I currently have my Plex server open to the world. I realise that’s probably not best practice, so I’m trying to find a solution that can work for me.

I’ve been looking at cloudflare tunnels and it seems like thats probably what I want. Giving me access to my home server from outside. And it’s free, which is a nice perk

I’ve noticed however that the terms of service don’t allow for video streaming, but is allowed in the paid tier. Before I commit to spending money, I’m curious if it’s even technically possible. Plex tends to phone home to allow users to authenticate and locate their servers, so is that possible through tunnels?

Is this a waste of time? Is there a better solution? How are others dealing with this problem?

  • ѕєχυαℓ ρσℓутσρє@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    13
    ·
    1 year ago

    If you want a free solution, wireguard and tailscale are your friends. It you’re willing to pay, get a cheap VPS (the one I use for this is from RackNerd for ~$12/yr). It’ll make the process very user friendly if you’re planning to share it with others.

      • ѕєχυαℓ ρσℓутσρє@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        1 year ago

        You don’t actually need to do reverse proxy while using tailscale. You can just use ports as if you’re on a local network.

        The price is super low, but it’s been very reliable. Will highly recommend. You can see their current offers here.

        • anytimesoon@lemmy.mlOP
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          You can just use ports as if you’re on a local network.

          This is the bit I find confusing. Doesn’t Plex need that port to be open to the outside world?

          Or is your setup only open to devices on your private tailscale network and therefore seeing it as local?

          If that’s the case, I’ll need to see if tailscale can work with osmc, since that’s what I have running on my raspi behind my tv

          • ѕєχυαℓ ρσℓутσρє@lemmy.sdf.org
            link
            fedilink
            English
            arrow-up
            3
            ·
            edit-2
            1 year ago

            For tailscale/wireguard, you just need to open the port in your machine as if you’re using it locally. No need to forward port in your router. For all intents and purposes, you can treat all devices in your tailscale network as if they were local devices.

  • u/lukmly013 💾 (lemmy.sdf.org)@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    12
    ·
    1 year ago

    I’ve noticed however that the terms of service don’t allow for video streaming

    I may be wrong, but are you sure that’s still the case?
    There used to be clause 2.8

    …Use of the Services for serving video or a disproportionate percentage of pictures, audio files, or other non-HTML content is prohibited, unless purchased separately as part of a Paid Service…

    However this has been removed from the current version of ToS: https://www.cloudflare.com/terms/

    Again, I may be wrong, I am often wrong, it’s possible I missed something ¯\_(ツ)_/¯

  • Alk@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    1 year ago

    I have my plex accessible from outside, but only to plex users I add. It’s not like anyone can just get my IP and watch my content.

    • kungen@feddit.nu
      link
      fedilink
      English
      arrow-up
      10
      ·
      1 year ago

      There are many crawlers, and I’m confident at least a couple have tried to connect to your server (unless you have an IP firewall, or if you’ve changed Plex Media Sever’s default port, in which case significantly less likely).

      I assume it’s not really about them watching content, but to avoid them exploiting any possible PMS bugs.

      • keyez@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        I have plex open on my pfsense to US only IPs and see lots of requests blocked from overseas crawlers and some curls from the US, I moved it to a different external port and nothing but expected traffic after that.

  • Mugmoor@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    7
    ·
    1 year ago

    Plex isn’t allowed on Cloudflare. Itll work, but you’ll get your account flagged.

    Use Tailscale instead.

  • Boring@lemmy.ml
    link
    fedilink
    English
    arrow-up
    6
    ·
    edit-2
    1 year ago

    Personally I’d just spin up a wireguard container with a GUI, user friendly and you can add anyone to your VPN in like 2 minutes wherever you are.

    Most advanced part would be forwarding port 51820

  • camr_on@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    1 year ago

    My understanding is that cloudflare will block you from doing this if/when they detect you doing it, someone correct me if I’m wrong.

    Off the top of my head, would a tailscale funnel work for what you want? Serving Plex to the Internet without port forwarding?

    Actually with Plex, I’m not sure you even need to expose it at all. People can reach your server via the Plex app as long as it’s connected to Plex servers, they don’t need to reach the site actually hosted on your hardware

    • kungen@feddit.nu
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      1 year ago

      Without direct connection, PMS uses Plex Relays, which limit streams to like 320p.

    • smegger@aussie.zone
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      2
      ·
      1 year ago

      Pretty sure it needs at least one port forwarded to make use of plex remotely

      • anytimesoon@lemmy.mlOP
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        Yes, there’s the one open port that is required. Otherwise your traffic gets routed through Plex servers and the streams are limited to pretty poor quality video

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    edit-2
    1 year ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    IP Internet Protocol
    Plex Brand of media server package
    VPN Virtual Private Network
    VPS Virtual Private Server (opposed to shared hosting)

    4 acronyms in this thread; the most compressed thread commented on today has 7 acronyms.

    [Thread #187 for this sub, first seen 4th Oct 2023, 22:55] [FAQ] [Full list] [Contact] [Source code]

  • Monkey With A Shell@lemmy.socdojo.com
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    I really should look into these cloudflare tunnels people keep speaking of. A simple enough solution is to host a VPN server of your choice with cert and pass and it’ll make it pretty well impossible to reach by anyone without the required creds.