Improve very slow library scans on Jellyfin 10.11 / 12 on spinning media
from avidamoeba@lemmy.ca to selfhosted@lemmy.world on 30 Jul 18:17
https://lemmy.ca/post/68629264

I’ve been trying to upgrade from 10.10 to 10.11 for a while now, as the Android TV app keeps nagging me, and every attempt ended with impossibly long library scan times.

After some thorough investigation, it appeared that a Home Videos type collection causes unending scan (yet to be solved), but also that Jellyfin does a lot of writes to the config directory (either database or metadata or both). Mine’s on spinning media part of a ZFS pool. I tried a few performance tuning options, such as testing the config dir with recordsize (similar to block size) of 4K, 8K, 64K, 128K and library scans fell from 30-40 minutes down to 8-13min with 4K-64K. The ZFS tuning wiki suggest 64K recordsize with LZ4 compression for SQLite workloads such as Jellyfin. That seems to work as well as 4K and 8K but likely is faster when reading thumbnails and such.

Note that upgrading to 12-rc3, which is supposed to speed up library scans did not improve scan times for me. Optimizing config/database write speed did. I cross-checked the culprit by experimenting with moving the config dir to NVMe and RAM. Both of those got the scan times down to 8-9 minutes compared to the optimized spinning media’s 12-13.

So if you had upgraded (or about to) to 10.11 your library scans are (about to get) dog slow and your Jellyfin’s config dir resides on spinning media, optimize its write performance for SQLite.

#selfhosted

threaded - newest

czl@lemmy.dbzer0.com on 30 Jul 18:34 next collapse

Isn’t it ironic that you post this meme along with complex instructions to fixing a problem in jellyfin?

fuckwit_mcbumcrumble@lemmy.dbzer0.com on 30 Jul 18:49 next collapse

Also doesn’t jellyfin not support remote streaming?

LodeMike@lemmy.today on 30 Jul 18:50 next collapse

It’s a nonsensical statement. Jellyfin is accessed through a website. You’re responsible for routing to it.

fuckwit_mcbumcrumble@lemmy.dbzer0.com on 30 Jul 19:01 next collapse

It’s a very sensical statement. I’m not exposing a whole ass website on my own network just for remote viewing. With plex you don’t need to do that.

LodeMike@lemmy.today on 30 Jul 19:02 next collapse

Yes you do. It just does it for you including handling SSL.

fuckwit_mcbumcrumble@lemmy.dbzer0.com on 30 Jul 19:04 collapse

Inside the network you do, but not for remote access outside the network.

abcdqfr@lemmy.world on 30 Jul 19:24 next collapse

Let’scrypt and port forward. Sprinkle on some free ddns with a sync script/job to keep ddns pointing to your real public IP. Can even roll in some headscale if you’re feeling adventurous

MaggiWuerze@feddit.org on 30 Jul 21:01 collapse

Feeling adventurous is exactly what you need if you decide to expose Jellyfin to the Internet (a reverse proxy adds nothing to security)

Blue_Morpho@lemmy.world on 30 Jul 21:44 collapse

Jellyfin doesn’t open up your network unless you specifically allow remote access exactly like Plex. The only difference is Jellyfin doesn’t have the encrypted tunnel built in- you need to know it needs it and add it yourself.

Plex has had bugs that allowed remote access into your home’s Plex server. nvd.nist.gov/vuln/detail/CVE-2025-34158

GoatSynagogue@lemmy.world on 31 Jul 04:42 collapse

That poster specifically said if you open jellyfin up to the internet ……

MaggiWuerze@feddit.org on 31 Jul 06:13 next collapse

Reading comprehension and Jellyfin stanning don’t go well together

Blue_Morpho@lemmy.world on 31 Jul 13:01 collapse

He said an encrypted tunnel does nothing. I don’t even run Jellyfin but that statement is false.

MaggiWuerze@feddit.org on 31 Jul 15:06 collapse

An encrypted tunnel and a reverse proxy are two very different things. He (I) never talked about a tunnel and neither did the comment I (he) responded to

Blue_Morpho@lemmy.world on 01 Aug 01:53 collapse

The reason to run the reverse proxy with Jellyfin is for the encryption. It’s written in the documentation that way. It’s why I still run Plex. I never finished getting through their steps to get the reverse proxy setup for the encryption.

It’s like I said you use a car to go to work and you reply AKSUALLY a car runs on TIRES. The OP didn’t say CAR.

MaggiWuerze@feddit.org on 01 Aug 06:42 collapse

Having an https connection doesn’t do shit if the Backend is insecure. The issue with exposing Jellyfin are not man in the middle attacks, but badly managed access controls and unsecured endpoints.

Thede issues and the unwillingness of the devs to fix them because they are hellbent on keeping a maximum of client compatibility is what makes it hard to trust the overall security of the project.

That’s why basically everyone, including the devs, says to not do that and instead rely on a vpn to mitigate security risks.

Blue_Morpho@lemmy.world on 31 Jul 13:01 collapse

Which Plex does by default. He doesn’t understand that running Plex at home opens itself up to the Internet. I specifically referenced a CVE that let hackers into your home if you ran Plex.

His claim that securing Jellyfin with an encrypted tunnel does nothing is false.

GoatSynagogue@lemmy.world on 01 Aug 00:14 collapse

He never claimed that in the comment you replied to.

Plex doesn’t open a port to the internet at large, unsecured no less, like jellyfin does.

Blue_Morpho@lemmy.world on 01 Aug 01:48 collapse

You obviously don’t use Plex to claim it doesn’t need an open port for remote access:

…plex.tv/…/201543147-what-network-ports-do-i-need…

I already posted a CVE that allowed hackers access to a Plex server running at home.

GoatSynagogue@lemmy.world on 01 Aug 01:59 collapse

OK so you don’t understand networking, don’t understand how Plex works, don’t understand how that CVE does nothing of the sort, and have poor reading comprehension skills.

I’d hate to be your poor server.

Blue_Morpho@lemmy.world on 01 Aug 04:14 collapse

I quoted Plex documentation where it explains in detail that you need port 32400 OPEN for remote access. support.plex.tv/…/200289506-remote-access/

I linked the CVE but here is the plain language version because you didn’t read what I linked:

howtogeek.com/over-300k-plex-servers-are-still-vu…

"The flaw has been assigned a CVSS score of 10.0, the highest possible level of severity. This score indicates that the vulnerability can be exploited remotely over the internet, is easy to execute, and requires no authentication or interaction from the server’s owner. A successful attack could result in a total loss of confidentiality, integrity, and availability. An attacker could access, modify, or delete a user’s private media files, or even disable the entire Plex server. "

What the fuck is wrong with you?

GoatSynagogue@lemmy.world on 01 Aug 07:12 collapse

You clearly don’t understand how Plex and port forwarding work if you think that is in any way the same as opening a port to the Internet for everyone to hit jellyfin with zero security on it.

The CVE has been exploited zero times that we know of, and at worst they can delete your media files and Plex server. It’s never been reported of happening, and we have no idea how difficult it is to do - but because it hasn’t happened, it’s probably extremely hard and requires a chain of very unlikely things to have happened first.

ragebutt@lemmy.dbzer0.com on 30 Jul 19:31 collapse

Outside the network you still have to open your server to allow plex cloud to access it and potentially tunnel your traffic through plex.tv if a direct connection doesn’t work. This happens automatically but it does happen

With Jellyfin you just have to supply your own relay, like Tailscale or wireguard, which does require more setup but is completely free, means that you can stop your media traffic from being funneled through services that harvest your data (which plex absolutely does), and doesn’t go to shit if plex.tv goes down

chisel@piefed.social on 30 Jul 20:13 next collapse

You can do the exact same thing with Plex, you just don’t need to since automatic remote streaming is built in. In fact, the article’s solution is literally Tailscale.

You can also bypass plex authentication on any ip range you choose, so if you add your local network and plex’s auth service goes down, it’s no big deal.

ragebutt@lemmy.dbzer0.com on 30 Jul 21:39 collapse

Yeah obviously, you can also use Tailscale to tunnel to whatever service you want (including just to the server itself). But if you’re bothering to override remote plex access with all this I don’t know why you wouldn’t just pick the option that doesn’t harvest your data and increasingly treat its customers as hostile

fuckwit_mcbumcrumble@lemmy.dbzer0.com on 30 Jul 22:16 collapse

This happens automatically but it does happen

And that’s the key, it happens automatically and it just works. With jellyfin you have to expose the web server to the internet, or point an app to something else exposed on the internet. With plex you don’t. If you don’t want to (or can’t) a direct connection from your server to their servers, then their servers to your device is established. No VPNs, no reverse proxies, no port forwarding, nothing exposed to the rest of the internet.

What I’m praying for is for Jellyfin to add a tailscale like direct peer to peer system. They can skip the backup funneling traffic through their servers. But just have something that coordinates a direct connection with just basic NAT.

ragebutt@lemmy.dbzer0.com on 31 Jul 00:29 next collapse

They won’t do that because it’s expensive and free software generally doesn’t have the budget to do this

I don’t know why you think the “just works” is any different from tunneling with a service. Your server is still opened to the internet through upnp with direct connections and through a tunnel to plex.tv when a direct connection is not possible. In fact plex is inherently less secure because their infra is both the encryption endpoint (as opposed to your client with Jellyfin and Tailscale or whatever) and their infra has been vulnerable in the past (like the massive breach in 2022).

Jellyfin with something like nginx and a vpn is open to the internet, yes, but a service that tunnels (like wireguard, Tailscale) bypasses this issue and it’s up to you to set it up as to your level of comfort

Plex is just easier but as with all things tech (especially those infected with VC dollars) “ease” translates to less secure and far more likely to exploit your data

avidamoeba@lemmy.ca on 31 Jul 02:43 collapse

I came up with a funny strategy I use to lock it down a bit. What’s exposed to the internet for me is Apache2 reverse proxy. The proxy is locked down to reject all connections EXCEPT for the ones coming from a special subdomain which is something like a 64-character long random string. This prevents pretty any unwanted connections. Obviously the special subdomain must remain as secret as a shared password among the Jellyfin users. It works for trusted users.

What I want ideally is an “authenticated firewall.” OpenWrt rejecting all connections on the open port except for an allowlist of IPs. Then there must be a system where users can authenticate and their IP is added to the allowlist. I haven’t found an off-the-shelf solution like this but I’ll make it some day. Too bad I figured this random string subdomain trick cause it seems good enough for now. :D

KairuByte@lemmy.dbzer0.com on 31 Jul 04:09 next collapse

How is your DNS set up for that subdomain? Is it on a wildcard DNS record?

[deleted] on 31 Jul 05:38 next collapse

.

avidamoeba@lemmy.ca on 31 Jul 05:38 collapse

Do you mean the SSL cert? Yes, that’s wildcard on *.mydomain.com. Then the subdomain is kvtn4ftxfreurdcw7qtr21mcywxaqqm.mydomain.com.

KairuByte@lemmy.dbzer0.com on 31 Jul 15:20 collapse

In this case I mean the DNS entry for the random string. The thing pointing that subdomain at your IP/proxy.

avidamoeba@lemmy.ca on 31 Jul 15:59 collapse

It’s just an A record pointing to my IP. IP’s updated from my router via the DNS provider API.

KairuByte@lemmy.dbzer0.com on 31 Jul 16:01 collapse

If that A record isn’t a wildcard, anyone can see it, is what I’m getting at.

avidamoeba@lemmy.ca on 31 Jul 16:05 collapse

Hm. As far as I know that can only be done if AXFR is enabled (it’s not), if the domain has entered some search engine that has remembered it, through SSL cert that’s not wildcard, or through brute force lookup. Am I missing something?

KairuByte@lemmy.dbzer0.com on 31 Jul 16:14 collapse

Give it a look on dnsdumpster.com or similar. Your dns records are inherently public, so anyone that works out the domain can work out the subdomain. In fact there are plenty of tools that just scan every domain/subdomain they can find.

avidamoeba@lemmy.ca on 31 Jul 16:47 collapse

Thanks for the pointer. Checked, tried a couple others - they don’t know about it. They have some other non-random DNS records. AFAIK they can absolutely find it if they scan for all domains, but it’ll take forever if the name is randomly-generated and sufficiently long. Someone has to be determined to spend the resources. This doesn’t guard against that but against bots trying to fuck with the service at the port. I could move it to a wildcard though. There’s an overlap with another subdomain (they’re actually sub-subdomains and the first sub is common) but I could move that.

left_is_best@feddit.online on 31 Jul 14:04 collapse

A semi-automated whitelist solution would be nice. I’ve settled for Crowdsec with very strict automatic banning behavior.

NewNewAugustEast@lemmy.zip on 31 Jul 01:19 next collapse

Well except during the Plex outage today.

And last week.

JustEnoughDucks@feddit.nl on 31 Jul 07:40 collapse

It is literally a cloudflare tunnel/ tailscale type thing but contained in the app. The only real difference is that it is bundled in the app, so less setup and in exchange, Plex itself is free to harvest all of your data.

fuckwit_mcbumcrumble@lemmy.dbzer0.com on 31 Jul 14:08 collapse

That’s the key. It just works. No extra setup necessary.

And more importantly, I do t have to have my 60 year old mom do some additional setup in her end. Just install the app, and go.

black0ut@pawb.social on 30 Jul 19:58 collapse

You don’t need to do that with jellyfin either. It includes the website for convenience, but you can just disable it or completely remove it and have just the server.

fuckwit_mcbumcrumble@lemmy.dbzer0.com on 30 Jul 21:50 collapse

How do you communicate with the server outside of your network? You’d still need to expose those ports directly to the internet right? (excluding VPNs/reverse proxy etc)

KairuByte@lemmy.dbzer0.com on 31 Jul 04:03 next collapse

I mean, if you put restrictions on the requirement sure. At that point it kinda becomes a loaded question though.

If you remove the restriction, just use a cloudflare tunnel.

keyez@lemmy.world on 31 Jul 14:14 collapse

Yeah dont use a cloudflare tunnel for media streaming

KairuByte@lemmy.dbzer0.com on 31 Jul 15:20 collapse

They don’t care, that line in the ToS was removed years ago now.

bagodogs@sh.itjust.works on 02 Aug 03:01 collapse

I believe it was moved, not removed, and that it is now located in a different document, but still applies.

KairuByte@lemmy.dbzer0.com on 02 Aug 04:29 collapse

No it was definitely removed, they now have essentially “don’t be an ass with the bandwidth.”

bagodogs@sh.itjust.works on 02 Aug 15:19 collapse

No, it was moved. It now sits in their CDN service terms; the difficulty is in determining whether tunneled traffic constitutes CDN usage because CF are kinda vague on this stuff. Are they going to limit your account over a little streaming? Probably not, but I would not risk it unless you don’t really care about the account.

KairuByte@lemmy.dbzer0.com on 02 Aug 19:16 collapse

Tunnels aren’t inherently CDN, you can tunnel UDP info for instance (if you use cloudflared on both sides) and inherently transient things such as websockets.

I’ve had none of my media be cached in their CDN for instance. In fact you’d likely have to do some hoop jumping to make it happen.

keyez@lemmy.world on 31 Jul 14:16 collapse

It is still an issue that is easier on plex which is why I run both because I can’t setup and troubleshoot vpns for all my family that has access. Plex is much easier on that way. Jellyfin is great but look what you need to mimic a fraction of plexs power 😆

HereIAm@lemmy.world on 01 Aug 08:46 collapse

Unfortunately for a Plex style easy to share library you need it to be centralized, handing over a lot of power to whoever is controlling it.

victorz@lemmy.world on 30 Jul 19:11 collapse

through a website

I access it via the app on my LG TV with WebOS, so not technically a website but yeah, over the network via an API at least 👍

ItsNotImportant24@lemmy.ml on 30 Jul 21:10 next collapse

Jellyfin does support remote streaming and it doesnt have to be through the web ui.

possiblylinux127@lemmy.zip on 31 Jul 00:36 next collapse

You just use a VPN

ryannathans@aussie.zone on 31 Jul 03:39 next collapse

I don’t have any issues with jellyfin and remote streaming?

NotSteve_@lemmy.ca on 31 Jul 17:55 next collapse

You just need to setup a reverse proxy. My Jellyfin instance has been accessed from all over the world

Faceman2K23@discuss.tchncs.de on 05 Aug 22:09 collapse

It absolutely does but you have to do it yourself, they dont accept any liability for doing that and nor should they, so if you dont know how to do it with at least the minimal level of safety and security and accept that risk yourself then you really shouldn’t try. Ideally you would only do it via a private VPN to trusted users.

Plex has some features built in to make just opening the port reasonably safe, though I’d still recommend against that. They also have a reasonably secure account verification system, and the software itself has proven to be somewhat safe.

Jellyfin has very little security built in and is not intended to be public facing, it also has the double edged sword of being open source, so you could read through all the code and pick it apart for flaws and exploits if you wanted to and we all just trust that when exploits or flaws are found they are reported properly.

JF is great but you are on your own if you want to make it available via WAN.

avidamoeba@lemmy.ca on 30 Jul 19:00 collapse

With great power come great … uuh … :D

Also the meme is just bait so you read abt the problem and see if you need to solve it for your setup.

victorz@lemmy.world on 30 Jul 19:04 next collapse

complications 😅

avidamoeba@lemmy.ca on 30 Jul 19:17 collapse

Complications, yes!

Cocodapuf@lemmy.world on 31 Jul 01:45 next collapse

Yeah but tell me about this tool for Plex remote streaming…

ruuster13@lemmy.zip on 31 Jul 02:01 next collapse

It’s a wrapper called jellyfin

GoatSynagogue@lemmy.world on 31 Jul 04:39 next collapse

Anyone using jellyfin should not be exposing it to the public internet.

HereIAm@lemmy.world on 01 Aug 08:42 next collapse

Why not? Unless you’re talking about unauthenticated steaming of media if you reverse engineer a servers folder structure.

GoatSynagogue@lemmy.world on 01 Aug 23:20 collapse

It’s not secure. It’s a horrible thing to do

HereIAm@lemmy.world on 02 Aug 00:56 collapse

Do you have any proof that it’s not secure?

GoatSynagogue@lemmy.world on 02 Aug 01:16 collapse

The developers of jellyfin themselves say it’s not.

HereIAm@lemmy.world on 02 Aug 01:40 collapse

I think you’ve fundamentally misunderstood some of their communication.

There’s the issue I described earlier where it is possible to stream files unauthenticated if you know the folder structure on the video. The devs have responded that they won’t fix this. Outside of streaming content, there’s no other access through this mean. github.com/jellyfin/jellyfin/issues/1501

Then there’s the release of 10.11.7 that fixed a number of security issues. github.com/jellyfin/jellyfin/releases/…/v10.11.7 with no major security issues since then. And all the issues were privilagr escalation for a normal user account on jellyfin. So the attacker would already needed to have an account on your server, and only the data that jellyfin could see was at risk, nothing escaped contagion so to say.

They also officially support a reverse proxy set up: jellyfin.org/docs/general/…/reverse-proxy/.

I have no idea where you’ve got the idea where they themselves claim it’s unsecure to open it to the internet. Of course there’s always a risk associated with exposing something, but jellyfin doesn’t pose any larger risk than anything else you might publish.

GoatSynagogue@lemmy.world on 02 Aug 01:43 collapse

Accessing files unauthenticated……the devs explicitly say they won’t fix it…… and you think that’s not a huge security hole? Software with something like that marked as “won’t fix” is a giant no-no for me. If they’re ok with that, their software should be nowhere near an internet connection.

The person with a fundamental misunderstanding is you.

HereIAm@lemmy.world on 02 Aug 08:10 collapse

I do agree it’s an odd choice not to fix it, and I do wish they would. But for now it’s a risk I’m fine with taking. If my server gets DOSd in the future from multiple unauthenticated streams I sure will be a grumpy git and complain to them, but in the mean time uuh… sharing is caring? 😅

GoatSynagogue@lemmy.world on 02 Aug 09:01 collapse

Just wait til movie studios start fishing for people hosting their movies illegally. With how everyone standardises their media structure and file names these days, finding people hosting your movie would be a cinch.

nibbs@lemmy.zip on 01 Aug 08:48 collapse

Hi, could you tell me why? I mean, I think I understand the basics of the risk of brute force attacks. My mitigation for the admin account is, not to allow login outside the local network. Users are allowed from anywhere, as my family uses the library. Also my service (there are others) are routed through NGINX.

Do you have tips for external users using, for example, a VPN only for specific addresses / IPs? At least that was an idea I had, but didn’t got got around to dig for solutions.

Thanks in advance.

GoatSynagogue@lemmy.world on 01 Aug 23:20 collapse

VPN is the only way I would ever be doing it.

Cocodapuf@lemmy.world on 31 Jul 06:30 collapse

No, I said remote…

amorpheus@lemmy.world on 31 Jul 14:33 collapse

That’s the nice thing about Plex, you just stream your Plex library using Plex, and Plex is also the only place you and anyone you share with need to log in.

Poxlox@lemmy.world on 31 Jul 23:32 next collapse

Excellent bait

Hupf@feddit.org on 01 Aug 14:22 collapse
coolasbreeze@lemmy.world on 30 Jul 21:19 next collapse

Thanks, will take a look a my setup

zr0@lemmy.dbzer0.com on 30 Jul 22:01 next collapse

How large is the database? Because there is a way to fully load SQLite into memory, which would speed everything up drastically for a scan. At the end of the scan, you could just write back everything to the disk, then it is just one blob of sequential write, which is fast enough on spinning rust.

lyralycan@sh.itjust.works on 30 Jul 23:24 next collapse

Interesting, I figured people would use MySQL instead if possible.

avidamoeba@lemmy.ca on 31 Jul 02:20 collapse

600MB. Would that require changes to Jellyfin? They’re on the path to introducing Postgres support.

zr0@lemmy.dbzer0.com on 31 Jul 09:10 collapse

I just checked the code and unfortunately, they do not support loading the SQLite file into memory yet. Even worse, the change would be substantially. It appears they currently abuse the database connection a bit. They basically create a new connection for each operation. This does not matter if you can read/write in parallel, but that’s only the case with NVMe and certain drivers. So all SATA (SSD and HDD) suffer from the current mechanic. So just loading it into memory is not going to solve the issue. Jellyfin needs to change architecturally, so that a database connection is reused. I don’t know why or who implemented the current logic, but it is clearly done by someone not understanding how databases work.

Depending on the mood and time, I will come up with a solution that is solid. For now, you are stuck with the current logic.

avidamoeba@lemmy.ca on 31 Jul 12:02 collapse

Thanks for looking into it. As far as I read they moved to an ORM with 10.11 as a prereq to supporting other db engines. I’m guessing the db connection code would be undergoing major changes when they do that so I wouldn’t rewrite the current implementation. I’d either follow that work and help them get it right or rework the implementation after they’re done. We’ll just suffer through the mean time. 😄

KingThrillgore@lemmy.ml on 30 Jul 23:35 next collapse

Hey not bad for the developer…he vibe coded it right

surewhynotlem@lemmy.world on 31 Jul 00:40 collapse

Just the desktop client. Not the server.

Decronym@lemmy.decronym.xyz on 31 Jul 00:40 next collapse

Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

Fewer Letters More Letters
CGNAT Carrier-Grade NAT
DNS Domain Name Service/System
Git Popular version control system, primarily for code
ISP Internet Service Provider
NAT Network Address Translation
NVMe Non-Volatile Memory Express interface for mass storage
Plex Brand of media server package
SATA Serial AT Attachment interface for mass storage
SSD Solid State Drive mass storage
UDP User Datagram Protocol, for real-time communications
VPN Virtual Private Network
ZFS Solaris/Linux filesystem focusing on data integrity

12 acronyms in this thread; the most compressed thread commented on today has 13 acronyms.

[Thread #66 for this comm, first seen 31st Jul 2026, 00:40] [FAQ] [Full list] [Contact] [Source code]

Strit@lemmy.linuxuserspace.show on 31 Jul 05:38 next collapse

I’ve had initial scans take hours and scans afterwards usually also take some minutes. Why do you think that is an unreasonable amount of time to check all entries for updated metadata?

unending != 40 minutes.

avidamoeba@lemmy.ca on 31 Jul 05:46 collapse

That would be reasonable. I did repeated rescans and only counted subsequent rescans. For me the initial scan after upgrade took a bit more but not hours. Subsequent scans took less. E.g. 20min -> 13min for write-optimized filesystem. So that’s reasonable, although 10.10 was way faster. Library scans are expected to get faster in 13 according to some Github threads I read.

When I had the broken Home Videos library I waited 3 days for the initial scan to complete and it did not. Repeated rescans did not seem to complete although I didn’t wait 3 days for them. I’m not taking into account those scan times. Something was wrong with this library type on 10.11 and/or my media. Worked fine on 10.10.

Strit@lemmy.linuxuserspace.show on 31 Jul 05:50 collapse

Fair. I have never had a Home Video library, so I don’t know how those are scanned or what they are looking for other than embedded metadata. But yes, sounds like that library type has some issues.

Carol2852@discuss.tchncs.de on 31 Jul 05:44 next collapse

If you use folders a lot, the library will get faster with v12 github.com/jellyfin/jellyfin/issues/15141

OP said this didn’t improve their situation though.

avidamoeba@lemmy.ca on 31 Jul 05:51 collapse

Not sure if this is the problem I was hitting with my Home Videos library type. It’s got directories with YouTube videos. I tried re-adding it in 12-rc3, which was released a month after the nightly mentioned in the issue thread. Still couldn’t complete. I ended up re-adding the media as Shows library. Works okay with the directory structure I have.

The write performance was recorded without the problematic library (deleted).

ragingHungryPanda@piefed.keyboardvagabond.com on 31 Jul 05:44 next collapse

I run the DB on the SSD and media on the hdds and haven’t had any issues, but I don’t have a huge library though. However, things are generally speedy. I thought the higher record sizes were recommended for media, not the DB? but if it worked for you, that’s good

avidamoeba@lemmy.ca on 31 Jul 06:50 collapse

64K is generally small recordsize. For media they recommend 1M. My db was sitting on the default 128K recordsize and perforned fine on 10.10. It doesn’t matter much for reads because ZFS keeps it in RAM and if it gets evicted it goes into SSD cache (l2arc). But for writes the cache wouldn’t help unless I disable sync which risks data loss. I don’t think 10.10 did much writes during lib scan so write perf only mattered when something changed.

cryptix@discuss.tchncs.de on 31 Jul 08:17 next collapse

Doesn’t jellyfin need a static IP.

peppericecream@lemmy.dbzer0.com on 31 Jul 08:48 next collapse

No.

sonofearth@lemmy.world on 31 Jul 09:24 next collapse

Static IP for what? As long as you know the ip address of your jellyfin server you can connect to it. A static IP is just good to have for ease of remembering, using your own domain (not that you can’t do it with Dynamic addresses) or if you are integrating other services with it. This applies to any service you host.

cryptix@discuss.tchncs.de on 31 Jul 09:35 collapse

Most ISP connection are behind CGNAT(ipv4), and in case of ipv6 to have a secure connection wouldn’t that require SSL certificate and a domain?

vividspecter@aussie.zone on 31 Jul 10:10 next collapse

You could use tailscale or netbird. Alternatively, you can use a dynamic DNS provider which usually provide free subdomains, if you don’t want to pay for a domain. And even with all of that, Jellyfin doesn’t require HTTPS, although there may be clients that do (make sure you’re behind a VPN in this case).

sonofearth@lemmy.world on 31 Jul 10:19 next collapse

I have Pangolin setup on a VPS so I and my family can access it externally. It “bypasses” my router’s firewall. Tailscale was a stupid solution because a lot of people will be using it and I don’t want to maintain another service and be tech support for their tailscsle client. So the only thing I did to restrict access was by geoblocking.

magic_smoke@lemmy.blahaj.zone on 31 Jul 14:20 collapse

Jellyfin expects you to actually host it yourself, instead of baking in a proxy and selling you the service.

There are plenty of free subdomain providers, and let’s encrypt gives out free certs.

If you’re not hosting through a VPN you should consider those a requirement so you’re not sending an unencrypted password to your jellyfin instance over the internet. Regardless of your ISP situation…

GreenKnight23@lemmy.world on 31 Jul 23:12 collapse

I’m hearing a common theme to poor application security here.

  • host through vpn
  • don’t expose publicly
  • use a free subdomain provider
archy@lemmy.world on 01 Aug 01:37 collapse

To function? No.
Useful? Yes.

[deleted] on 31 Jul 09:31 next collapse

.

Faceman2K23@discuss.tchncs.de on 05 Aug 22:18 collapse

I’ve always kept my apps and databases on solid state media, putting them on spinning rust, even in a well tuned ZFS pool with lots of disks is way too slow for their (admittedly inefficient) database.

avidamoeba@lemmy.ca on 06 Aug 00:17 collapse

This is true but it’s nice to have the whole app, data and database in one place, going together, snapshotted together, “backupable” together. It’s slower for sure. That said it can be reasonably fast with a large pool (more disks). With the magic of SSD cache, database reads fly and reads are the majority of the loads in my heads. In the future I would put root on ZFS as well and either do SSD cache or have root on ZFS SSD pool that gets send/recved regularly onto the spinning pool so it’s easy to restore when needed.