Skip to content

Access from outside your network

AIDev edited this page Sep 17, 2026 · 1 revision

Access from outside your network

Marquee runs on your LAN and speaks plain HTTP. Three ways to reach it from elsewhere, best first. The README's Access from outside your network section has the same guidance alongside the install steps.

Cloudflare Tunnel and a domain (recommended)

The tunnel dials out from your server, so nothing is exposed inbound: no open ports, your home IP stays private, and you get HTTPS on your own domain.

  1. Point a domain at Cloudflare (the free plan is enough).
  2. Zero Trust dashboard → Networks → Tunnels → Create a tunnel → Cloudflared.
  3. Install the connector on the server — on Unraid, the cloudflared app from Community Applications, with the token the dashboard gives you.
  4. Add a public hostname: marquee.example.com → HTTP → <server-ip>:3000.
  5. Visit the domain. Certificates are handled for you.

Port forwarding

Forward a router port to <server-ip>:3000. It works, and it's the least safe option: your home IP is public, there's no HTTPS without a reverse proxy, and the login page faces the internet. Sign-ins are rate limited and passwords are hashed with argon2, but a tunnel is still better. Never forward the database port.

Authelia or Cloudflare Access

To require a stronger login — with 2FA — before anyone reaches Marquee's own login page:

  • Cloudflare Access is simplest if you already tunnel: add an Application for the hostname and a policy (your email addresses, a one-time PIN, a social login).
  • Authelia keeps it self-hosted, and needs a reverse proxy that supports forward auth — Traefik, Caddy or Nginx Proxy Manager — because a tunnel alone can't ask another service whether a request is allowed. Point the tunnel at the proxy, and the proxy at Marquee.

Exempt the API, or the Mac app stops working. Marquee for Mac signs in with a bearer token on /api/v1; a browser login portal in front of it blocks that. Add a bypass rule for /api/v1* (or a Cloudflare Access service token), or use the LAN address when you're home. Marquee authenticates those requests itself. Sonarr/Radarr webhooks stay on the LAN and are unaffected unless you deliberately route them through the domain.

Clone this wiki locally