How to self-host a Jellyfin server for your household
Watch your movies and shows anywhere — free, no account needed, apps on every device. Cresdock runs it on a server you own, from a catalogue, with no Docker and no reverse proxy to configure.
This is Cresdock's suggested starting point in its category — the one to pick if you have no reason to prefer another.
What Cresdock does for you with Jellyfin
Jellyfin owns its own first-run setup, so Cresdock locks that wizard to your IP address until you finish it. Nobody else can reach the box in the minute between the app starting and you claiming it.
Given its own web address, with its own login seeded in advance. Jellyfin can't live under a shared path, and apps like this are reached by clients that don't carry a browser session — so it gets a real password rather than being left open.
If your library lives on cloud storage rather than the server's own disk, this app can read it from there.
Gets its own web address (a subdomain, not a sub-path) so native phone, TV and streaming-box apps connect the same way they would to any Jellyfin server.
Exempt from the panel's login screen by design — a TV app can't carry a browser cookie, so Jellyfin's own account system runs instead.
Locked to the installing IP until its setup wizard is completed, then the lock lifts on its own — a stranger can't find and claim a freshly-installed server before you do.
Sonarr, Radarr and Lidarr can tell Jellyfin to look for new arrivals as soon as they land. The key that needs is made inside Jellyfin, after you've created your account there on first open — so there's none to hand over beforehand, and you finish that step yourself.
Install Jellyseerr and the people you share with can ask for things themselves, signing in with their Jellyfin accounts.
Why run Jellyfin yourself
Streaming services remove things. A film you paid to watch last year can simply stop being there, and nothing tells you in advance. Running your own means the library is whatever you put in it, and it stays.
It is also how you retire the streaming services that quietly remove things — one line in replacing cloud subscriptions, app by app.
What kind of server Jellyfin needs
A media server is the one category where the hardware matters. Direct play — where the app hands the file straight to your TV or phone — costs almost nothing, and 2 GB of memory is plenty. Converting on the fly for a device that can't play the original is what gets expensive; if you expect that often, a machine with hardware video support pays for itself immediately.
Cresdock itself is undemanding — it runs on a small rented server, an old desktop or a mini PC, on Ubuntu or Debian. Everything it installs shares that machine, so the honest question is not "will this app run" but "how much am I going to put on here in total".
Where to run Jellyfin
Jellyfin runs wherever Cresdock runs, and the choice is about the machine, not the app:
- At home, on hardware you already own. A mini PC, an old desktop or a NAS that can run Debian. Cresdock works behind a home router with no port forwarding and no domain, so Jellyfin is reachable on your own network first and from outside only if you choose.
- On a rented server. A small VPS is enough for most apps and is the usual answer when Jellyfin should be reachable from anywhere. The setup guide covers the specs and the one-command install.
- Through a provider that runs Cresdock. Hosting companies deploy Cresdock workspaces for their customers, so Jellyfin can come with a server you rent rather than one you set up — ask your provider, or see how providers offer it.
Installing Jellyfin
- Put Cresdock on a server
One line on any Ubuntu or Debian machine — a rented VPS, a spare PC, a home server. It sets itself up.
- Pick Jellyfin from the catalogue
Click Install. The panel pulls the image, writes the configuration, gets a certificate and starts it.
- Open it from your dashboard
Its address and any login details are on its card. Start, stop, update, roll back or remove it from the same place, any time.
What's left for you to do
Cresdock does not pretend to do the parts that are genuinely yours to decide. After it's running:
Open Jellyfin and create your account. Do this now: the first visitor becomes the owner.
Add a library and point it at /media — that is your media folder, and the only one Jellyfin can see
Your downloads are not in there, so a library aimed at them finds nothing. A library manager moves finished files across for you; without one, put what you want to watch into your media folder yourself
What this replaces
Doing it by hand means writing something like this, then keeping it working:
services:
jellyfin:
image: lscr.io/linuxserver/jellyfin:10.11.11ubu2404-ls42
restart: unless-stopped
ports:
- "8096:8096"
environment:
- PUID=1000
- PGID=1000
- TZ=Etc/UTC
volumes:
- ./jellyfin/config:/config
And that is the easy half. Still to do:
Install a reverse proxy and write a server block for it
Get a TLS certificate and set up automatic renewal
Create the folders above with the right ownership, or it will not start
Point a DNS record at the server, because Jellyfin cannot run under a shared path
Repeat all of it for the next app, and again on every server rebuild
On Cresdock, Jellyfin is one click and none of the above exists.
Common questions
Do I need to know Docker to run Jellyfin?
No. Cresdock installs Jellyfin in one click from its catalogue: it pulls the image, writes the configuration, gets an HTTPS certificate and starts it. Jellyfin runs its own first-time setup, and Cresdock locks that screen to your IP address until you have finished it.
What happens to my Jellyfin data when it updates?
Cresdock updates the Jellyfin image and leaves its stored data in place. Jellyfin keeps its own files in its own folder, which survives an update, a rebuild and a reinstall — and Cresdock never writes into it.
How is Jellyfin protected if it isn't behind the panel login?
It gets its own password, generated and set before it first starts, shown on its card in your dashboard. Apps end up here when they are reached by programs rather than a web browser, so a shared login can't be used.
Can someone else claim my Jellyfin before I do?
No. Its setup screen is locked to your IP address until you have finished it. This is the window that catches people out on a self-managed server.
Can my family use Jellyfin too?
Yes. Cresdock is built for sharing a server: each person you add gets their own space, with their own apps and their own folders. The free plan covers one person, and adding more is what Pro is for. Jellyfin also keeps its own accounts, so everyone signs in as themselves.
Can I run Jellyfin at home instead of on a VPS?
Yes. Cresdock runs on a mini PC, an old desktop or anything that boots Debian, behind a normal home router with no port forwarding, and Jellyfin is reachable on your own network first. A rented server is only needed when Jellyfin must be reachable from anywhere without a VPN.
Can I remove Jellyfin later?
Yes. Cresdock removes Jellyfin in one click, and asks whether to keep its configuration for a future reinstall. Nothing else you have installed is affected.
Looking for what Jellyfin itself can do? That lives in its own documentation — this page is only about running it.
Pairs well with: Jellyseerr · Kavita · how Jellyfin connects to your other apps
Before you start: where to rent a server · what it needs to run · Cresdock vs CasaOS