I already host multiple services via caddy as my reverse proxy. Jellyfin, I am worried about authentication. How do you secure it?

  • softcat
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    10
    ·
    7 days ago

    CloudFlare tunnel with Zero Trust, plus their bot and abuse blocking. Users can get in with the right oauth, plus only allowed from the countries I know they’re in. Then just their username and password on jellyfin.

      • softcat
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        1
        ·
        edit-2
        7 days ago

        They prohibit large amounts of media being streamed, and they reserve the right to suspend or terminate accounts for it. Multiple years in, that has not happened.

        Edit: here, you can read https://blog.cloudflare.com/updated-tos/

        • merthyr1831@lemmy.ml
          link
          fedilink
          English
          arrow-up
          3
          ·
          7 days ago

          Cloudflare is known for being unreliable with how and when it enforces the ToS (especially for paying customers!). Just because they haven’t cracked down on everyone doesn’t mean they won’t arbitrarily pick out your account from thousands of others just to slap a ban on. There’s inherent risk to it

      • Dave@lemmy.nz
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        3
        ·
        7 days ago

        No, they removed that clause some 2 or 3 years back.

    • ftbd@feddit.org
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      7 days ago

      I hate the cloudflare stuff making me do captchas or outright denying me with a burning passion. My fault for committing the heinous crime of using a VPN!

      • softcat
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        2
        ·
        7 days ago

        Oh no they’ll see I’m watching TNG

      • softcat
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        7 days ago

        My users aren’t going to figure that out.

        • rice@lemmy.org
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          7 days ago

          they don’t have to figure it out, you are the one running it

          • softcat
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            1
            ·
            7 days ago

            They’d have to connect to it, and possibly reconnect. That aspect is the issue.