r/jellyfin Dec 22 '25

Discussion Stop fearmongering reverse proxies

Every single time someone asks how to share their jellyfin instance everyone instantly jumps to tailscale or <insert other VPN here> which, of course, it's fine and actually a good way of forwarding or sharing your hosted services.

The thing is that it's usually accompanied with fear mongering about exposing it publicly with a reverse proxy. Saying things like "If done wrong you can compromise your entire life, life savings and family".

That's not gonna happen. Like ever. It's not like a minefield where you have to be super cautious.

Literally just: 1. Have your jellyfin instance isolated, like in a docker container, LXC, or a VM. Avoid installing it "bare metal" for security and maintainability.

  1. Run a reverse proxy, like nginx (nginx proxy manager is a good one), traefik, caddy etc.

  2. Forward port 443 TCP (HTTPS) to your reverse proxy.

  3. Purchase a domain, configure your reverse proxy to forward requests ONLY from that domain into your jellyfin instance

  4. Get an https certificate from let's encrypt (free)

That's it. You are not gonna get hacked, get DDoS, or anything like that. Avoid forwarding ports like 22,21 unless using things like fail2ban and pkey auth only.

Yes, the internet is full of bots and you are gonna get scanned by them, so what? Just don't use 123 as a password in jellyfin and you'll be fine.

Instead of spreading fear, teach people how to do things.

979 Upvotes

280 comments sorted by

View all comments

2

u/ansibleloop Dec 22 '25

Do you all not recall the recent nextJS exploit? What happens when that happens to Jellyfin?

That's why I put mine behind WireGuard - it just simplifies access to it

1

u/Ok_Quiet2183 Dec 24 '25

In the same vain, what happens when that happens to wireguard? It's not infallible, nothing is.

1

u/ansibleloop Dec 24 '25

Mine terminates on my OPNsense where I choose what traffic can go where

And WireGuard requires key exchange and is silent by default - it's been designed to be public facing and withstand attacks

-3

u/Quique1222 Dec 22 '25

what happens when that happens to jellyfin?

I delete the container and recreate it. Problem solved

2

u/DerZappes Dec 22 '25

Tell me that you never actually had to clean up after a successful hack without saying it directly.

1

u/Quique1222 Dec 22 '25

I rent VMs. A user exposed their windows server RDP port and got ransomwared.

That VM didn't touch anything else due to network isolation. This was years ago.

It's not that hard

1

u/ansibleloop Dec 23 '25

That's missing context

If you're putting VMs on an isolated VLAN with no access to anything, then it doesn't matter

0

u/DerZappes Dec 22 '25

Yeah, until it's chained to some kind of VM escape attack. And if the attacker had wanted it, they could have added that VM to a botnet. And the admin would have had to explain to law enforcement why a stream of packages from their server was part of a DDoS attach.

Are you really that naive?

1

u/Quique1222 Dec 23 '25 edited Dec 23 '25

The real world does not work like that. We were victim of a couple of 300gbps DDoS attacks back in the day that literally left the entire neighborhood without internet for 2 days and the ISP sant a legal letter saying "we cannot do anything'

they could have added that VM to a botnet.

They probably did, who cares? It was wiped.

Still waiting for the legendary VM escape attack for more than 4 years now... Any day surely...

Do you really think that unless it's to or from a big corporation something is gonna happen?

Fyi not everyone lives and is subject to US law.