Jellyfin: Media server with hardware-accelerated transcoding (VA-API via /dev/dri/renderD128), hardware encoding for HEVC and hardware decoding for AV1/H.264/HEVC/VP9.
All downloading apps run inside a WireGuard VPN namespace (vpnNamespaces.wg) so P2P/usenet traffic egresses through the VPN rather than the host’s normal connection.
The VPN config is provided as a sops binary secret (wg.conf) that restarts wg.service when rotated.
Access to VPN-isolated apps is allowed from the LAN and the configured tailnet; see the Tailscale module documentation for the cluster’s tailnet integration.
VPN download services restart on failure and wait for wg.service to come up before starting, so they don’t fail during early boot when networking isn’t ready.
Hardware transcoding relies on the host exposing a working /dev/dri device.
Media apps are exposed through the IO Coordinator reverse proxy.