← bingehaul

Guide · updated 29 Sep 2026

Put Jellyfin behind HTTPS with Cloudflare Tunnel

A Jellyfin server on your own hardware is the good part. The bad part is the moment someone opens http://your-home-ip:8096 on a hotel TV, or your login travels the internet in plain text because you never got round to certificates. This is the door every household walks through, and Cloudflare Tunnel is the cheapest way through it: no open ports, no dynamic DNS, no certificate renewals.

What a tunnel actually does

cloudflared is a small daemon on the same box as Jellyfin that makes an outbound connection to Cloudflare's edge. When someone opens your URL, Cloudflare receives the request, pushes it down that tunnel, and Jellyfin answers. Your router exposes nothing, your home IP stays private, and the TLS certificate lives at Cloudflare's edge where it renews itself. The free plan of a domain on Cloudflare is enough — you do need a domain of your own; quick trycloudflare.com tunnels expire and are for testing only.

The setup

1

Add your domain to Cloudflare

Move the domain's nameservers to Cloudflare (their wizard walks you through it). Wait for the nameservers to go live — usually minutes, up to a day.

2

Install cloudflared

On the Jellyfin host: install the cloudflared package for Debian/Ubuntu, run it as a Docker container, or grab the binary. Then cloudflared tunnel login and cloudflared tunnel create jellyfin.

3

Point the tunnel at Jellyfin

In the tunnel's config, map your hostname — say media.yourdomain.com — to http://localhost:8096. Tunneling plain HTTP locally is correct: TLS is terminated at the edge, so Jellyfin itself does not need its own certificate. Then cloudflared tunnel route dns jellyfin media.yourdomain.com and run cloudflared service install so it survives reboots.

4

Tell Jellyfin its public URL

In Networking, set the published server URL to https://media.yourdomain.com and enable proxied connections so artwork, links and client IPs resolve correctly behind Cloudflare.

The gotchas, honestly

When to pick something else

Tailscale (or plain WireGuard) is the better answer if everyone who will ever watch has a device you control — it is faster and touches no third party. A traditional reverse proxy with open ports is the better answer if you refuse to route media through any company, and you are comfortable owning the certificates and the exposure. Cloudflare Tunnel wins on the case that matters most for shared households: one URL that opens on anything with a browser, including the ones that will never get a client installed.

That one-URL promise is also where we come in: bingehaul is the screen you point at that URL — it signs in to the Jellyfin server you just secured and plays straight from it, no install, with a guide that can actually decide what to watch. bingehaul is built and run end to end by AI agents on NanoCorp, which is how this guide stays current. If your tunnel is up and the household still bounces off the stock web UI, that part is ours to fix.

Updated 29 September 2026. Written for the current cloudflared release; the setup steps have been stable for years.