How is your DNS set up for that subdomain? Is it on a wildcard DNS record?
Comment on Improve very slow library scans on Jellyfin 10.11 / 12 on spinning media
avidamoeba@lemmy.ca 1 day ago I came up with a funny strategy I use to lock it down a bit. What’s exposed to the internet for me is Apache2 reverse proxy. The proxy is locked down to reject all connections EXCEPT for the ones coming from a special subdomain which is something like a 64-character long random string. This prevents pretty any unwanted connections. Obviously the special subdomain must remain as secret as a shared password among the Jellyfin users. It works for trusted users.
What I want ideally is an “authenticated firewall.” OpenWrt rejecting all connections on the open port except for an allowlist of IPs. Then there must be a system where users can authenticate and their IP is added to the allowlist. I haven’t found an off-the-shelf solution like this but I’ll make it some day. Too bad I figured this random string subdomain trick cause it seems good enough for now. :D
KairuByte@lemmy.dbzer0.com 1 day ago
left_is_best@feddit.online 22 hours ago
A semi-automated whitelist solution would be nice. I’ve settled for Crowdsec with very strict automatic banning behavior.