DefederateLemmyMl

  • Gen𝕏
  • Engineer ⚙
  • Techie 💻
  • Self hoster 🖧
  • Linux user 🐧
  • Ukraine supporter 🇺🇦
  • Pro science 💉
  • Dutch speaker
  • 0 Posts
  • 10 Comments
Joined 2 years ago
cake
Cake day: August 8th, 2023

help-circle
  • Oh, by the way, road works, 80km/h. Aaaand you’re free again! Have f- oh no, roadworks again, 80 pls. Ok done. Now you can really hit the gas! Joke, roadworks again haha, 80! Finally done, now we promise we don’t have roadworks anymore, enjoy! Aaaand welcome to the Netherlands, 100 please.

    If that isn’t the most accurate description of driving through Germany, I don’t know what is :D







  • What I used to do was: I put jellyfin behind an nginx reverse proxy, on a separate vhost (so on a unique domain). Then I added basic authentication (a htpasswd file) with an unguessable password on the whole domain. Then I added geoip firewall rules so that port 443 was only reachable from the country I was in. I live in small country, so this significantly limits exposure.

    Downside of this approach: basic auth is annoying. The jellyfin client doesn’t like it … so I had to use a browser to stream.

    Nowadays, I put all my services behind a wireguard VPN and I expose nothing else. Only issue I’ve had is when I was on vacation in a bnb and they used the same IP range as my home network :-|