-
Notifications
You must be signed in to change notification settings - Fork 0
Access from outside your network
Marquee runs on your LAN and speaks plain HTTP. Three ways to reach it from elsewhere, best first. The README's Access from outside your network section has the same guidance alongside the install steps.
The tunnel dials out from your server, so nothing is exposed inbound: no open ports, your home IP stays private, and you get HTTPS on your own domain.
- Point a domain at Cloudflare (the free plan is enough).
- Zero Trust dashboard → Networks → Tunnels → Create a tunnel → Cloudflared.
- Install the connector on the server — on Unraid, the cloudflared app from Community Applications, with the token the dashboard gives you.
- Add a public hostname:
marquee.example.com→ HTTP →<server-ip>:3000. - Visit the domain. Certificates are handled for you.
Forward a router port to <server-ip>:3000. It works, and it's the least safe
option: your home IP is public, there's no HTTPS without a reverse proxy, and
the login page faces the internet. Sign-ins are rate limited and passwords are
hashed with argon2, but a tunnel is still better. Never forward the database
port.
To require a stronger login — with 2FA — before anyone reaches Marquee's own login page:
- Cloudflare Access is simplest if you already tunnel: add an Application for the hostname and a policy (your email addresses, a one-time PIN, a social login).
- Authelia keeps it self-hosted, and needs a reverse proxy that supports forward auth — Traefik, Caddy or Nginx Proxy Manager — because a tunnel alone can't ask another service whether a request is allowed. Point the tunnel at the proxy, and the proxy at Marquee.
Exempt the API, or the Mac app stops working. Marquee for Mac
signs in with a bearer token on /api/v1; a browser login portal in front of
it blocks that. Add a bypass rule for /api/v1* (or a Cloudflare Access
service token), or use the LAN address when you're home. Marquee authenticates
those requests itself. Sonarr/Radarr webhooks stay on the LAN and are
unaffected unless you deliberately route them through the domain.
Marquee is self-hosted and beta — open an issue if something here is wrong or missing.