I got my domain hooked up through them for $12/year but I feel like it is the leak for my data. I didn’t mind it for a long time because getting shorts served to me that were movie clips was fine with me.

        Anyone notice similar behaviors? My paranoia has me wanting to go a different route or lock things down more.

          • happydoors@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            26 days ago

            Notice custom ads based on the content you ARE piping through zero trust? Just curious. I realize many users here are probably very avoidant of ads or algorithmic shifts in the first place so it may be unnoticeable

            • irmadlad@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              26 days ago

              I’ll have to say it has been decades since I’ve seen an ad show up on my screen. However, as I said, I do not run the *arr stack or JF, so my experience might not be applicable to everyone.

              So, you stream a video using JF or other and you are getting ads show up? Like pre-roll ads, or other? That just sounds weird to me. Could you provide a screen capture of said intrusions?

              • happydoors@lemmy.world
                link
                fedilink
                English
                arrow-up
                2
                ·
                26 days ago

                It is content recommended on YouTube, essentially. Not the usual long form content but the shorts feed in particular draws specifically from my Jellyfin downloads and views. Not ads, necessarily, but video clips of movies or similar genres in my algorithmic feeds based on apps using zero trust. It is typically a pattern of download a movie(behind mullvad) or watch Jellyfin and then notice similar movie clips by the next morning. I’m not really interested in going over the details on this thread because it’s not the main topic and there are many other ways this type of behavior happens. For instance, I have Jellyfin installed on a google chromecast and that could be enough or the actual leak. I have a pi-hole running and don’t see many traditional ads but YT shorts was an area where I could physically see how my location, travels, and activity on the web in other places changed the clips they served me in realtime. Pretty cool and scary stuff! I’ve been slowly pruning back corporate spyware. Good luck out there.

                • irmadlad@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  26 days ago

                  Ok cool. I was just curious. I think you’re the first I’ve heard with this situation so it piqued my interest.

      • Pika@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        8
        ·
        28 days ago

        it’s actually the recommended way if you use jellyfin, theres a few security/privacy vulnerabilities with publicly exposing the jellyfin server anyway, they are being worked on but, the safest way to do it is just use a vpn regardless.

        • frongt@lemmy.zip
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          2
          ·
          28 days ago

          Plus it enables you to access everything. If you have radarr or sonarr or whatever, you can get to those and add media while out and about.

          Personally I use Mealie and pull up ingredient lists while I’m im at the grocery store.

      • djdarren@piefed.social
        link
        fedilink
        English
        arrow-up
        5
        ·
        28 days ago

        Just be aware that if you want anyone else to connect to your Jellyfin, you’ll still have to route it through a domain and reverse proxy, unless you’re comfortable letting them log in to your tailnet.

        It’s a bit of a fiddle to set up, but once it’s done it’s quite satisfying.

    • Pacrat173@lemmy.ml
      link
      fedilink
      English
      arrow-up
      3
      ·
      28 days ago

      It’s my go to method super easy to set up and use on both the device hosting your JellyFinn server and whatever your steaming on

  • frongt@lemmy.zip
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    2
    ·
    28 days ago

    Yes, a VPN. And dynamic DNS if you don’t have a static IP address.

    • Vegan_Joe@anarchist.nexusOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      28 days ago

      To be clear, your suggesting I set up my home computer as a virtual private Network server that I would connect to from the TV or device outside of my home network?

      • frongt@lemmy.zip
        link
        fedilink
        English
        arrow-up
        11
        arrow-down
        2
        ·
        28 days ago

        Yes, it works great for me. Probably not for a TV though, for that you’d probably need some travel router VPN client. But I don’t know how often you’d be at a random TV and need to get to jellyfin.

      • towerful@programming.dev
        link
        fedilink
        English
        arrow-up
        5
        ·
        28 days ago

        Yeh, exactly.
        And the “dynamic DNS” part handles your public IP address changing with 0 pain.
        You either buy a domain (like example.com), or there are free domain name providers that give you a subdomain (like mycooldomain.example.com) of one of their domains.
        You then run an additional service on your home server that checks what the current public IP address is. If it changes, it notifies the DNS responsible for your domain/subdomain, which then points to your new public IP.
        To connect to your VPN, you only ever care about “mycooldomain.example.com” and never the underlying IP address.


        As long as your ISP isn’t running CG-NAT of course 😵‍💫

  • Faceman🇦🇺@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    8
    ·
    26 days ago

    for a beginner with just a few remote clients, tailscale all the way.

    though I still like doing it the old way with a custom nginx setup, fail2ban and a domain name, but its more work to make it secure and even then it’s still somewhat of a liability.

    • Phoenixz@lemmy.ca
      link
      fedilink
      English
      arrow-up
      2
      ·
      26 days ago

      How stable is tail scale in teal life? I constantly have issues with relay servers not being available, spontaneous logouts, etc…

      I want to use it, but I also want my wife to use it and she will need a “no matter what, it must work” solution or she won’t use it

  • alexquiniou@lemmy.zip
    link
    fedilink
    English
    arrow-up
    8
    ·
    28 days ago

    I’m using wireguard with wg-easy. It’s a gui that let you easely setup wireguard. My isp is giving a fixed ipv4. So i don’t have to think about dns or other complicated things. I have Jellyfin and wg-easy installed on truenas as docker apps.

    There are official app for any os you want.

    https://www.wireguard.com/install/

  • paultimate14@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    27 days ago

    I ended up using duckdns for a free domain. It sucks that I had to tie it to a google account, and maybe one day this might be an area where I buy a proper domain instead.

    I have a glinet Flint3 router that makes it easy to spin up Wireguard servers on it. It was a bit more finnicky, but eventually I was able to get into the advanced settings and configure the router to sync the dynamic IP with DuckDNS too.

    So I have Wireguard on my phone and my wife’s phone. We have one pair of close friends who have a connection on their router too (and vice-versa) and their own Jellyfin server.

  • Darkassassin07@lemmy.ca
    link
    fedilink
    English
    arrow-up
    6
    ·
    edit-2
    28 days ago

    You don’t need a static IP, you just have to keep track of what your current dynamic IP is.

    You can do this with either a free or a paid DNS service.

    There are a few different ‘free dns’ services that will delegate a subdomain of theirs to you at no cost. Admittedly, I’ve never actually used one of these so their names escape me. Hopefully someone else can point one of those out if that’s what you really want.


    I purchased a domain via google domains, when they existed. It’s now transferred to squarespace, because they bought out google domains a few years ago.

    It was around $13/year when I first got it a decade ago. It’s now around $28/year.

    This allows me full control over the domain: I can use as many subdomains as I want to give each service I use it’s own unique name. (Instead of using their own separate ports that you’ve gotta remember) My domain will also forward all inbound email to my gmail account; this lets me use email addresses like <servicename>@mydomain.example. This way, I don’t share my real email and can immediately tell who sold my info to the highest bidder when I get spam. (I could also host my own email service if I really wanted, but I haven’t bothered)

    Add Cloudflare ontop (for free); and it can filter out known attacks, ddos attempts, geofence your services to regions you’ll actually be in, provide/autorenew ssl certs for https, show you usage analytics, cache static data reducing server/network load, etc.

    Ultimately, the paid option is well worth it IMO. $2/month (which I typically pay in 3-10 year blocks) is hardly anything.

    /edit; vpns are good and all, but they require you to setup software on the remote device to connect to it, and that typically routes most if not all your traffic back to the vpn server then out to the internet. That can create speed/bandwidth issues.

    A domain allows you to access your services from any Internet connection with 0 configuration on the client side. Just accessing it like any other website.

    I also host a vpn directly from my network, that I access/find via my domain. This means I’m not dependent on a public service like tailscale, but can still add additional security to access private only services (stuff I don’t expose to the open internet)

    • Vegan_Joe@anarchist.nexusOP
      link
      fedilink
      English
      arrow-up
      5
      ·
      edit-2
      28 days ago

      As averse as I am to spending money on subscription services, having my own domain for less than 30 bucks a year might be worth it.

      I think I’m going to try out the tailscale VPN route first before I fully warm up to buying a domain.

      *Edit-You’ve definitely got me sold on getting a domain! Thank you so much for all the info!

      • Darkassassin07@lemmy.ca
        link
        fedilink
        English
        arrow-up
        3
        ·
        28 days ago

        Glad I could help. I’m not always immediately available, but I don’t mind answering questions if you run into troubles. Just send me a DM and I’ll do what I can. :)

    • Rivalarrival@lemmy.today
      link
      fedilink
      English
      arrow-up
      2
      ·
      28 days ago

      You don’t need a static IP, you just have to keep track of what your current dynamic IP is.

      You still need a public IP address. More and more often, IPv4 services are provided behind CGNAT, which won’t be able to work as you describe.

      If you don’t have a public IPv4 for your LAN you can use IPv6. Or, you can reverse proxy your services through a gateway with a public IPv4.

      I use a a reverse proxy (Pangolin) running on a VPS. A Newt tunnel connects my LAN to to Pangolin, exposing my local services via subdomains.

      /edit; vpns are good and all, but they require you to setup software on the remote device to connect to it, and that typically routes most if not all your traffic back to the vpn server then out to the internet. That can create speed/bandwidth issues.

      Tailscale, ZeroTier, and other similar services generally establish direct tunnels between devices, without a separate VPN server. They use a central service merely as a sort of common meeting point (STUN/TURN) for the devices to figure out how to establish direct tunnel(s).

      • Darkassassin07@lemmy.ca
        link
        fedilink
        English
        arrow-up
        2
        ·
        28 days ago

        Fair points.

        I’ve been lucky enough to have never been behind cgnat, so I keep forgetting about it.


        My bigger concern with tailscale is being required to install software on the client. Not every device I use, I have permission to install a vpn client, nor would I want to.

        For example, I have a fileshare using Filebrowser where I store work related files that I don’t want to loose access to or need access to from multiple machines (non proprietary info, stuff IT/MGT wouldnt get mad at me for ofc. I’ve actually cleared it with my managers, so no worries). That’s also a handy way to (temporarily) share large files with people or provide a way for friends to upload large files to me.

        I also like to access my emby server (using sufficiently limited accounts), from things like the TV in the work break room, or a friends PC while I’m visiting.

        Tailscale is a hurdle that I just don’t need/want.

  • chellomere@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    28 days ago

    I use pangolin and subdomains on my domain. It works really well, and enables SSO login to all services on the network.

      • chellomere@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        27 days ago

        Yeah, for certain apps you may need to do that. I’ve had to do that with Nextcloud and Linkwarden. But Immich will happily work with a shareable link.

        • PeriodicallyPedantic@lemmy.ca
          link
          fedilink
          English
          arrow-up
          1
          ·
          27 days ago

          I actually commented a solution on a pangolin ticket, and they were like “good idea!” And implemented it, but then made it an enterprise only feature 😭

  • Err(()).unwrap()@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    28 days ago

    As others have said, Tailscale is the most pragmatic solution. It’s a mesh VPN based on Wireguard. It’s implemented in such a way that you don’t need a static IP and don’t need to open any ports on your firewall. The caveat is that you either need to register an account on tailscale.com (it’s free for small-scale use) or set up a self-hosted alternative like Headscale on a VPS. Then you have to install the Tailscale client on each of the hosts you want to access and log into your account.

    Tailscale nodes will be accessible using an internal, private address in the 100.64.0.0/10 address space. You can also set up a split DNS that allows you to access your hosts using a DNS name like hostname.your-tailnet-name.ts.net.

  • ThePowerOfGeek@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    3
    ·
    28 days ago

    An easy way? I guess the term ‘easy’ depends on your expertise with networking, firewalls, etc. Sounds like you and I are at about the same level there. In which case the answer is: no, there’s no easy way from what I can tell. I’ve looked into it and it’s a lot more involved than, say, Plex (because Plex does a bunch of the routing and stuff for you, but at a cost).

  • terrifyingtuba@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    edit-2
    28 days ago

    Personally I purchased a domain, and use Caddy for a reverse proxy. My ISP gives me a static IP for free, but I don’t think that makes a difference in this situation. Tailscale would be safer but requires more setup from friends. My friends seem to like how simple the setup is, and I also use requestrr so they can add movies/shows via a discord command.

  • Morgikan@fedia.io
    link
    fedilink
    arrow-up
    4
    ·
    28 days ago

    If the goal is doing this in a simple fashion, then use Tailscale funnels (https://tailscale.com/docs/features/tailscale-funnel). Funnels automate the process and act as a reverse proxy into specific servers within your tailnet.

    The downside is there is no authentication to funnels, so whatever you’re running (Jellyfin in this case so that’s not an issue) needs it’s own authentication setup. You might consider running fail2ban on that machine and have it watch for login attempts, but otherwise that is the simplest setup I think you could do.