• 1 Post
  • 18 Comments
Joined 9 months ago
cake
Cake day: January 22nd, 2026

help-circle







  • I use Caddy with Authelia and Caddy MIB. Anything that I need access to is exposed via reverse proxy with Authelia infront of it. That sometimes mean I have to login twice. Caddy MIB makes it so repeat offenders are blocked for longer and longer. Prevents brute forcing stuff like Jellyfin.

    I am considering using Tailscale (or Headscale) because I could combine that with Mullvad VPN and still have my internal DNS. But I only have one server and I have hairpin NAT configured so I just enter my domain name inside and outside of my LAN and it just workstm. I also considered using Traefik but Caddy just just workstm. Only problem I had was with Dawarish needing brotli encryption, I had to create my own docker image (and then I automated keeping it up to date with Woodpecker CI and Renovate).

    All in all, I like the reverse proxy route.








  • No changes to the container image, but I had to fiddle with the config file. There is an option (tokenExpirationHours) to set for how long a token is valid, default is 2 hours. I can only find this in the commented example config, setting it to sometime really high like 50 let my friend upload his audiobooks without problems.

    Create a config file and place it somewhere the container can access it. Then add the environment variable FILEBROWSER_CONFIG=/some/path/to/your/config.yaml.

    Here is a snippet from my config:

    server:
      # ...
    auth:
      tokenExpirationHours: 50
      # ...
    userDefaults:
      fileLoading:
        maxConcurrentUpload: 100 # The inferface only shows up to 10 so I don't know if setting this value higher does anything
        uploadChunkSizeMb: 10
    

    tokenExpirationHours is the key to set.