I have docker installed, but only have a vague idea of how it works.
Back in the day, I would just port forward, but even then, I would need a static IP somehow.
I have heard a reverse proxy is an option, but that is an entirely new topic to me.
Surely there is an easy way to access Jellyfin outside of my home network that I’m just missing.
Tailscale. It’s free. Insanely easy to set up.
Just install on your devices and connect via the given tailscale ip for the jellyfin server.
Tailscale. It’s free.
Something about Tailscale rubs me the wrong way. That “free” aspect, specifically. No company ever runs a free service without some sort of compromise somewhere.
I would also propose going with Tailscale instead If a VPN + DynDNS solution. Imho it is a lot easier to Setup compared to VPN + DynDNS If you are a beginner and just starting out.
If at some point you need more and then is available in the free Tier of Tailscale and you do not want to pay for it (and you have built up some knowledge!) you can switch to something like Headscale or Netbird.
Currently I’m using tailscale. I like it but often switching IP address if I’m at home and I can’t use my normal vpn on it. Plus, I’m excited to learn about DNS and cloud flare. Its just very overwhelming haha
I forgot to mention that one because I kinda thought it belongs with radmin and hamachi, but it’s my choice as well currently.
I am using it with my own Headscale though, so add a domain to that as well.
And I finally need to switch my vaultwarden to work over tailscale & LAN finally, it’s a huge security risk to expose that one.
Or head scale if you don’t want something you don’t control that requires an account with google/apple/microsoft
Headscale is great but requires port forwarding which, aside from having its own iasues, is something op wants to avoid.
Yes, a VPN. And dynamic DNS if you don’t have a static IP address.
To be clear, your suggesting I set up my home computer as a virtual private Network server that I would connect to from the TV or device outside of my home network?
Yes, it works great for me. Probably not for a TV though, for that you’d probably need some travel router VPN client. But I don’t know how often you’d be at a random TV and need to get to jellyfin.
Got it! I think this is the plan of attack I’m going with
Yeh, exactly.
And the “dynamic DNS” part handles your public IP address changing with 0 pain.
You either buy a domain (like example.com), or there are free domain name providers that give you a subdomain (like mycooldomain.example.com) of one of their domains.
You then run an additional service on your home server that checks what the current public IP address is. If it changes, it notifies the DNS responsible for your domain/subdomain, which then points to your new public IP.
To connect to your VPN, you only ever care about “mycooldomain.example.com” and never the underlying IP address.…
As long as your ISP isn’t running CG-NAT of course 😵💫
I forward my port to my bastion host, and reverse tunnel to it when I want to access my stuff.
My router allows you to set a device in the DMZ zone which will let you use your routers IP as its address.
Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:
Fewer Letters More Letters DNS Domain Name Service/System ISP Internet Service Provider Plex Brand of media server package VPN Virtual Private Network VPS Virtual Private Server (opposed to shared hosting)
[Thread #41 for this comm, first seen 5th Jul 2026, 18:30] [FAQ] [Full list] [Contact] [Source code]
An easy way? I guess the term ‘easy’ depends on your expertise with networking, firewalls, etc. Sounds like you and I are at about the same level there. In which case the answer is: no, there’s no easy way from what I can tell. I’ve looked into it and it’s a lot more involved than, say, Plex (because Plex does a bunch of the routing and stuff for you, but at a cost).
That is the answer my intuition was leading me to, but I hoped I was wrong. It looks like this is an opportunity to learn something outside of my comfort zone.
consider zerotier or tailscale
Tailscale is incredibly easy. Install, start, sign in on both devices. Boom. Jellyfin from anywhere
I’m sold! Setting it up now!
Let me know if you have any trouble!
A VPN such as Tailscale.
It’s my go to method super easy to set up and use on both the device hosting your JellyFinn server and whatever your steaming on
That is a new concept to me, but I’ll definitely look into it.
Just be aware that if you want anyone else to connect to your Jellyfin, you’ll still have to route it through a domain and reverse proxy, unless you’re comfortable letting them log in to your tailnet.
It’s a bit of a fiddle to set up, but once it’s done it’s quite satisfying.
it’s actually the recommended way if you use jellyfin, theres a few security/privacy vulnerabilities with publicly exposing the jellyfin server anyway, they are being worked on but, the safest way to do it is just use a vpn regardless.
Plus it enables you to access everything. If you have radarr or sonarr or whatever, you can get to those and add media while out and about.
Personally I use Mealie and pull up ingredient lists while I’m im at the grocery store.
Domain and vps pointed to your ip. Or if behind cgnat reverse proxy to vps
That’s the whole point of a domain. Your IP changes every now and again you need people to know where to reach you. You give them a domain, and you configure the name records so that the domain always points to the right IP address.
Your options:
- dynamic IP - you keep your setup as is and just periodically tell them the new IP you’re on. Annoying and exposed
- static IP - you buy a static IP (from your ISP) and share it with your friends once. A little bit less annoying and still exposed
- you use a VPN like hamachi or radmin - your friends install the software, they look for you IP in there, you’re done - very secure but also very annoying
- you buy a domain - you have to configure an IP updater like ddclient or similar, then you jellyfin should be reachable - least annoying for your friends but also slightly less secure
Domain is the cleanest option.
I am telling you how annoying it is because that’s how likely your friends are to adopt it and how secure it is because depending on your country you are doing something illegal and you really don’t want anyone to find out and you gotta keep it updated more often if you don’t want people to exploit it. There’s an endless supply of very smart people out there who use known bugs to target public services.
You left out DDNS. It’s free, easy to set up with lots of detailed guides online, and works as well as a static IP.
I added a reference to your comment
yeah I forgot that one. I had to rush the comment a bit.
I appreciate your response!
It looks like a VPN is the option I’m leaning towards, but I’ll definitely put the idea of buying a domain in my back pocket for a while.
Some .xyz domains cost less than 1$. Mine is 0,85$/year
What do you do, randomise it every year?
Nah same domain, 0,85$/year. It’s 8 numbers + .xyz
Wow thanks!! I’ll use a different amount of numbers or something
You get to pick your numbers
On June 1, 2017, .XYZ launched the 1.111B class .xyz domains, cheap domains priced at US$0.99 per year and renewed at the same price. The class of domains consists of six-, seven-, eight-, and nine-digit numeric combinations between 000000.xyz and 999999999.xyz. Daniel Negari, CEO of .XYZ, stated that it was meant to bring competition, choice, and innovation to the market
Thank you. I’ve bought a domain. I’d like to go with this option. Just researching how to do it on cloud flare
On Cloudflare, you’ll want to set a DNS record to point any relevant subdomains to your current WAN IP address. IPv4 will be an A Name record. IPv6 would be an AAAA Name record, but I’m not going to deal with IPv6 for this… Here is an example of mine, with info blocked out:


So for instance, maybe you have a
peepee.example.comsubdomain, apoopoo.example.comsubdomain, etc which all point to your WAN IP address. That will basically tell Cloudflare’s DNS to forward any traffic for those subdomains to your WAN IP. Each subdomain can also choose whether or not to proxy the content, or just directly send it to your WAN with DNS. Basically, when Cloudflare propagates the DNS records to the various DNS servers, you can choose whether that record has your WAN IP (DNS Only) or one of Cloudflare’s (Proxied). Proxy support means you can take advantage of some additional CF protections, but it also means passing all of the data through CF’s server. In most cases, you’ll want DNS Only. Proxy support will depend on the individual service. Some will work fine with it, some won’t. And it’s also possible that you don’t want services proxied through CF for privacy reasons.Next, you’ll want to set up a reverse proxy service. This will be something like Nginx Proxy Manager, Caddy, etc that you run on a device on your LAN. It can even be on the same machine running your various services. The big reverse proxies all offer Docker images, so you can incorporate it directly into an existing Docker stack if you already have one. Personally I use NPM, but Caddy is also very popular.
You’ll tell this reverse proxy “when you receive valid traffic addressed to {subdomain}, forward it to {relevant service on your LAN}.” You can also set some additional options for each subdomain, like automatically upgrading to https. For instance, maybe
peepee.example.comforwards to192.168.1.100:42069on your LAN, and is configured to automatically upgrade any http traffic to https, and to require https.You can also set up automatic TLS certificate renewal, so https traffic can be properly encrypted. The reverse proxy will need an API key, and it will allow the service to automatically check expiration dates and pull a fresh TLS cert for your domain if the date is coming up soon.
You’ll probably want to use a wildcard certificate, (basically
*.example.com) because the TLS certificates are open to the public. So if you do individual certs for all of your various services, bots will scrape the public records and you’ll inevitably get a lot of bot traffic probing your various subdomains. A wildcard domain usually means the bots hit the standardexample.comandwww.example.comfirst, which makes them super easy to detect and block. I even have rules set up to automatically block anything that tries to access my www subdomain, because I specifically don’t host a landing page and don’t have anything available there. So I know that any traffic hitting that www subdomain is a bot trying to access common subdomains.Next, you’ll want to forward ports 80 and 443 to your reverse proxy. Port 80 is the standard port for http traffic, and 443 is the standard port for https traffic. These will be the ports that your reverse proxy actually receives the traffic on, before forwarding it to the various services. Note that lots of lazy devs default to using 80 and 443 for lots of things, so you may want to configure your router to use a different port (like 81 or 444) for its config page if you’re able. Otherwise, you may end up accidentally locking yourself out of your router’s config page, because it will attempt to use 80 to reach the page, then get automatically forwarded to the reverse proxy instead.
Finally, for some ease-of-maintenance, you may want to consider adding a DDNS service (like Cloudflare-DDNS) to your docker stack. This will occasionally check your current WAN IP, and update it with Cloudflare if necessary. For example, if you have an outage and your router gets a new WAN IP when it boots back up again. Normally you would need to manually go to Cloudflare and update the IP info to point at your new address. But DDNS does that automatically.
The way traffic flows when it is all set up is along these lines:
- A device wants to access your service at
peepee.example.com. It doesn’t know where to find that site, so it asks a DNS server. - Cloudflare has told all of the various DNS servers “hey,
peepee.example.comcan be found at {your IPv4 WAN address}”. - The device follows that DNS record, and attempts to connect to your IPv4 WAN address, on port 80 or 443. For this example, let’s say it tries to connect on port 80 for standard http traffic. The device knocks on port 80’s door and says “hey, I’m here to access
http://peepee.example.com/.” - Your reverse proxy checks the configured list, finds the valid
peepee.example.comsubdomain, finds it has a valid TLS cert, finds it is configured to automatically upgrade to https, and responds “Yes, please upgrade to https. Http traffic is not allowed.” - The external device knocks again, this time on port 443’s door. It goes “hey, I’m here to access
https://peepee.example.com/. Your reverse proxy goes “thank you, here is the TLS cert and my half of the TLS security handshake.” - Your external device uses the data in the TLS cert to validate and complete the TLS handshake with the reverse proxy, and the traffic between the reverse proxy and your external device is now encrypted with https. Your device gets the nice little “secured” padlock icon in your browser. Because the traffic is encrypted, a malicious actor may be able to tell what kind of info you are passing (for example, a video stream will likely have a pretty obvious pattern) but they won’t be able to see what specific data you are passing. They may be able to tell that you’re streaming a video, but they won’t know which video specifically.
- The reverse proxy forwards the traffic to the service, configured at
192.168.1.100:42069. - Your service does not ever know the device is being accessed via WAN, because (as far as the service can tell) the traffic is coming from your reverse proxy (also a LAN device). So any “pay to use WAN” services will continue to work for free.
- The external device never gets access to info like the specific LAN IP or port number, because it only has access to the reverse proxy. All of the traffic is passing back and forth between the reverse proxy.
But notably, keep in mind that the reverse proxy didn’t do any actual user authentication. If your service has a weak password, a reverse proxy will act as a gateway for any potential hackers to gain access to the service. The same way an open port is a gateway directly to the service, the reverse proxy is now a gateway that simply requires an attacker to use a subdomain instead of an IP and port number. And if you make your subdomain something like
jellyfin.example.comit will probably be dead simple for a bot to guess. And any vulnerabilities in the service will still be exploitable via the reverse proxy, because the reverse proxy is simply making sure the request is valid, and then passing the traffic back and forth. It isn’t actually inspecting the content of that traffic, so it’s not going to stop things like attackers. When you hear digital security folks talk about things like attack vectors, this is what they’re referring to. Your reverse proxy is a potential vector of attack for your configured services. Use strong passwords, keep your services updated, etc…You can technically add authentication to a reverse proxy. So for instance, maybe a service doesn’t have any built-in way to add a password. You can have the reverse proxy act as an authentication gate, so it will prompt the user for a username+password before they can even reach the service. This will make the services more secure (yes, even the ones that already have passwords, as long as you use a different password for your reverse proxy authentication) but it will break most apps that are designed to work with a service. For instance, Jellyfin has several apps that work, but those apps won’t have any way to get past the reverse proxy’s password gate. So those apps will simply break if you add a second layer of authentication with your reverse proxy.
There are also some security options you’ll likely want to enable on Cloudflare’s side, but this comment is already long enough.
Thank you so much for such a detailed reply. I’m going to print this off and go through it point by point.
I didn’t realize how overwhelming this would be, the amount of information is incredible.
I was trying to use the cloud flare ai assistant to set up WARP access to my phone but then I realized its basically another VPN which defeats the whole point on me using the domain because I wanted to be able to use my traditional VPN to stay protected.
I also wanted to be able to log into my server android apps like immich and Joplin but can’t do that with authentication as its not a webpage.
I’ll print this off and anything I don’t understand (most of it at this stage haha) I’ll spend some time studying it.
I got a good laugh at peepee poopoo
Thanks again
I actually just updated it slightly, and may continue to do so if I think of things. So you may simply want to check back here instead of printing it.
I didn’t realize how overwhelming this would be, the amount of information is incredible.
Speaking from experience, it was quite overwhelming to me at first as well. It took me a handful of tries to wrap my head around Cloudflare Tunnels/Zero Trust. I persisted tho, and succeeded. It doesn’t help much that Cloudflare keeps rearranging their site, making it difficult to find necessary information. I will say, that when I migrated to a new server recently, it was a snap and everything clicked in place. There was no need to set up anything on their side. As I remember, it was a matter of a one liner code sequence they provided, to install the necessary components on my server. Jack’s a doughnut, Bob’s your uncle.
Yeah I’ve noticed that. A lot of the tutorials for learning cloudflare are with older GUI
- A device wants to access your service at
Device -> VPN Tunnel (ideally WireGuard) -> Home Router / Server.
The only port that needs to be opened is your WireGuard server which typically is :51820.
The issue with this is you have explain VPN’s and WireGuard to people which, in my experience turns people away as they see it as a hassle.
Alternatively buy a domain, setup DDNS so that your home IP is associated with your domain, setup a reverse proxy and open port :443 on your router however, I would suggest a blacklist-first approach and only whitelist the few known IP’s you can trust.
Free vps in oracle cloud with Pangolin. Never have to worry about explaining VPNs.
Free vps in oracle cloud with Pangolin
If I’m not mistaken I tried setting up pangolin to work along side my already running Traefik setup and it was just an absolute nightmare.
I just don’t have the time nor energy to reinvent my already running configuration.
I’ve set it up next to my NPM and it’s more complicated, but so much more capable. Traefik is what it uses to proxy things. You’re comparing a full suite of tools with just one piece.
Traefik is what it uses to proxy things. You’re comparing a full suite of tools with just one piece.
I mean, that’s debatable. Taking a look at their
docker-compose.ymlthere are 3 containers they recommend running, with a 4 optional container.- image: docker.io/fosrl/pangolin:latest # Pangolin itself
- image: docker.io/fosrl/gerbil:latest # WireGuard server
- image: docker.io/traefik:v3.6 # Traefik Reverse Proxy
- image: hhftechnology/middleware-manager:latest # Optional middleware manager for Traefik
To say this is a “full-suite” is a bit much when majority of the heavy lifting is done by Traefik, the middleware’s you assign to Traefik and WireGuard. Pangolin if I’m reading this correctly;
“Pangolin combines reverse proxy and VPN capabilities into one platform.”
Which is great! However as I mentioned previously, does not integrate well when these services are already setup to work standalone.
I suspect the same reaction from folks when they hear “download pangolin from the App Store, and use xyz credentials to connect.” And “download WireGuard from the App Store, and use xyz file to connect.”
Pangolin uses gerbil with newt for those wireguard tunnels. That’s a massive improvement already. It also adds a bunch more features like vpn, you can crowdsec, and more that I don’t use. To say it’s debatable if it’s a suite of tools is just wrong.
To say it’s debatable if it’s a suite of tools is just wrong.
How is it wrong to say it is debatable when Traefik and WireGuard have quite literally done majority of the development. Pangolin is just a man in the middle.
Pangolin uses gerbil with newt for those wireguard tunnels. That’s a massive improvement already. It also adds a bunch more features like vpn.
According to the Newt ReadMe -
Newt is a fully user space WireGuard tunnel client and TCP/UDP proxy, designed to securely expose private resources controlled by Pangolin. By using Newt, you don’t need to manage complex WireGuard tunnels and NATing.
Seems to me that WireGuard is their primary dependency, without WireGuard what use is it?
you can crowdsec
According to Pangolin docs they rely on the Crowdsec middleware offered by Traefik.
By default, Crowdsec is installed with a basic configuration, which includes the Crowdsec Bouncer Traefik plugin
I did the last one. Bought a domain for $5 per year from cloudflare and used a cloudflared tunnel to direct traffic to Caddy (reverse proxy). Set up everything as deny-by-default, requiring log in to access things like sonarr, and let things like Jellyfin and Immich bypass the login requirement. Took a bit to get it all figured out, but it worked.
There is also a way to use the cloudflared tunnel for free that gives you a domain as well (sort of anyways).
All of that is run via docker containers, minus the
Documentation on all of this is fragmented and a challenge to figure out. Happy to help anyone who wants to message me about it.
I took this a step further as I use a wireguard tunnel to make use of my router level ad blocking. So I added an entry for my domain to route back to caddy and serve it all locally. This is proving to be a challenge due to the way some browsers handle forced https, but I’m making due.
and used a cloudflared tunnel to direct traffic to Caddy
There is also a way to use the cloudflared tunnel for free that gives you a domain as well (sort of anyways).
This is DDNS, a popular, free alternative would be ddclient. Essentially updating an A Record so that your dynamic IP is remains associated with your domain.
While cloudflare is also my registrar as well, I don’t use any of the “features” they offer, and opted to use Keycloak for my authentication needs.
I’ve debated setting up Authelia or something similar because cloudflare is sooo slow to load their login page, but haven’t landed on anything yet… Plus I worry I set something up wrong and expose my network
I can’t be much of a help with Caddy however, for Traefik you can use the OIDC Middleware to forward requests to your authentication service.
Plus I worry I set something up wrong and expose my network
The only port that would need opening is :443, leave port :80 closed so that people cannot connect to your services insecurely. Slap fail2ban or geoblock on it and call it a day. Also, DDNS allowlist for that deny-first approach.
The current config routes through the cloudflared tunnel so no ports are open externally at the moment, so that’s nice, but yea, I’d have to imagine there’s some documentation out there for caddy.
Caddy has been a pain, though, so I might give one of the others a try. Thanks for the tips!
People’s IP addresses usually change so that might be annoying keeping a whitelist up to date.
A good alternative is something like fail2ban to ban ip addresses that spam your server looking for a way in and potentially geo-restricting access to your country.
I mean not for free, but I did it for cheap. A good domain can cost you $5 a year, and you simply route your jellyfin to a sublevel like watch.mydomain.com
Fun part is you can also route your sonarr like sonarr.mydomain.com
Any suggestions on where to start when looking into buying and setting up a domain?
A cheap way to start is noip.com. You can get a domain name for free, you just need to check in every 3 months to say you are still using it. It’s big enough that many routers support it.
After 2 years of checking in every 3 months I paid for their next tier of service where you don’t have to check in and get multiple domains etc. So their free service marketing worked.
I’d recommend buying a domain through Cloudflare. Once you have one, you can create subdomains and point them to services running on your home server. Cloudflare’s dashboard makes the DNS side pretty straightforward.
I mean I cheated and used chatgpt to help figure it out. But it’s more or less 3 programs max running on whatever server you’re using and using the cloudflare UI to redirect the traffic to the right place
I’ve been with NameCheap for over a decade. They’re a relatively quiet company that’s been around a while.
They’ve never done anything to make me want to change providers. Have my email through them as well. Good uptime. Ok-ish prices. Good customer service the one time I’ve needed it. Web site takes some getting used to, but it’s also never changed since I started using them.
Only thing they did once was lock me out of my account with endless CAPTCHAs, even with 2FA enabled.
Eventually they fixed it
You don’t need a static IP, you just have to keep track of what your current dynamic IP is.
You can do this with either a free or a paid DNS service.
There are a few different ‘free dns’ services that will delegate a subdomain of theirs to you at no cost. Admittedly, I’ve never actually used one of these so their names escape me. Hopefully someone else can point one of those out if that’s what you really want.
I purchased a domain via google domains, when they existed. It’s now transferred to squarespace, because they bought out google domains a few years ago.
It was around $13/year when I first got it a decade ago. It’s now around $28/year.
This allows me full control over the domain: I can use as many subdomains as I want to give each service I use it’s own unique name. (Instead of using their own separate ports that you’ve gotta remember) My domain will also forward all inbound email to my gmail account; this lets me use email addresses like <servicename>@mydomain.example. This way, I don’t share my real email and can immediately tell who sold my info to the highest bidder when I get spam. (I could also host my own email service if I really wanted, but I haven’t bothered)
Add Cloudflare ontop (for free); and it can filter out known attacks, ddos attempts, geofence your services to regions you’ll actually be in, provide/autorenew ssl certs for https, show you usage analytics, cache static data reducing server/network load, etc.
Ultimately, the paid option is well worth it IMO.
You don’t need a static IP, you just have to keep track of what your current dynamic IP is.
You still need a public IP address. More and more often, IPv4 services are provided behind CGNAT, which won’t be able to work as you describe.
If you don’t have a public IPv4 for your LAN you can use IPv6. Or, you can reverse proxy your services through a gateway with a public IPv4.
I use a a reverse proxy (Pangolin) running on a VPS. A Newt tunnel connects my LAN to to Pangolin, exposing my local services via subdomains.
/edit; vpns are good and all, but they require you to setup software on the remote device to connect to it, and that typically routes most if not all your traffic back to the vpn server then out to the internet. That can create speed/bandwidth issues.
Tailscale, ZeroTier, and other similar services generally establish direct tunnels between devices, without a separate VPN server. They use a central service merely as a sort of common meeting point (STUN/TURN) for the devices to figure out how to establish direct tunnel(s).
Fair points.
I’ve been lucky enough to have never been behind cgnat, so I keep forgetting about it.
My bigger concern with tailscale is being required to install software on the client. Not every device I use, I have permission to install a vpn client, nor would I want to.
For example, I have a fileshare using Filebrowser where I store work related files that I don’t want to loose access to or need access to from multiple machines (non proprietary info, stuff IT/MGT wouldnt get mad at me for ofc. I’ve actually cleared it with my managers, so no worries). That’s also a handy way to (temporarily) share large files with people or provide a way for friends to upload large files to me.
I also like to access my emby server (using sufficiently limited accounts), from things like the TV in the work break room, or a friends PC while I’m visiting.
Tailscale is a hurdle that I just don’t need/want.
As averse as I am to spending money on subscription services, having my own domain for less than 30 bucks a year might be worth it.
I think I’m going to try out the tailscale VPN route first before I fully warm up to buying a domain.
*Edit-You’ve definitely got me sold on getting a domain! Thank you so much for all the info!
Glad I could help. I’m not always immediately available, but I don’t mind answering questions if you run into troubles. Just send me a DM and I’ll do what I can. :)
What you want is Tailscale. The downside of Tailscale is that you have to connect to a VPN to access your services, the advantage - it is so easy to set up on the server it feels like magic.
As others have said, Tailscale is the most pragmatic solution. It’s a mesh VPN based on Wireguard. It’s implemented in such a way that you don’t need a static IP and don’t need to open any ports on your firewall. The caveat is that you either need to register an account on tailscale.com (it’s free for small-scale use) or set up a self-hosted alternative like Headscale on a VPS. Then you have to install the Tailscale client on each of the hosts you want to access and log into your account.
Tailscale nodes will be accessible using an internal, private address in the
100.64.0.0/8address space. You can also set up a split DNS that allows you to access your hosts using a DNS name likehostname.your-tailnet-name.ts.net.Used to have a tool specifically to route my dynamic IP to something static, without buying a domain name, back when I first hosted a website on my own regular home PC as a teen called “No-IP.”
Not sure if it’s still a thing.
Free ones are less common now (no-ip went paid.) Afraiddns is still free but requires regular account logins.
If the goal is doing this in a simple fashion, then use Tailscale funnels (https://tailscale.com/docs/features/tailscale-funnel). Funnels automate the process and act as a reverse proxy into specific servers within your tailnet.
The downside is there is no authentication to funnels, so whatever you’re running (Jellyfin in this case so that’s not an issue) needs it’s own authentication setup. You might consider running fail2ban on that machine and have it watch for login attempts, but otherwise that is the simplest setup I think you could do.


















