this post was submitted on 31 Mar 2025
211 points (98.2% liked)

Selfhosted

45371 readers
818 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I already host multiple services via caddy as my reverse proxy. Jellyfin, I am worried about authentication. How do you secure it?

you are viewing a single comment's thread
view the rest of the comments
[–] softcat -3 points 2 days ago (4 children)

CloudFlare tunnel with Zero Trust, plus their bot and abuse blocking. Users can get in with the right oauth, plus only allowed from the countries I know they're in. Then just their username and password on jellyfin.

[–] [email protected] 9 points 2 days ago (3 children)

Doesn't streaming media over a cloudflare tunnel/proxy violate their ToS

[–] softcat 2 points 2 days ago* (last edited 2 days ago) (1 children)

They prohibit large amounts of media being streamed, and they reserve the right to suspend or terminate accounts for it. Multiple years in, that has not happened.

Edit: here, you can read https://blog.cloudflare.com/updated-tos/

[–] [email protected] 3 points 2 days ago

Cloudflare is known for being unreliable with how and when it enforces the ToS (especially for paying customers!). Just because they haven't cracked down on everyone doesn't mean they won't arbitrarily pick out your account from thousands of others just to slap a ban on. There's inherent risk to it

[–] [email protected] 0 points 2 days ago

No, they removed that clause some 2 or 3 years back.

[–] [email protected] 5 points 2 days ago (1 children)

I hate the cloudflare stuff making me do captchas or outright denying me with a burning passion. My fault for committing the heinous crime of using a VPN!

[–] softcat -2 points 2 days ago
[–] [email protected] 1 points 2 days ago (2 children)

just run wireguard on the jelly server..

[–] [email protected] 1 points 2 days ago

Can't use double VPN on mobile.

[–] softcat 1 points 2 days ago (1 children)

My users aren't going to figure that out.

[–] [email protected] 0 points 2 days ago (1 children)

they don't have to figure it out, you are the one running it

[–] softcat 1 points 2 days ago

They'd have to connect to it, and possibly reconnect. That aspect is the issue.

[–] [email protected] 1 points 2 days ago* (last edited 2 days ago) (1 children)

Using cloudflare tunnels means nothing is encrypted and cloudflare sees all.

[–] softcat 0 points 2 days ago

Oh no they'll see I'm watching TNG