Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

nixarr — Media Management

Purpose

nixarr is the media management host for the fleet. All downloading happens through a VPN tunnel so P2P traffic is isolated.

Entry Point

Architecture / Services / Scope

Playback

  • Jellyfin: Media server with hardware-accelerated transcoding (VA-API via /dev/dri/renderD128), hardware encoding for HEVC and hardware decoding for AV1/H.264/HEVC/VP9.

Media Management (“arr” stack)

AppRole
RadarrMovie management
SonarrTV series management
ProwlarrIndexer management for the whole stack
LidarrMusic management
ReadarrBook management
BazarrSubtitle management
TransmissionBitTorrent downloader (Flood UI, cross-seed)
SabnzbdUsenet downloader
SeerrUser-facing media request portal

Networking / VPN

  • All downloading apps run inside a WireGuard VPN namespace (vpnNamespaces.wg) so P2P/usenet traffic egresses through the VPN rather than the host’s normal connection.
  • The VPN config is provided as a sops binary secret (wg.conf) that restarts wg.service when rotated.
  • Access to VPN-isolated apps is allowed from the LAN and the configured tailnet; see the Tailscale module documentation for the cluster’s tailnet integration.

Authentication

  • An arr-services Kanidm OAuth2 context restricts the media apps to the sysadmin group on the Identity Coordinator.

Secrets

Declared secrets

Secret keyPurpose
wireguardWireGuard VPN config (binary, wg.conf)

Operational Notes / Assumptions

  • VPN download services restart on failure and wait for wg.service to come up before starting, so they don’t fail during early boot when networking isn’t ready.
  • Hardware transcoding relies on the host exposing a working /dev/dri device.
  • Media apps are exposed through the IO Coordinator reverse proxy.

References