In their comments to a recent post that I made, asking people to share their torrenting ratios, some folks were talking about how they have setup media servers for their parents. This sounded really cool and I would like to do the same thing for my family.
I simply mount my torrenting drives with sshfs and consume media with mpv, because I don’t need anything else. But for my technologically less inclined family members, I guess setting up something with a GUI would be kind and nice.
I am torrenting on a VPN router, behind which there is a switch that only switches a specific port - which I rotate regularly for safety - to a public facing router, so that I can ssh into my home network.
Questions:
- I have no experience with or knowledge of these to me fancy sounding GUI projects. For instance, do my family members create accounts that I then approve? Do I need to install and setup something on their endpoints (for instance, to configure which port to use, etc.) or is it simple enough for the layperson to do this themselves?
- Will the fancy stuff accept and be accessible with port forwarding from my public facing router to my VPN router and then into my torrenting rig just like my ssh server does or am I going to have to set this up directly connected to the public facing router?
Please give me your most straightforward recommendations! 🥰
Kodi - compiled from source on whatever hardware suits your needs. I use an old laptop (busted screen) with an external HD.
Jellyfin and Plex don’t offer as many features. I used Plex for a long time but ultimately it’s untrustable proprietary trash. And, when I last tried Jellyfin, it doesn’t do games, IPTV, music, youtube, other addons, etc. It also seemed kind of buggy/slow.
(I just use qbittorent for torrenting.)
So my family and friends could reach my Kodi server with their clients? Just open/forward a port?
*arr stack with plex/jellyfin. I have my stack on a pi hooked into a NAS running plex (jellyfin soon if plex keeps up the shitty updates). Lookup some Trash guides. It’s much simpler than it appears.
Look up yams (yet another media server) still a little complicated but there’sa fair bit of docs and a helpful dev and community
I use proxmox, all the *arrs are in one docker host running as an LXC. So the stack is: Proxmox> LXC> Docker Compose> Gluetun> *arrs.
I run it this way because ease of set up, as a normie Nix scares me in ways YAML doesn’t. It’s one big compose file, everything talks to each other using the virtual docker network. Update is one button. It just works™.
I have an Lxc running jellyfin as a front end, an Audiobookshelf Lxc, one running Seerr. A bunch of other front end service lxcs (Immich, Homarr, what have you). All the front ends have Tailscale installed for remote access.
Family and friends have a pi acting as an access point to Tailscale. Then it’s the nginx, pihole combo for nice URLs and HTTPS. Nothing is on the open web, it’s all behind tailscale.
I started on just a pi running docker running everything for my fiancée and I, then it just kinda grew. I originally just wanted to block ads.
Trash-guides is your friend for *arr set up. Dockstarter is your friend for basic installation of *arrs. Thousands of guides on YouTube to get you started.
Are you just using Proxmox for LXCs? In that case why use Proxmox + LXCs + Docker, instead of say, bare metal Debian + Docker, without the extra LXC middle layer?
Medusa to auto download TV shows to a seedbox, Synology to store it, Nvidia shield to play using plex.
Look in the Arr stack and combine it with jellyfin. It is fairly easy to setup with docker.
It’s not fairly easy :/ … Specially if you want something that works flawlessly over time !
Maybe for most IT workers, yes it’s easy… But if you are starting out right with 0 knowledge with docker, networking, VPN, gluetun, multi-arch player (tvOS, android TV, Linux, Android, MacOS, iOS), linux, private tracker, exposing your media securely, arr stack configuration… You name it !
Naaah it’s not fairly easy if you’re just starting out !
If you really want to get in to media sharing. I think it is a good idea to learn at least some of the basics about Linux and docker (with compose). It will make your life a load easier. Forget about the client for just a bit. Most of the time that’s just a app you install and login to. But without the server side done. It is fairly useless.
If you truly wish to not look in to that. While I am not a fan of doing it that way… You can setup a read only smb share with the media files and let people access it over a VPN.
The 3 basic things I would get started with is Linux. Docker with compose and a VPN. VPN can be tied in using docker. Look at wg-easy for that.
I wouldn’t mess with any of the other things you mentioned yet. Also if you need help with any of those things I mentioned. Feel free to ask for help with it. Their is a great community willing to help.
I currently am set up with Jellyfin as the GUI which gives your media library a Netflix-like front end. And I use Tailscale as a VPN to access media off my home network. You can send an invite link to your family to join your Tailscale network, and they create an account there. With Jellyfin, I just have everyone use one main account, but maybe there’s some other benefits to using separate Jellyfin accounts that I’m not aware of. Overall it’s pretty straightforward to setup in my opinion. Both those apps have Apple TV apps, which is important because that’s what my family uses to watch their tv already.
I use jellyseer with jellyfin so that my family can make requests for movies/shows thru another netflix-style GUI rather than messaging me constantly about whatever they wanna watch lol. You can set it up with auto approval if you trust them to manage shit, and they can just download stuff on demand without you having to be involved at all. Really great stack if you wanna be less involved in the whole process
maybe there’s some other benefits to using separate Jellyfin accounts that I’m not aware of
Watch history, parental controls, library access controls, etc.
Parental controls are the biggest reason for me and my use.
I actually just made a little diagram for myself to help with troubleshooting. Hopefully it’s helpful for others wanting to automate their movie/show accumulation. I made it a little simpler than the original by taking out the music part of it (lmk if I should share the full thing).

For context, the green boxes are the main server, the grey boxes are running on a Raspberry Pi that’s behind an always-on VPN (Mullvad). You search for movies/shows with Sonarr/Radarr, which browses torrent trackers with Prowlarr, and sends the torrent to QBittorrent. QBT then moves downloaded files to the Seeding directory, where they’re automatically copied into the media directory. Jellyfin then automatically scans for new content and fetches Metadata to make it look pretty.
Your family wouldn’t need to do any fancy port stuff, you’d just need to create accounts on your Jellyfin server and have them log in. All you’d need to port forward is a port for Jellyfin.
edit: I read over the post again and you could definitely take out the whole automated part with Sonarr/Radarr/Prowlarr and just manually search for torrents and the end experience would be the same for your family, just a little more tedious if you get a lot of requests
That’s a really cool setup! And the diagram too! How did you draw that? XD
Also, a stupid question, since the Jellyfin connection will be going in and out through my public router, unencrypted, won’t media consumption through it look like downloading or the likes? Jellyfin sessions aren’t looked for by the powers that be? XD
Thanks! I used LibreOffice Draw so it was pretty easy to make.
To be honest, it probably would be best to use a VPN to get into your home network to watch the content if you wanna be extra-safe. I kind of just run under the assumption that I can always claim it’s my media since it’s all downloaded on a separate connection. I suppose if I ever get a notice of some sort, I’ll switch over to a VPN, but currently it’s working fine for me to have it ran through a domain and makes it a lot easier for family members to use.
Jellyfin + NetBird.
NetBird can be used either as a VPN like tailscale (but FOSS and self-host able) or as a reverse proxy. I have it on a VPS so I don’t have to point any traffic directly to my home network.
Is Jellyfin running on the VPS too or only NetBird? Sorry for the stupid question. 🙏
I just saw that they discourage forwarding ports directly over the internet, which, I guess, is fair, since we’re not using ssh or other encrypted protocols here - although if we are able to use https, then I don’t quite follow…
So! I’m considering giving your setup a try! Is their free plan sufficient? Is the layout then something like:
My mom’s client ===> VPS (NetBird, I guess any port forwarding and/or routing happens here?) ===> My Jellyfin server + storage
? 😊
I have two servers. There’s the VPS hosted by Hetzner, and then I have my own home server sitting on a shelf in my hallway. The home server has all of my data and private apps, like Jellyfin, Navidrome, Audiobookshelf, etc. Then I pipe traffic via Netbird on my Hetzner VPS to my home server. Since Netbird goes via Wireguard, it’s a VPN connection and I don’t expose anything to the public.
The one exception to this are game servers that I host. Those are pointed directly to my home network, and I only give that out to friends. Still, it’s a possible attack surface.
I self-host Netbird, so I’m not familiar with how they work as a host. Netbird when used as a reverse proxy also handles all the SSL certificates and whatnot. It’s basically a front for Traefik, with convenient VPN tunneling built in.
I started out with Jellyfin. However, when it came to opening up the media server to friends and family, I had to roll up an instance of Plex (and eventually bought their pass).
Plex simply requires less fiddling to get things to acceptable state, especially for users outside your home network. Their guides are very straightforward.
Moreover, the apps are more polished and reliable, especially for TV platforms. Fortunately, some third party polished apps like Infuse and Plezy also support Jellyfin should you choose to switch servers later (I know that I do).
Though the reason Plex is convenient, is also its most ickiest part. I hate that Plex owns the middle layer which handles authentication and other orchestration. That same piece of infrastructure can also bring down your media server if it goes down (though it can be partially mitigated by disabling authentication for devices on LAN so that devices on your home network can still access your media).
I eventually plan to move everyone to Jellyfin, but I don’t think that’s happening anytime soon as the apps are not there yet, and I will also have to redo parts of my infrastructure.
Infuse is paid but only requires a SMB share somewhere on your LAN, no special server to fiddle with. Easiest of the bunch, especially if you have an appleTV.
I use Emby. It’s set up so I can use it when I’m on vacation through a domain.
I mostly use Emby because I can get their app on my tv. It just seems easier than whatever Jellyfin has.
On my Emby server I can make accounts, give those accounts passwords or reset the passwords. People can also choose a 4 number pin so they don’t have to write a password whenever they need to login.
I don’t really know anything about the stuff you described in your setup, but I don’t imagine it’s different from any other setup.
I just use Plex. It’s super easy. The users just have to create a Plex account then you can invite them to have access to your server and media.
+1. I bought the lifetime pass 8 or so years ago, and it’s served me pretty well since.
+1 for plex as “it just works”. No VPNs or reverse proxies or half baked apps (if one exists).




