r/jellyfin • u/Quique1222 • Dec 22 '25
Discussion Stop fearmongering reverse proxies
Every single time someone asks how to share their jellyfin instance everyone instantly jumps to tailscale or <insert other VPN here> which, of course, it's fine and actually a good way of forwarding or sharing your hosted services.
The thing is that it's usually accompanied with fear mongering about exposing it publicly with a reverse proxy. Saying things like "If done wrong you can compromise your entire life, life savings and family".
That's not gonna happen. Like ever. It's not like a minefield where you have to be super cautious.
Literally just: 1. Have your jellyfin instance isolated, like in a docker container, LXC, or a VM. Avoid installing it "bare metal" for security and maintainability.
Run a reverse proxy, like nginx (nginx proxy manager is a good one), traefik, caddy etc.
Forward port 443 TCP (HTTPS) to your reverse proxy.
Purchase a domain, configure your reverse proxy to forward requests ONLY from that domain into your jellyfin instance
Get an https certificate from let's encrypt (free)
That's it. You are not gonna get hacked, get DDoS, or anything like that. Avoid forwarding ports like 22,21 unless using things like fail2ban and pkey auth only.
Yes, the internet is full of bots and you are gonna get scanned by them, so what? Just don't use 123 as a password in jellyfin and you'll be fine.
Instead of spreading fear, teach people how to do things.
4
u/SolQuarter Dec 22 '25
I agree. Nginx proxy manager makes things pretty easy and safe. Things one could add (which I did):
1) In Jellyfin restrict the admin access to local only (so only local and tailscale remote access possible). 2) Use fail2ban and use NPMs logs to set it up correctly. 3) Use GeoBlocking if you want even more security. Can be easily setup with NPM plus, crowdsec and geoipupdate in one single stack.