Arama Yap Mesaj Submit
Request a Callback
+90
X
X

Select Your Currency

Turkish Lira $ US Dollar Euro
X
X

Select Your Currency

Turkish Lira $ US Dollar Euro

Contact Us

Location Halkali merkez neighborhood fatih st ozgur apt no 46 , Kucukcekmece , Istanbul , 34303 , TR

Jellyfin Media Server Setup: NVIDIA GPU Transcoding and Nginx TLS

Deploy Jellyfin with Docker on Ubuntu, including media permissions, Nginx HTTPS, NVIDIA Container Toolkit, NVENC/NVDEC transcoding, remote access, backup and real GPU verification.

Jellyfin Media Server Setup: NVIDIA GPU Transcoding and Nginx TLS
What will be running at the end?

Deploy Jellyfin with Docker on Ubuntu, including media permissions, Nginx HTTPS, NVIDIA Container Toolkit, NVENC/NVDEC transcoding, remote access, backup and real GPU verification. Every command is presented as an operational step; replace example hostnames, passwords and secrets before execution.

Architecture and requirements before installation

  • Ubuntu 24.04 LTS with sudo access and a dedicated IPv4 address
  • Docker Engine and Compose v2 where the deployment uses containers
  • A DNS A record pointing the application hostname to the server
  • NVMe capacity sized for application data, logs, temporary files and backups
  • Memory and CPU headroom based on measured concurrency rather than vendor minimums

DNS and port plan

  • 8096/TCP: Jellyfin HTTP yalnız reverse proxy
  • 8920/TCP: uygulama içi HTTPS kullanılacaksa
  • 7359/UDP: istemci keşfi, yalnız gerekli yerel ağda
  • 1900/UDP: DLNA, yalnız gerekli yerel ağda

Hands-on installation steps

1. GPU ve codec denetimi
lspci -nn | grep -Ei "3d|display|vga"
nvidia-smi
ls -l /dev/nvidia*
2. NVIDIA Docker runtime
distribution=$(. /etc/os-release;echo $ID$VERSION_ID)
curl -fsSL https://nvidia.github.io/libnvidia-container/gpgkey | sudo gpg --dearmor -o /usr/share/keyrings/nvidia-container-toolkit-keyring.gpg
curl -s -L https://nvidia.github.io/libnvidia-container/stable/deb/nvidia-container-toolkit.list | sed "s#deb https://#deb [signed-by=/usr/share/keyrings/nvidia-container-toolkit-keyring.gpg] https://#" | sudo tee /etc/apt/sources.list.d/nvidia-container-toolkit.list
sudo apt update
sudo apt install -y nvidia-container-toolkit
sudo nvidia-ctk runtime configure --runtime=docker
sudo systemctl restart docker
3. Compose yapısı
services:
  jellyfin:
    image: jellyfin/jellyfin:10
    container_name: jellyfin
    restart: unless-stopped
    user: "1000:1000"
    ports:
      - 127.0.0.1:8096:8096
    volumes:
      - ./config:/config
      - ./cache:/cache
      - /srv/media:/media:ro
    deploy:
      resources:
        reservations:
          devices:
            - driver: nvidia
              count: all
              capabilities: [gpu]
4. Dizin izinleri ve başlatma
sudo mkdir -p /opt/jellyfin/config /opt/jellyfin/cache /srv/media
sudo chown -R 1000:1000 /opt/jellyfin
sudo find /srv/media -type d -exec chmod 755 {} \;
sudo docker compose up -d
sudo docker compose ps
5. GPU container testi
sudo docker exec jellyfin nvidia-smi
sudo docker exec jellyfin /usr/lib/jellyfin-ffmpeg/ffmpeg -version
sudo docker logs --tail 100 jellyfin
6. Transcode doğrulama
watch -n 1 nvidia-smi
sudo docker exec jellyfin sh -lc "ls -lah /cache/transcodes"
sudo docker logs -f jellyfin | grep -Ei "ffmpeg|nvenc|nvdec|transcod"
7. Yedekleme
sudo docker stop jellyfin
sudo tar -C /opt/jellyfin -czf /root/jellyfin-config-$(date +%F).tar.gz config
sudo docker start jellyfin
sha256sum /root/jellyfin-config-$(date +%F).tar.gz
8. Nginx reverse proxy
sudo apt update
sudo apt install -y nginx certbot python3-certbot-nginx
sudo tee /etc/nginx/sites-available/media.example.com > /dev/null <<'NGINX'
server {
    listen 80;
    listen [::]:80;
    server_name media.example.com;
    client_max_body_size 10G;
    proxy_read_timeout 3600;
    proxy_send_timeout 3600;
    location / {
        proxy_pass http://127.0.0.1:8096;
        proxy_http_version 1.1;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
    }
}
NGINX
sudo ln -s /etc/nginx/sites-available/media.example.com /etc/nginx/sites-enabled/media.example.com
sudo nginx -t
sudo systemctl reload nginx
9. Let’s Encrypt SSL ve yenileme testi
sudo certbot --nginx -d media.example.com --redirect --agree-tos --no-eff-email -m [email protected]
sudo certbot renew --dry-run
curl -I https://media.example.com
openssl s_client -connect media.example.com:443 -servername media.example.com </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer -dates

What to know before production

Production note
Jellyfin Media Server Setup must be isolated behind HTTPS; databases, queues and internal APIs must not be published directly to the internet.
Production note
Pin tested image versions before production. Read release notes and take an application-consistent backup before database migrations.
Production note
A database dump alone may be incomplete. Preserve persistent files, configuration, encryption keys and the exact deployed version together.
Production note
Validate the installation with a real transaction or workload, then reboot the host and confirm automatic recovery before accepting production traffic.

Common failures and root causes

Belirti / SymptomKök neden ve çözüm / Root cause and fix
Service or container does not startInspect compose configuration, dependency health, file permissions and the first fatal log line instead of repeatedly restarting.
Domain opens but HTTPS failsCheck A/AAAA records, ports 80/443, proxy mode, certificate challenge and conflicting reverse proxies.
Application cannot reach its database or queueUse the internal service hostname, verify credentials and health checks, and keep database ports off the public interface.
Works initially but fails under loadMeasure memory peaks, disk latency, connection pools and worker concurrency; increase capacity only after identifying the bottleneck.

Post-installation validation checklist

  • All services are running and their health checks pass
  • The public hostname serves a valid HTTPS certificate
  • Only explicitly required ports are reachable
  • Administrator MFA and recovery access are configured
  • Backup checksums have been recorded
  • A restore was completed in an isolated environment
  • Logs contain no repeating critical failure
  • Services recover automatically after a host reboot

Official technical sources

Related EKA Sunucu guides

Frequently asked questions

Is this suitable for production?

Yes after secrets are replaced, public access is restricted and a complete restore test has succeeded.

Are minimum resources enough?

Minimums only prove the software can start. Size CPU, memory, IOPS and storage from representative workload measurements.

Can I use Cloudflare?

Yes. Use Full (strict) TLS and configure origin certificates, WebSockets and client IP forwarding where required.

Should upgrades be automatic?

Do not automatically apply major releases. Review migrations, back up data and retain the previous tested image.

What must be backed up?

Back up databases, uploaded files, persistent volumes, configuration, encryption keys and the deployed version together.

VPS or GPU server?

An NVMe VPS fits normal web workloads. Inference, accelerated OCR and video transcoding may require a compatible GPU.

Contact us for deployment

Deploy Jellyfin with Docker on Ubuntu, including media permissions, Nginx HTTPS, NVIDIA Container Toolkit, NVENC/NVDEC transcoding, remote access, backup and real GPU verification.

Explore GPU serversContact us for deployment
Top