{ "schema_version": "0.4.0", "kind": "proxmenux.oci-template", "id": "linuxserver-jellyfin", "status": "generated-unvalidated", "catalog_ui": { "title": { "en_US": "Jellyfin" }, "tagline": { "en_US": "LinuxServer Jellyfin with optional GPU passthrough" }, "description": { "en_US": "Jellyfin is a Free Software Media System that puts you in control of managing and streaming your media. It is an alternative to the proprietary Emby and Plex, to provide media from a dedicated server to end-user devices via multiple apps. Jellyfin is descended from Emby's 3.5.2 release and ported to the .NET Core framework to enable full cross-platform support. There are no strings attached, no premium licenses or features, and no hidden agendas: just a team who want to build something better and work together to achieve it." }, "category": "media", "category_label": "Media & Streaming", "author": "LinuxServer.io", "developer": null, "icon": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/jellyfin-icon.png", "thumbnail": "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/jellyfin-banner.png", "screenshots": [], "architectures": [ "amd64", "arm64" ], "launch": { "scheme": "http", "port": 8096, "path": "/" }, "website": "https://github.com/jellyfin/jellyfin", "documentation": "https://docs.linuxserver.io/images/docker-jellyfin/", "repository": "https://github.com/linuxserver/docker-jellyfin", "tips": [ "VA-API and OpenCL tone mapping are separate capabilities. The tested LinuxServer image provides AMD VA-API; AMD OpenCL required the official jellyfin-amd mod.", "Choose AMD + OpenCL or Intel + OpenCL to install the corresponding official LinuxServer mod at startup. These are options for the same image, not additional catalog variants.", "ProxMenux passes explicit device paths through ATTACHED_DEVICES_PERMS so the native LinuxServer init grants the service user access. No privileged LXC or mode 0777 is needed.", "Optional Jellyfin settings are persisted in /config/encoding.xml. AMD OpenCL and VA-API were tested on Lucienne; Intel OpenCL remains untested in this laboratory. Dolby Vision support depends on the source profile and FFmpeg/GPU capabilities." ], "mini_changelog": [ { "date": "2026-07-14", "note": "Rebase to Ubuntu Resolute." }, { "date": "2026-03-02", "note": "Add support for IPv6 OOTB." }, { "date": "2025-10-20", "note": "Add libjemalloc2 as runtime dep." }, { "date": "2024-10-06", "note": "Fix fontconfig cache path." }, { "date": "2024-08-13", "note": "Rebase to Ubuntu Noble." } ], "display_version": null, "updated_at": "2026-07-14" }, "source": { "provider": "linuxserver.io", "repository": "https://github.com/linuxserver/docker-jellyfin", "default_branch": "master", "revision": "868a7bb1f2aa77b87a75e128da7b1869c19b0623", "readme_raw_url": "https://raw.githubusercontent.com/linuxserver/docker-jellyfin/868a7bb1f2aa77b87a75e128da7b1869c19b0623/README.md", "readme_pushed_at": "2026-09-08T02:43:27Z", "compose_sha256": "933be53b6f9fe99d1c56fad3abe6b1122c448bd9449d8aa4ca8c2ae4ce89ab77", "generated_at": "2026-09-14T14:56:07+00:00" }, "container_contract": { "service_name": "jellyfin", "container_name": "jellyfin", "image": { "reference": "lscr.io/linuxserver/jellyfin:latest", "registry": "lscr.io", "repository": "lscr.io/linuxserver/jellyfin", "tag": "latest", "digest": null, "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" }, "environment": [ { "name": "PUID", "example": "1000", "required": true, "sensitive": false, "source": "linuxserver-compose" }, { "name": "PGID", "example": "1000", "required": true, "sensitive": false, "source": "linuxserver-compose" }, { "name": "TZ", "example": "Etc/UTC", "required": true, "sensitive": false, "source": "linuxserver-compose" } ], "volumes": [ { "id": "volume-0", "container_path": "/config", "compose_source_example": "/path/to/jellyfin/library", "read_only": false, "required": true, "installation_choice": [ "managed-volume", "host-bind" ], "default": "managed-volume", "managed_volume": { "backup": true, "default_size_gb": 16 } }, { "id": "volume-1", "container_path": "/data/tvshows", "compose_source_example": "/path/to/tvseries", "read_only": false, "required": true, "installation_choice": [ "managed-volume", "host-bind" ], "default": "managed-volume", "managed_volume": { "backup": true, "default_size_gb": 8 } }, { "id": "volume-2", "container_path": "/data/movies", "compose_source_example": "/path/to/movies", "read_only": false, "required": true, "installation_choice": [ "managed-volume", "host-bind" ], "default": "managed-volume", "managed_volume": { "backup": true, "default_size_gb": 8 } } ], "ports": [ { "container_port": 8096, "published_example": 8096, "protocol": "tcp", "required": true, "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" }, { "container_port": 8920, "published_example": 8920, "protocol": "tcp", "required": false, "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" }, { "container_port": 7359, "published_example": 7359, "protocol": "udp", "required": false, "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" }, { "container_port": 1900, "published_example": 1900, "protocol": "udp", "required": false, "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" } ], "related_services": [], "restart": "unless-stopped", "stop_grace_period": null, "original_compose": "---\nservices:\n jellyfin:\n image: lscr.io/linuxserver/jellyfin:latest\n container_name: jellyfin\n environment:\n - PUID=1000\n - PGID=1000\n - TZ=Etc/UTC\n - JELLYFIN_PublishedServerUrl=http://192.168.0.5 #optional\n volumes:\n - /path/to/jellyfin/library:/config\n - /path/to/tvseries:/data/tvshows\n - /path/to/movies:/data/movies\n ports:\n - 8096:8096\n - 8920:8920 #optional\n - 7359:7359/udp #optional\n - 1900:1900/udp #optional\n restart: unless-stopped\n" }, "first_run": { "endpoints": [ { "label": "Web UI", "scheme": "http", "port": 8096, "path": "/", "source": "compose-first-tcp-port-fallback" } ], "credentials": [] }, "proxmox": { "runtime": "native-oci-lxc", "technology_status": "proxmox-technology-preview", "defaults": { "unprivileged": true, "ostype": "auto-from-image", "cores": 2, "memory_mb": 2048, "swap_mb": 512, "rootfs_size_gb": 8, "rootfs_storage": "local-lvm", "volume_storage": "local-lvm", "template_storage": "local", "bridge": "vmbr0", "ipv4": "dhcp", "firewall": true, "host_managed_network": true, "onboot": false, "features": [ "nesting=1" ], "shutdown_timeout_seconds": 30 }, "image_metadata_policy": { "entrypoint": "import-from-oci-image", "cmd": "import-from-oci-image", "environment": "import-image-env-then-apply-compose-overrides", "user": "import-from-oci-image", "working_dir": "import-from-oci-image", "stop_signal": "import-from-oci-image" }, "adaptations": [ { "id": "dedicated-lxc-network", "upstream_behavior": "Docker publishes selected container ports on the Docker host.", "native_lxc_behavior": "The application listens on the same container ports at its dedicated LXC address.", "reason": "A native LXC has its own address and does not require Docker port NAT.", "behavioral_impact": "Users open the LXC address instead of the Proxmox host address.", "validation": "pending-per-application" }, { "id": "compose-environment-overlay", "upstream_behavior": "Compose environment values override OCI image environment values.", "native_lxc_behavior": "ProxMenux merges the same values into lxc.environment.runtime while the CT is stopped.", "reason": "PVE imports image Env automatically; Compose values still need to override it.", "behavioral_impact": "None expected.", "validation": "pending-per-application" }, { "id": "stop-grace-period", "upstream_behavior": "Docker waits for Compose stop_grace_period before forcing termination.", "native_lxc_behavior": "ProxMenux records the same timeout for its pct shutdown lifecycle operations.", "reason": "Proxmox has no equivalent per-CT persistent restart-policy field; startup.down is not a shutdown timeout.", "behavioral_impact": "Normal Proxmox node shutdown remains governed by the node-wide shutdown policy.", "validation": "not-requested-by-compose" }, { "id": "compose-shm-size", "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", "behavioral_impact": "None expected.", "validation": "not-requested-by-compose" }, { "id": "compose-command", "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", "reason": "Proxmox stores the effective OCI process as one entrypoint string.", "behavioral_impact": "None expected.", "validation": "not-requested-by-compose" }, { "id": "compose-process-runtime", "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", "reason": "The OCI process must start with the same identity, command and working directory without Docker.", "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", "validation": "not-requested-by-compose" }, { "id": "compose-healthcheck", "upstream_behavior": "Docker periodically executes the declared container healthcheck.", "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", "behavioral_impact": "The check runs during installation rather than continuously after installation.", "validation": "not-requested-by-compose" }, { "id": "compose-cpu-priority", "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", "reason": "Both settings express relative CPU priority on different scales.", "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", "validation": "not-requested-by-compose" }, { "id": "compose-network-identity", "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", "validation": "not-requested-by-compose" }, { "id": "compose-network-mode", "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", "reason": "The LXC is the application host and already has its own address and port namespace.", "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", "validation": "not-requested-by-compose" }, { "id": "compose-capabilities-and-sysctls", "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", "validation": "not-requested-by-compose" }, { "id": "docker-engine-metadata", "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", "validation": "not-requested-by-compose" }, { "id": "compose-device-passthrough", "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", "validation": "not-requested-by-compose" }, { "id": "compose-host-ipc", "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", "validation": "not-requested-by-compose" } ], "deployment_profile": { "variant": "hardware-selectable", "gpu_passthrough": "installer-selection" }, "installer_profile": { "hardware_acceleration": { "prompt": "Hardware acceleration for Jellyfin", "default": "none", "profiles": [ { "id": "none", "label": "No acceleration (CPU)", "device_requests": [] }, { "id": "vaapi", "label": "Intel/AMD VA-API (no OpenCL mod)", "device_requests": [ { "id": "vaapi-render", "kind": "character-device", "purpose": "vaapi", "path_prompt": "GPU render device", "host_path_default": "/dev/dri/renderD128", "container_path_strategy": "same-as-host", "mode": "0660", "deny_write": false, "gid_strategy": "host-device-gid", "environment": [ { "name": "LIBVA_DRIVER_NAME", "prompt": "VA-API driver", "choices": [ "auto", "radeonsi", "iHD", "i965" ], "default": "auto", "omit_values": [ "auto" ] } ] } ], "environment_from_devices": { "ATTACHED_DEVICES_PERMS": [ "vaapi-render" ] } }, { "id": "amd-opencl", "label": "AMD VA-API + OpenCL (official mod)", "device_requests": [ { "id": "vaapi-render", "kind": "character-device", "purpose": "vaapi", "path_prompt": "GPU render device", "host_path_default": "/dev/dri/renderD128", "container_path_strategy": "same-as-host", "mode": "0660", "deny_write": false, "gid_strategy": "host-device-gid", "drm_vendor_ids": [ "0x1002", "0x1022" ] }, { "id": "amd-kfd", "kind": "character-device", "purpose": "amd-opencl", "path_prompt": "AMD KFD device", "host_path_default": "/dev/kfd", "container_path_strategy": "same-as-host", "mode": "0660", "deny_write": false, "gid_strategy": "host-device-gid" } ], "environment_from_devices": { "ATTACHED_DEVICES_PERMS": [ "vaapi-render", "amd-kfd" ] }, "environment": [ { "name": "DOCKER_MODS", "value": "linuxserver/mods:jellyfin-amd" } ], "post_start_configurations": [ { "id": "jellyfin-amd-opencl", "type": "jellyfin-encoding-xml", "enable_prompt": "Enable VA-API, hardware encoding and OpenCL tone mapping in Jellyfin", "enabled_default": true, "required": true, "timeout_seconds": 120, "candidate_paths": [ "/config/encoding.xml" ], "settings": { "HardwareAccelerationType": "vaapi", "VaapiDevice": { "device_path_from": "vaapi-render" }, "EnableHardwareEncoding": "true", "EnableTonemapping": "true", "EnableVppTonemapping": "false" } } ], "architectures": [ "amd64" ] }, { "id": "intel-opencl", "label": "Intel VA-API + OpenCL (official mod)", "device_requests": [ { "id": "vaapi-render", "kind": "character-device", "purpose": "vaapi", "path_prompt": "GPU render device", "host_path_default": "/dev/dri/renderD128", "container_path_strategy": "same-as-host", "mode": "0660", "deny_write": false, "gid_strategy": "host-device-gid", "drm_vendor_ids": [ "0x8086" ] } ], "environment_from_devices": { "ATTACHED_DEVICES_PERMS": [ "vaapi-render" ] }, "environment": [ { "name": "DOCKER_MODS", "value": "linuxserver/mods:jellyfin-opencl-intel" } ], "post_start_configurations": [ { "id": "jellyfin-intel-opencl", "type": "jellyfin-encoding-xml", "enable_prompt": "Enable VA-API, hardware encoding and OpenCL tone mapping in Jellyfin", "enabled_default": true, "required": true, "timeout_seconds": 120, "candidate_paths": [ "/config/encoding.xml" ], "settings": { "HardwareAccelerationType": "vaapi", "VaapiDevice": { "device_path_from": "vaapi-render" }, "EnableHardwareEncoding": "true", "EnableTonemapping": "true", "EnableVppTonemapping": "false" } } ], "architectures": [ "amd64" ] }, { "id": "nvidia", "label": "NVIDIA (NVENC/NVDEC)", "device_requests": [ { "id": "nvidia-runtime", "kind": "nvidia-runtime", "purpose": "nvidia-cuda-nvenc-nvdec", "device_selection": "all-requested-by-compose" } ], "environment": [ { "name": "NVIDIA_VISIBLE_DEVICES", "value": "all" } ] } ] }, "startup_healthcheck": { "scheme": "http", "port": 8096, "path": "/System/Info/Public", "timeout_seconds": 600, "request_timeout_seconds": 10, "stability_seconds": 4, "verify_tls": false }, "gpu_validation": { "device_inventory": "host-sysfs-and-stat", "application_acceleration": "requires-workload-test", "tone_mapping": "not-implied-by-device-access" }, "device_permissions": { "strategy": "linuxserver-native-init", "service_user": "abc", "environment": "ATTACHED_DEVICES_PERMS", "paths": "all-resolved-selected-character-devices" } }, "application_options": { "hdr10_dolby_vision_tone_mapping": { "show_in_catalog": true, "selectable": true, "provided_by_image": false, "configuration": "Optional official LinuxServer GPU mod and persistent Jellyfin encoding settings", "scope": "OpenCL tone mapping; not a guarantee for every HDR/Dolby Vision source" } }, "gpu_lab_references": { "amd_mod": "https://github.com/linuxserver/docker-mods/tree/jellyfin-amd", "intel_mod": "https://github.com/linuxserver/docker-mods/tree/jellyfin-opencl-intel" } }, "compatibility": { "automatic_install_candidate": true, "validated": false, "supported_compose_keys": [ "cap_add", "command", "container_name", "cpu_shares", "devices", "entrypoint", "environment", "extra_hosts", "group_add", "healthcheck", "hostname", "image", "init", "ipc", "labels", "logging", "mac_address", "network_mode", "networks", "ports", "privileged", "restart", "runtime", "security_opt", "shm_size", "stdin_open", "stop_grace_period", "sysctls", "tty", "user", "volumes", "working_dir" ], "untranslated_blockers": [], "policy": "A generated template is never promoted to validated without install, health, restart and persistence tests." }, "validation": { "schema": "passed-at-generation", "clean_install": "pending", "service_health": "pending", "restart_persistence": "pending", "backup_restore": "pending", "update_preserves_data": "pending" }, "lifecycle": { "update_strategy": "replace-rootfs-from-new-oci-image-preserve-managed-volumes", "registry_state": { "resolved_architecture": null, "resolved_digest": null, "image_version_label": null, "image_created": null }, "change_detection": "compare-resolved-architecture-digest", "automatic_unattended_updates": false } }