HOMELAB MEDIA
A single Docker host that requests, organizes, compresses, and streams a personal media library, reachable from anywhere through a Cloudflare Tunnel with no open ports.
dockercloudflare-tunnelwireguardquick-syncpython
// problem
Run a full media pipeline on one box without exposing the home network, without babysitting stuck jobs, and without filling the disks.
// constraints
- One host, consumer hardware.
- 1080p playback target for remote viewers.
- Every secret lives in an untracked .env. The repo holds only placeholders.
// approach
- Docker Compose stack split into a main services file and a separate playback stack.
- Outbound-only Cloudflare Tunnel publishes the two public apps. No inbound firewall rules.
- Download traffic is pinned inside a WireGuard VPN network namespace.
- Tdarr flows convert the library to HEVC on Intel Quick Sync, with worker limits by time of day.
- A strict HAProxy socket proxy limits which Docker API calls the health tooling can make.
// outcome
Hands-off operation: cron jobs throttle searches, a watchdog restarts a stalled service, and a Slack digest reports health, usage, and weekly activity.