• 1 Post
  • 14 Comments
Joined 3 months ago
cake
Cake day: May 7th, 2026

help-circle

  • I use prowlarr to manage my sources, and that container in its entirety is backed up, so if the whole unit were to die simultaneously. I would lose all content, but retain all setup.

    The key part for my recovery method is my Arr stack (prowlarr, sonarr, radarr). Loading up sonarr/radarr shows the entire catalogue of content; and highlights/ can search for any that are missing; so once the media drives been replaced its as easy as pressing a button.

    If you’re just getting started. I’d recommend checking out yams.media. it provides a strong starting stack including arr containers, vpn setup etc… Its a strong foundation for a successful media server. I believe it also has media separated from app data, which makes a setup like this easy to achieve.





  • Glad to hear others are doing the same! I actually started out with authentik, but just could not get emails to play ball. It was no doubt something I was doing wrong though, as I remember finding nobody else with the same issues when trawling support forums, which is why I ultimately jumped to keycloak.

    I definitely prefer the customisation in authentik to keycloak. I have to use a git project for compiling my keycloak ‘theme’, that allows basic UI changes like logos. Safe to say the theme hasn’t changed since it was first setup.


  • Its pretty rudimentary reverse proxy via VPN setup. Just Client - VPS - server, using a separate wireguard connection for each service for a zero trust setup.

    I’m using an oldish github project called selfhosted-gateway for setup. It hasn’t been updated in some time, but I’m still using it as the overhead on the VPS side is tiny compared to any other solution (like netbird for example) and honestly, it just works.

    The setup is pretty simple, a docker container for the wireguard setup Is spun up on both sides creating a wireguard tunnel, with the home server container running nginx, that will expose the relevant container depending on config. The VPS side uses caddy which automatically handles TLS too, so its a quick and easy implementation once you get your head around it.


  • Using ironwolf pros for the HDD space, they’re enterprise grade high storage SATA HDDs that go as high as 32TB these days I believe.

    If you use this approach, its important to make note of the workload rate of the drive you’re looking at. Anything marked as a NAS drive should be designed for 24/7 operation, whereas standard HDDs will likely crap out far sooner, but connectivity wise, the only important step is to ensure the drive is SATA rather than SAS connection, otherwise you’ll end up fiddling with PCI-e adapters which is wasteful IMO.

    I’ve not built any redundancy into the media drives. Opting for maximum space possible instead. I don’t consider any of the content to be irreplaceable. Config for the Arr stack (Sonarr, Radar etc…) is held on my RAID NVMes that also has non local backups, so theoretically, when a media drive is lost, any content can be redownloaded onto a replacement drive with little effort.


  • Sure, I’d be more than happy to! It’s a home server build that started life as a gaming pc, so it’s not a rack setup in any stretch of the imagination. I’m not at home currently so can’t give exact specs offhand, but the setup is essentially:

    OS: Ubuntu running on 256gb NVMe (not backed up I just replace if/when it fails)

    Jellyfin/Navidrome Media: 3 SATA HDDs totalling ~60TB (2 x 15TBs, 1 30TB, no RAID, no backup. I call this my replaceable media, as I can simply redownload if a drive fails)

    Config/compose files and ‘irreplacable’ data stores: 2 x 4TB NVMe (RAID 1, 7 rolling daily backups, 4 rolling weekly to a much more modest machine on the same network. This includes configuration/database etc. for jellyfin)

    Entry points are all handled via a single VPS using a wire guard reverse proxy. So I’m using domain based access for all services I’m running. The only one that seems to struggle is Navidrome, which can lose sync. But jellyfin works flawlessly with this setup.

    Off the top of my head, I believe the specs are something like:

    • 128GB DDR5 RAM (bought pre AI boom thankfully)
    • AMD Ryzen 7 9800x3d
    • Nvidia rtx 4080
    • 2 x fanxiang 4TB NVMe
    • 1 x Kingston(?) 256GB NVMe
    • 2 X Seagate ironwolf pro 15TB
    • 1 x Seagate ironwolf pro 30TB

    The case itself is a fractal meshify 2 XL. I got it due to the lack of RGB way back when, but it fits everything listed quite comfortably, as well as an AIO cooling system for the CPU.

    If you’re looking for large storage solutions, NAS servers definitely fit the bill, and make setting up RAID a breeze. But you can quite easily find large scale SATA based drives, which fit into most mid to large cases, commercial or personal. My current build is nearly at its limit now (I think there’s a single available sata port left… Maybe another M2, can’t recall), so going forward I will likely invest in a decent NAS, but I’ve never felt the need for a rack solution if I’m honest.

    Another thing worth mentioning is that the server is not quiet. The ironwolf drives in particular can drum up a fair bit of noise when busy. I’ve got the server setup in my home office, so it’s no issue personally. But it would definitely cause me sleep issues if it were in my bedroom.


  • The total space used is somewhere in the region of 20tb. I recently expanded to it by another 30tb by adding a seagate ironwolf pro hard drive to the build.

    It’s overkill in all honesty, and I don’t have a raid setup/backups on any of my jellyfin drives, I figure none of it is irreplacable, and opted for maximum space possible over redundancy. But one day drives will inevitably fail, and a lot of content will be lost. I also have a pretty hands off style with the content added, so there’s no doubt plenty of space I could reclaim if I were to more actively manage the content.

    My servers configuration files as well as irreplacable content like immich data etc. are all running on much more modestly sized (but just as expensive) 4TB NVMes, which are in a basic RAID 1 setup. The server itself is running on a 256gb NVMe, with no consideration for redundancy. If the OS dies, I’ll just reformat, and spin up services using the compose files stored in the RAID setup.

    Glad to hear you’re starting them on the foss path young 😁 Mac users are a tough nut to crack in my experience! They’re usually very invested in the apple ecosystem, and it makes finding an alternative for their everyday usage a busy task to say the least!



  • You should be able to decrypt the messages if you still have the old device to verify the new connection, or if you saved the encryption key that’s setup when you first login to the account.

    Appreciate it’s not as simple as logging in, because that’s the point of separating the encryption key from login creds in the first place. Even if your accounts credentials are compromised, previous messages aren’t, and any future messages from the unverified device are flagged as suspicious.

    XMPP has some good options. I tried utilising mov.im servers, which claims to have E2EE.(using conversations app to connect) Its very user friendly and just works. Though, I’m not sure how the encryption works on there as I’d already got my users used to element, and saw no reason to move (IMO its still a better option than signal due to the self hosting capabilities, but depends on what level of solution you’re after)