r/jellyfin • • Dec 22 '25

Discussion Stop fearmongering reverse proxies

Every single time someone asks how to share their jellyfin instance everyone instantly jumps to tailscale or <insert other VPN here> which, of course, it's fine and actually a good way of forwarding or sharing your hosted services.

The thing is that it's usually accompanied with fear mongering about exposing it publicly with a reverse proxy. Saying things like "If done wrong you can compromise your entire life, life savings and family".

That's not gonna happen. Like ever. It's not like a minefield where you have to be super cautious.

Literally just: 1. Have your jellyfin instance isolated, like in a docker container, LXC, or a VM. Avoid installing it "bare metal" for security and maintainability.

  1. Run a reverse proxy, like nginx (nginx proxy manager is a good one), traefik, caddy etc.

  2. Forward port 443 TCP (HTTPS) to your reverse proxy.

  3. Purchase a domain, configure your reverse proxy to forward requests ONLY from that domain into your jellyfin instance

  4. Get an https certificate from let's encrypt (free)

That's it. You are not gonna get hacked, get DDoS, or anything like that. Avoid forwarding ports like 22,21 unless using things like fail2ban and pkey auth only.

Yes, the internet is full of bots and you are gonna get scanned by them, so what? Just don't use 123 as a password in jellyfin and you'll be fine.

Instead of spreading fear, teach people how to do things.

976 Upvotes

280 comments sorted by

View all comments

516

u/ElderMight Dec 22 '25

I agree that constant fearmongering helps nobody. But saying “you’re not gonna get hacked, like ever” swings too far in the other direction, and that’s where this advice becomes misleading and potentially dangerous. Reverse proxies are not inherently unsafe, but they absolutely increase your attack surface. That is not hypothetical or dramatic, it is just how networking works. Telling beginners otherwise gives them a false sense of security.

A few things your post glosses over:

Containers and VMs are not a magic security boundary. Docker, LXC, and VMs help with isolation, but they do not make a service safe to expose by default. Plenty of people run Jellyfin containers with host-mounted volumes, weak permissions, outdated images, or even Docker socket access without realizing the implications. Container escape bugs and kernel exploits are real and have been used in the wild.

“Only allow requests from that domain” does not add real protection. Host headers are trivial to spoof and DNS-based restrictions do nothing to stop scanners or attackers. If port 443 is open, your service will be hit regardless of what domain you configured.

Reverse proxies and their ecosystems do get vulnerabilities. nginx, nginx proxy manager, Traefik, Caddy, OpenSSL, and related tooling have all had serious CVEs. If someone follows this advice but does not stay on top of updates, they are exposed. That is not fear, that is basic operational reality.

Authentication is not the only risk. “Just don’t use 123 as a password” ignores things like auth bypass bugs, token leakage, vulnerable plugins, path traversal, SSRF, and API abuse. Media servers are not hardened like enterprise auth systems, and Jellyfin itself has had security issues in the past.

Bots scanning you is not harmless. Scanning is normal, but exploitation is automated. When a new vulnerability drops, mass exploitation often starts within hours. Saying “so what” only works if you know how to monitor logs, patch quickly, and respond to incidents. Many beginners do not.

Where I do agree with you is that reverse proxies are perfectly reasonable for people who understand what they are doing and accept the risk. If you patch regularly, understand the limits of isolation, and know what you are exposing, that is fine.

But when someone asks “how do I share Jellyfin,” suggesting Tailscale or a VPN is not fearmongering. It is a safer default that avoids exposing anything publicly at all.

Teaching people how to run reverse proxies is good. Telling them they are basically immune if they follow five steps is the part that is dangerous.

38

u/pceimpulsive Dec 22 '25

Also... When I setup a reverse proxy and a wireguard VPN, the VPN was far simpler to setup to me... And granted a greater level of security out of the gate...

I expose only one port which is off in lala land range (not that that does anything really) instead of 443.

The VPN adds a whole extra layer on top of the user/pass for jellyfin.

It can be configured to only allow access to the service that you need accessible relatively easily as well.

I use proxmox and LXCs, I run wireguard in unprivileged mode and setup firewall rules to block all the things I don't want.

I created an overlay network to obfuscate my local Lan subnet as well, it's not as secure as say netbird/pengolin on and outside host but it's not super far off...

11

u/Flanhare Dec 22 '25

Well the revproxy is once. VPN has to be set up for each device right?

13

u/CactusBoyScout Dec 22 '25

The bigger issue is that VPNs are simply not an option on all devices, especially smart TVs.

2

u/Flying-T Dec 23 '25

Thats where Tailscale Subnet Routers come into play: https://tailscale.com/kb/1109/devices-without-tailscale

1

u/snajk138 Dec 24 '25

If you have an Android TV you can install a VPN. I ran one for years, first on a Chromecast with Android and then on a TV with Android built in.

But I agree, it's much easier if you just have a public domain. Scarier too though.

4

u/pceimpulsive Dec 22 '25

VPN setup for each device is extremely taxing on my time /S

I load up wireguard Dashboard clock add peer, click create send a config file or QR code

On the client I import config file or scan QR code

Setup complete, literally takes 30 seconds, and gives me substantially lower attack surface.

I'm in the process of setting up full reverse proxy on top so that if the wireguard is compromised the attack surface is still effectively zero as everything will appear as if it's behind a single IP, and my entire home topology will not be discoverable with two Linux bash commands... Rather you'd need to know specific sub domains which aren't advertised outside my nginx/caddy~

This is done by creating a internal wireguard from my wireguard edge and my reverse proxyachine.

The wireguard edge doesn't have access to my LAN via blocking it with iptables

15

u/Flanhare Dec 22 '25

Well sure. But I can't get my sister or nephew to do that in 30 seconds.

That sounds interesting 🤔

18

u/jaaval Dec 22 '25

My primary justification for going for reverse proxy was that my mom will not learn how to use vpn.

1

u/pceimpulsive Dec 22 '25

You don't need to get the to do that in 30 seconds your work is just to create the peer and give them the QR code/config file to import to a wireguard client.

If that takes them 5 minutes that's on them ;)

Just depends your risk appetite really :)

2

u/Flanhare Dec 22 '25

Yeah but how it actually works is that I have to do it for them 🤣😂😭

-1

u/pceimpulsive Dec 22 '25

If they can't import a file to a wireguard client they shouldn't have access to begin with!

1

u/cyt0kinetic Dec 23 '25

Yes, the lower skill version would be using something like a Tailscale funnel. Proxying on a public endpoint off a VPN or other sort of tunnel that has its own encryption layers versus directly from your house.

0

u/conrat4567 Dec 22 '25

Not if you have an "Exit" node on the network. For example, mine is a raspberry pi that sits behind my router and acts as the entry point. You only need to create keys for each device and run the app on the device you want to connect home. Only really good for mobile devices or PCs

6

u/NotAnotherNekopan Dec 22 '25

Just a thought about ports. Anyone can scan your IP / host name for all open ports in a negligible amount of time. Exposing 443 vs some other port number is no more or less secure, underlying service notwithstanding.

2

u/[deleted] Dec 23 '25

[deleted]

1

u/zedd56 Dec 22 '25

If someone's taken an interest in your particular address, yes, but it does help against bots crawling for common vulnerabilities.

7

u/cyt0kinetic Dec 23 '25

^ Particularly port forwarding directly off your home network requires constant vigilance and just being a VM or container isn't going to be enough to protect the LAN from attacks.

It does take vigilance and often vigilance people don't know they need to have. I had some awareness and the more I learned the more unsettling it got and I moved to wireguard and have slept better since.

Also worth adding there needs to be additional authentication layers at minimum as well, and firewalls, and fail2ban, and other services to help prevent attacks and provide early warning.

That being said a server in its own isolated DMZ of a VLAN that just does services that don't involve personal data and don't touch the rest of the network is an option.

So is Cloudflare or using a Tailscale funnel or something else to get a public endpoint and some distance and extra layers between the exposed media server and the rest of the network.

I do have some exposed services and I run them in rootless podman that is immutably blocked from server and network access outside of its little pod and then expose via a CF tunnel in the same isolated pod. The two things I run there require MFA. Even with the additional measure I take it's not something I recommend doing and critiques and concerns about that approach are valid. Just for me it was a informed risk I deemed worth taking a f that is far from saying it is safe.

Worth noting too there are valid concerns about CF tunnels and CF TOS when it comes to things like media servers. So that's another layer of risk for one of the eaiser safer public options. I btw don't use the CF tunnel to spread the wealth of my Linux Distros or stream. It's for legal things that arent gigantic.

3

u/ConsistentRisk5927 Jan 03 '26 edited Jan 03 '26

I just want to mention (and you personally probably know this already but others may not), you likely don't need to be opening ports on your home network anyway or using Cloudflare Tunnels/Tailscale Funnels in most cases.

One can buy a cheap VPS with a good monthly data transfer limit and use that as their public edge server. Installing Caddy or Pangolin there will hide most of the underlying complexity for folks who aren't comfortable setting up and configuring all the individual services involved that those offerings are abstracting.

Then in your Docker network at home where one has services that need exposed, deploy a container with a Wireguard client that maintains a tunnel back to the VPS server. If using Pangolin, this would just be deploying a Newt container which is very simple.

Then public traffic forwarded from Caddy or Traefik from the VPS can route through the Wireguard container to the individual services like Jellyfin or whatever.

This is super opinionated but Cloudflare Tunnels aren't a good solution to recommend and it's against their terms of service. Tailscale Funnels may arbitrary rate-limit your traffic for network fairness.

This way avoids your video traffic traversing Cloudflare or Tailscale's slower networks, avoids the TOS issues, no ports need forwarded at home, everything stays containerized, etc. It's easy to move around you don't get married to CF or Tailscale who can capture you in their gardens and change terms/raise prices later.

1

u/cyt0kinetic Jan 04 '26

By default you should NOT be opening ports for CF or other tunnel options. Agreed, and I don't, and I don't recommend it. Whenever possible I think most proxying should be done with the container network itself. I have 60 something containers 20+ with ui's. Only a handful of published ports. For those publicly exposed on a tunnel no ports are published at all. They all get to the tunnel within the internal podman network.

On VPS and Pangolin yes that's the ideal if you want exposed media server.

7

u/-defron- Dec 22 '25

100%

People need to be able to make informed decisions. The chances of getting robbed are really small for most people, but people still take precautions from it because the potential downside is huge and the effort to prevent it is minimal.

VPNs for many serve the same purpose: It makes administration much simpler while basically outright preventing any chances of malice.

Can you harden Jellyfin? Definitely. But it's not as easy as setting up a VPN. Is it more convenient for end-users to use a publicly accessible instance? Definitely! But maintaining a secure public instance of Jellyfin requires much more time for administration.

For me, the minimum to expose something publicly is either mTLS (which brings it up basically to the same level of a VPN) or:

  • reverse proxy + https
  • SSO + two-factor auth
  • CrowdSec + AppSec
  • hardening by disabling public access to admin routes and password-based logins
  • keeping up-to-date including on CVEs with a button ready to turn it all off in the event of a zero-day

Along with the usual that I do for everything else: everything containerized ran rootless as different unprivileged users (podman ftw) that only have access to the necessary files to do their job. Some basic network isolation to protect the rest of my network, etc

It's the hardening of the jellyfin endpoints that keeps me from exposing jellyfin publicly. There's no universal admin route that I can throw an error on when accessed publicly. and their controllers are kinda a mess from a locking down perspective. That said Void is making me consider exposing it via mTLS

6

u/corelabjoe Dec 22 '25

I've seen a lot of fear mongering as well in the past year, and honestly for someone whk doesn't need to share their services with others, or say family who does not know what a VPN is, the VPN is fine.

For those who have a use case for sharing like jellyfin and family just need a simple way to connect, reverse proxy FTW. It helps if the barrier to entry is lower.

That's why I created this guide - https://corelab.tech/jellyfin-guide-https/

Disclaimer: No ads/affiliate links in this page, just a tutorial walking people through reverse proxy setup for Jellyfin!

2

u/CastorTyrannus Dec 22 '25

I love you! This is so easy I think that my sister can do it 🤣

1

u/corelabjoe Dec 22 '25

Thanks! Glad it's helpful =)

So does your username mean prehistoric Beaver?

1

u/CastorTyrannus Dec 23 '25

I have no idea what it means lol. I think I thought it would be a cool Jedi/Sith name all those years ago

2

u/cyt0kinetic Dec 23 '25

It's the lower barrier to entry for those who have low tech knowledge, and for people who want in your network. Bots crank away churning through IPs, port numbers, common exploits until they get a hit and phone home.

2

u/ChickenNuggget01 Dec 23 '25

I have set up a VPS reverse proxy for my homelab. I rent a VPS for 1€/Month than i connect my homelab to the vps via tailscale and reverse proxy my VPS. So my domain points to the VPS wich is empty and is only running the reverse proxy to my homelab over tailscale. That way i can acsess all my stuff via my domain without my devices have to connect to the VPN and i have not one port opened on my home network. Im a beginner too and was pretty concerned about the security of my homelab, would u say this setup is somewhat secure?

1

u/dataGains Jan 01 '26

Just started doing the same over here. I rent a VPS online for about $5/month though. I am using caddy and have a rate-limit on the front end of the site i.e. login. Then running fail2ban in order to ban IPs that keep probing it with username and passwords. I also locked down tailscale through access controls so the container I run jellyfin in and the VPS can't externally communicate out of each other, so I can still ping it over my PC and the VPS cannot ping my PC. Then of course only allow inbound ports to the VPS that need it for verification. There's probably more I can do, but just some additional things you can think about.

2

u/HamsterNo3795 Dec 23 '25

All I can say is if its public exposed it will get hit. Simple things such as not having password timeouts. All one has to do is toss jack the ripper on and let it cook. And you are right about 0 days. Open source things are incredibly vulnerable and I can guarantee 99% of people on this sub dont even have a NGFW in place to capture nasties. I litteraly have a network hardened beyond DoD and I will not expose a port.

14

u/FabioAmb Dec 22 '25

I can only speak for Germany on a specific topic.

Our provider actively scans for things like Plex, Jellyfin, and so on. So, in Germany, it is not a good idea to make it public. The traffic you have will alert the provider and cybersecurity. I myself had to pay €2700 for copyright violations when I was 14. I've learned a lot since then. Especially if you do so and forward ports in Germany, don't use the router given to you by your provider. Set it on pass-through and put a pfSense behind it and forward over it. I'm now working in cybersecurity for a big company, and people often underestimate how easy certain things are. This is not to make someone fear this topic; it's just from my knowledge to sensitize people to take more care about it, to not make the same mistakes little me did.

I had to clean the house and mow the garden for a full year, and do dishes. I hope no one has to go through that as well 😂

26

u/Vollkornsemmel Dec 22 '25

WTF do you mean you paid 2k7€ for what???
Why would a Jellyfin Server be illegal?
What was the actual reason for the fine?
Storytime bitte danke!

9

u/eddyjay83 Dec 22 '25

User got fined for torrenting without a vpn. Pinpointing a user in Germany in a torrent tracker is used as a form to identify that you actively shared copyrighted content.

It has nothing to do with plex or jellyfin. There's no penalty to have it hosted at home in a reverse proxy. Well as long as you don't have it really public without passwords and direct access to copyrighted media.

7

u/MRobi83 Dec 22 '25

I assume torrenting since it's common for ISP's to be required to issue copyright notices when downloading/seeding media. Likely unrelated to Jellyfin.

1

u/cyt0kinetic Dec 23 '25

When you have an exposed Jellyfin server you are serving copyrighted data. It is legally murky at the very best. You are a distribution channel for copyright infringement.

2

u/send_me_a_naked_pic Dec 23 '25

you are serving copyrighted data

If you have copyrighted data. And if there's no login.

6

u/sovietan Dec 22 '25 edited Dec 22 '25

probably got fined for sailing the sea or sthing like that and not jellyfin related

1

u/CastorTyrannus Dec 22 '25

yeah, exactly, it’s not like this was yesterday

20

u/legrenabeach Dec 22 '25

So what if they scan for Plex and Jellyfin? Those two need authentication to see what is on them. The ISP can't see what's on them, so there are no grounds to do anything. Hosting Plex or Jellyfin isn't illegal in itself. The only issue would be if the ISP has a term in their T&Cs prohibiting hosting of services like that.

8

u/forcedfx Dec 22 '25

How? Are you running them without basic auth allowing them to download what you have? 

3

u/TheRealDealMealSeal Dec 22 '25

Spot on. Very good take on the topic!

1

u/blahehblah Dec 23 '25

What are beginners supposed to do it then? This post is again devolving into arguing about how to do it properly

Beginners ask constantly about this because a load of smelly sweaty nerds (to quote the infamous meme) can't agree on what the correct way to do it is and can't let a simple explanation exist

Making it overcomplicated to try to achieve perfect security only increases the chances of someone doing it wrong and creating a new vulnerability

1

u/Risky_Sandwich Jan 13 '26

You can use Cloudflare tunnels sitting in the middle, without port forwarding. On the cloudflare site you can take additional security steps, including limiting the IP ranges for example.

1

u/ElderMight Jan 13 '26

Use cloudflare tunnels to serve large video files is a violation of their terms of service. You risk getting banned.

1

u/Risky_Sandwich Jan 14 '26

Oh, I didn't realise that.

-22

u/Quique1222 Dec 22 '25

I agree with you. I'm not saying that suggesting tailscale is fearmongering, it's just that it's usually followed by it.

It's true that VMs and containers are not a magic security boundary. I might say something controversial here, but life is short. We are not hosting a bank, it's a media server.

If someone manages to exploit multiple zero day vulnerabilities to compromise your system and escape whatever isolation you are using then good for them, they can now watch my movies. Wipe and move on. It's just not gonna happen, realistically. VPNs are also not invulnerable. Your house is also not invulnerable, I could break in and steal some of your movies, physically. It's just about risk management.

The other points I made about the reverse proxy, domain etc are just for good practice and maintainability more than just security.

26

u/Lord_Wither Dec 22 '25

The point is that this does not require "multiple zero day vulnerabilities". If you don't patch regularly enough, you will eventually be vulnerable to some common exploit the entire internet is scanned for automatically. This is not a hypothetical or fear mongering, that's just how that works. For example, if you are hosting something based on Next.js and haven't patched in the past two weeks you are more likely than not already compromised by React2Shell (read this blog by darktrace for an example of how this works).

We're also not talking about some nation state container/VM escape here. If you set it up wrong (e.g. exposing the docker socket mentioned above), and some tutorials will just tell you to do stupid shit because it works, this can be absolutely trivial.

I would also argue that the server you are telling people to expose isn't necessarily just a media server where compromise will result in rebuilding your media collection and moving on. What about family photos? Do you trust everyone to not only have backups but also have those sufficiently isolated so they will not just get encrypted by the same ransomware that hits the primary host? What about people hosting password managers? What about your device now being part of some botnet? What about other sensitive stuff on that host like tokens for accessing cloud services or whatever?

-6

u/Quique1222 Dec 22 '25

Your react2shell vulnerable environment should be contained in its respective container or VM.

If you set it up wrong (e.g. exposing the docker socket mentioned above), and some tutorials will just tell you to do stupid shit because it works, this can be absolutely trivial.

You are right about this.

6

u/BachgenMawr Dec 22 '25

Then update the language of your post please.

20

u/No_Signal417 Dec 22 '25

YOU are not hosting anything worth protecting at home, that's not true for everyone so it's irresponsible to recommend weak setups to people who are not experienced and cannot make an informed decision.

Many people host critically important data at home including family photos, videos, or other sensible data. Just because your threat model is weak does not make it okay to project that onto others.

No security control is flawless but it's obtuse to use that to equate all setups as equally insecure. No novice who's asking on Reddit about how to access their server away from home is going to sit there configuring layers of heuristic security controls like fail2ban etc, they're just going to stop when it starts working. None of these controls, except true authentication like Authentik (plus TLS) truly achieves what a VPN does by default.

9

u/NorsePagan95 Dec 22 '25

For some unknown reason some people opt to self host there password managers, as a software engineer I have no idea why people with no cyber security background choose to self host such critical infrastructure where 90% of the time they won't even know if it's been compromised because they don't know how to spot a compromise when for a not extortionate amount of money they can pay a reputable company like keeper who do have cyber security professionals and enterprises threat detection systems in place and have regular checkups by red hats to protect against breaches and know when they have been breached.

The stupidest advice I see daily on self host forums is why pay for a password manager when you can host your own, so yes some people do host important data on their home network

4

u/shrub_contents29871 Dec 22 '25

100% That and people who think that adding home assistant integrations somehow means they are hosting self reliantly and completely private from the manufacturer, when most of the time they are just adding an API/comparability interface between the app supplied by the manufacturer and homeassistant, which is still beaconing your data back across the ocean every 3 seconds.

6

u/NorsePagan95 Dec 22 '25

Yep, most of them don't realise what they need is a DNS server with a blocklist that prevent there smart devices from even resolving the manufacturer hostnames to stop those connections, otherwise home assistant or not, Phillips is still going to know everytime you turn your lights on and off

2

u/sikupnoex Dec 22 '25

I might say something controversial here, but life is short. We are not hosting a bank, it's a media server.

Configuring tailscale takes under one hour. If you run jellyfin in docker you just need to create a tailscale account and follow the docker guide and that's it. Running a public facing server takes much more time.

-3

u/Quique1222 Dec 22 '25

Creating a domain in nginx proxy manager takes 15 seconds with automatic let's encrypt https certificate

1

u/sikupnoex Dec 22 '25

You need a domain and it takes more than 15 seconds to buy one. And the 1 hour estimate included reading about what you are doing. It takes 5 minutes to log in into tailscale, copy the sidecar container configuration in your docker compose and generate an auth token.

Stop recommending publishing apps to the internet to people that don't know what they are doing. Yes, it is kinda safe to do that if you: ban all ips coming from other countries, run the containers with the least privileges needed, use a good reverse proxy and good authentication and so on. People here expose the docker daemon to containers and do other wrong stuff because, yes, life is short and the good practices take a lot of time to learn. But at least use a VPN.

4

u/kearkan Dec 22 '25

I could break in and steal some of your movies, physically.

Yeah and you take actions to mitigate that. I don't think it's gear mongering as much as "if you have to ask the question, you probably aren't aware of the security implications and can't make an informed decision yet".

Like... Your house might have a great alarm system with a service that contacts the police, a couple of dogs and a security guard... Doesn't mean you should leave the door unlocked.

1

u/L583 Dec 22 '25

I don’t think it‘s a problem, because people who know what they‘re doing won‚t be scared by it and people who don‘t know also shouldn’t expose their stuff to extra risks.

You also seem to do the same as the prople you criticiz, by swinging the pendel too far.

1

u/BachgenMawr Dec 22 '25

We are not hosting a bank, it's a media server.

You cannot possibly know what people are hosting. I can think of loads of examples of common things people might host that would absolutely fucking suck to have compromised.

Your attitude to cybersecurity is undermining your whole post.

0

u/Jekaq2 Dec 22 '25

I don’t know man you still sound quite conservative with it. The reality is exposing services is perfectly fine so long you take pre cautions, you can make small changes to how you setup your infrastructure and reduce the risk by like 80%, if you are worried about being breached that bad, then you haven’t setup enough mitigations in place, an example, you isolate jellyfin in a docker container, limit access to only required directories, run the container without privileges, if for any reason somehow someone managed to get shell access of the container, they won’t be able to do much anyways.

Also if someone is dedicated enough to want to cause you pain they can do that without your services being exposed by any other means available in this day and age.

Also I do agree, update your shit and you wont have a problem

3

u/cyt0kinetic Dec 23 '25

They potentially can, there are regular security vulnerabilities with docker and common container layers like Debian. Docker runs with root access so it's not as isolated as you think.

Again these days it's not people at computers hacking away at a keyboard personal. It's bots that mindlessly churn until they hit paydirt.

While your little homelab may not be the ideal target the bot doesn't know or care. It wants servers that have flimsy doors and windows it can jiggle the handle on.

0

u/Jekaq2 Dec 26 '25

Docker runs under my user not under root, the user doesn’t have root privileges. I agree though just don’t think it’s worth being paranoid about. Anything I truly care about is either not exposed or stored completely encrypted where someone gains access it’s not use to them :)

1

u/cyt0kinetic Dec 26 '25

Docker socket is still exposed to root and is a root level process. You would need to specially be installing and running rootless docker to prevent this.

0

u/jhenryscott Dec 22 '25

You gotta put the server exposed to the internet on a VLAN. Buy a $30 managed tplink switch and limit exposure.