I’ve been trying to upgrade from 10.10 to 10.11 for a while now, as the Android TV app keeps nagging me, and every attempt ended with impossibly long library scan times.

After some thorough investigation, it appeared that a Home Videos type collection causes unending scan (yet to be solved), but also that Jellyfin does a lot of writes to the config directory (either database or metadata or both). Mine’s on spinning media part of a ZFS pool. I tried a few performance tuning options, such as testing the config dir with recordsize (similar to block size) of 4K, 8K, 64K, 128K and library scans fell from 30-40 minutes down to 8-13min with 4K-64K. The ZFS tuning wiki suggest 64K recordsize with LZ4 compression for SQLite workloads such as Jellyfin. That seems to work as well as 4K and 8K but likely is faster when reading thumbnails and such.

Note that upgrading to 12-rc3, which is supposed to speed up library scans did not improve scan times for me. Optimizing config/database write speed did. I cross-checked the culprit by experimenting with moving the config dir to NVMe and RAM. Both of those got the scan times down to 8-9 minutes compared to the optimized spinning media’s 12-13.

So if you had upgraded (or about to) to 10.11 your library scans are (about to get) dog slow and your Jellyfin’s config dir resides on spinning media, optimize its write performance for SQLite.

        • nibbs@lemmy.zip
          link
          fedilink
          English
          arrow-up
          1
          ·
          22 hours ago

          Hi, could you tell me why? I mean, I think I understand the basics of the risk of brute force attacks. My mitigation for the admin account is, not to allow login outside the local network. Users are allowed from anywhere, as my family uses the library. Also my service (there are others) are routed through NGINX.

          Do you have tips for external users using, for example, a VPN only for specific addresses / IPs? At least that was an idea I had, but didn’t got got around to dig for solutions.

          Thanks in advance.

        • HereIAm@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          22 hours ago

          Why not? Unless you’re talking about unauthenticated steaming of media if you reverse engineer a servers folder structure.

                • HereIAm@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  6 hours ago

                  I think you’ve fundamentally misunderstood some of their communication.

                  There’s the issue I described earlier where it is possible to stream files unauthenticated if you know the folder structure on the video. The devs have responded that they won’t fix this. Outside of streaming content, there’s no other access through this mean. https://github.com/jellyfin/jellyfin/issues/1501

                  Then there’s the release of 10.11.7 that fixed a number of security issues. https://github.com/jellyfin/jellyfin/releases/tag/v10.11.7 with no major security issues since then. And all the issues were privilagr escalation for a normal user account on jellyfin. So the attacker would already needed to have an account on your server, and only the data that jellyfin could see was at risk, nothing escaped contagion so to say.

                  They also officially support a reverse proxy set up: https://jellyfin.org/docs/general/post-install/networking/reverse-proxy/.

                  I have no idea where you’ve got the idea where they themselves claim it’s unsecure to open it to the internet. Of course there’s always a risk associated with exposing something, but jellyfin doesn’t pose any larger risk than anything else you might publish.

                  • GoatSynagogue@lemmy.world
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    5 hours ago

                    Accessing files unauthenticated……the devs explicitly say they won’t fix it…… and you think that’s not a huge security hole? Software with something like that marked as “won’t fix” is a giant no-no for me. If they’re ok with that, their software should be nowhere near an internet connection.

                    The person with a fundamental misunderstanding is you.

    • amorpheus@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      2 days ago

      That’s the nice thing about Plex, you just stream your Plex library using Plex, and Plex is also the only place you and anyone you share with need to log in.