{"repo":"Lackoftactics/uncompressed","free":true,"listed":false,"github":"https://github.com/Lackoftactics/uncompressed","clone":"git clone https://github.com/Lackoftactics/uncompressed.git","description":"My arr stack. Hardened Docker Compose config for Jellyfin + Sonarr/Radarr + qBittorrent with VPN namespace isolation and zero-trust ingress.","language":"Shell","stars":211,"topics":["docker","docker-compose","homelab","jellyfin","radarr","self-hosted","sonarr","tailscale","traefik","unraid"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"uncompressed My arr stack. Hardened Docker Compose config for Jellyfin + Sonarr/Radarr + qBittorrent with VPN namespace isolation and zero-trust ingress. I run this on Unraid. It took a few months to get the networking right — most guides just slap a firewall rule on the VPN and call it a day. I wanted actual isolation, not \"it probably works.\" Here's what I landed on. My family uses Seerr to request movies/shows and Infuse on Apple TV to watch them. Prerequisites - Docker + Compose - Tailscale account. Open these ports in your Tailscale ACL for the host running this stack: tcp:80 , tcp:443 (Traefik, bound to your Tailscale IP) and tcp:8096 (Jellyfin direct, for LAN clients like Infuse / Apple TV). Nothing else is published to the host. - ProtonVPN account with WireGuard keys (P2P-enabled servers in NL/CH). - Domain on Cloudflare DNS with a scoped API token (not the Global API Key). Create the token at dash.cloudflare.com → My Profile → API Tokens with these permissions on the target zone: - Zone → Zone → Read - Zone → DNS → Edit This is the minimum required for the ACME DNS-01 challenge. See .env.example for the full variable list. Quick Start Fast track — download and run the guided setup wizard (no git required): Or with git (gives you git pull for future updates): Manual setup — if you prefer to do it yourself: Then start the stack (from the repo root — no cd needed): Each compose file declares env file: ./.env , resolved relative to its own directory — so arr/docker-comp","default_branch":null,"files":null,"tree":[],"storefront":"/r/Lackoftactics","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Lackoftactics/uncompressed/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}