Jellyfin

Jellyfin is the free and open-source media server that provides the playback interface for the entire media stack. It streams content organized by Sonarr and Radarr to any device with a web browser or native client.

Deployment Details

SettingValue
Imageghcr.io/jellyfin/jellyfin (tag and digest pinned in values.yaml)
Namespacemedia
Gatewayenvoy-external
URLjellyfin.wibrow.dev
Nodeworker-04 (pinned; tolerates the dedicated=media-home:NoSchedule taint)
LoadBalancer IP10.20.10.229

GPU Transcoding

Jellyfin is configured for hardware-accelerated transcoding using Intel Quick Sync Video (QSV) on worker-04's Intel iGPU. The pod adds supplemental groups 44 and 109 (video, render) for /dev/dri access and runs as UID/GID 2000.

GPU resource allocation
resources:
  requests:
    cpu: 10m
    gpu.intel.com/i915: 1
    memory: 320Mi
  limits:
    gpu.intel.com/i915: 1
    memory: 8192M

The node selector ensures Jellyfin runs on a node with an Intel GPU:

yaml
nodeSelector:
  intel.feature.node.kubernetes.io/gpu: "true"
  kubernetes.io/arch: amd64
  kubernetes.io/hostname: "worker-04"

Storage

Jellyfin uses these volumes:

MountSourcePurpose
/configPVC jellyfin (10Gi, pvc component, backed up by kopiur)Server configuration and database
/config/metadataPVC jellyfin-cache (50Gi, openebs-hostpath, not backed up)Metadata and image cache
/data/nas-mediaNFS data:/volume1/mediaMedia library (Synology NAS)
/cache, /config/log, /tmpemptyDirTemporary files, logs
NFS media mount
persistence:
  media:
    type: nfs
    server: data
    path: /volume1/media
    advancedMounts:
      jellyfin:
        app:
          - path: /data/nas-media

Configuration

Environment Variables

VariableValuePurpose
DOTNET_SYSTEM_IO_DISABLEFILELOCKINGtruePrevents file locking issues on NFS volumes
JELLYFIN_PublishedServerUrlhttps://jellyfin.wibrow.devURL advertised to clients

Service

Jellyfin is also exposed as a LoadBalancer service with a dedicated Cilium LBIPAM IP (10.20.10.229), allowing direct access from the LAN without going through Envoy Gateway. This enables native client discovery via DLNA or Jellyfin's UDP broadcast.

LoadBalancer service
service:
  app:
    controller: jellyfin
    type: LoadBalancer
    annotations:
      lbipam.cilium.io/ips: "10.20.10.229"
    ports:
      http:
        port: 8096

Route Configuration

HTTPRoute via envoy-external
route:
  app:
    hostnames:
      - jellyfin.wibrow.dev
    parentRefs:
      - name: envoy-external
        namespace: networking
        sectionName: https