Skip to content

Repository files navigation

Plex Media Server

Build Status Last Commit OCI Pulls

Personal media server that organizes and streams your movie, TV, and music collections to all your devices.

Port 32400
Registry ghcr.io/daemonless/plex
Source https://github.com/daemonless/plex
Website https://plex.tv/

Version Tags

Tag Description Best For
latest Upstream Binary. Built from official release. Most users — recommended.

Prerequisites

Before deploying, ensure your host environment is ready. See the Quick Start Guide for host setup instructions.

Deployment

Podman Compose

services:
  plex:
    image: "ghcr.io/daemonless/plex:latest"
    container_name: plex
    environment:
      - PUID=1000  # User ID for the application process
      - PGID=1000  # Group ID for the application process
      - TZ=UTC  # Timezone for the container
      - VERSION=container  # Plex update channel (container, public, plexpass)
      - PLEX_CLAIM=  # Claim token — get one at https://plex.tv/claim
      - ADVERTISE_IP=  # URLs clients should use to reach the server, comma-separated, e.g. http://192.168.1.10:32400 (bridge networking)
      - ALLOWED_NETWORKS=  # Networks allowed in without signing in, comma-separated, e.g. 192.168.1.0/24
    volumes:
      - "/path/to/containers/plex:/config"
      - "/path/to/containers/plex/transcode:/transcode" # optional
      - "/path/to/movies:/movies"
      - "/path/to/tv:/tv"
    ports:
      - "32400:32400"
    # always (not unless-stopped) so FreeBSD's podman rc.d auto-starts it at boot
    restart: always

Save as compose.yaml, then run podman-compose up -d.

AppJail Director

.env:

# .env

DIRECTOR_PROJECT=plex
PUID=1000
PGID=1000
TZ=UTC
VERSION=container
PLEX_CLAIM=
ADVERTISE_IP=
ALLOWED_NETWORKS=

appjail-director.yml:

# appjail-director.yml

options:
  - virtualnet: ':<random> default'
  - nat:
services:
  plex:
    name: plex
    options:
      - container: 'args:--pull'
      - expose: '32400:32400 proto:tcp'
    oci:
      user: root
      environment:
        - PUID: !ENV '${PUID}'
        - PGID: !ENV '${PGID}'
        - TZ: !ENV '${TZ}'
        - VERSION: !ENV '${VERSION}'
        - PLEX_CLAIM: !ENV '${PLEX_CLAIM}'
        - ADVERTISE_IP: !ENV '${ADVERTISE_IP}'
        - ALLOWED_NETWORKS: !ENV '${ALLOWED_NETWORKS}'
    volumes:
      - plex: /config
      - plex_transcode: /transcode
      - movies: /movies
      - tv: /tv
volumes:
  plex:
    device: '/path/to/containers/plex'
  plex_transcode:
    device: '/path/to/containers/plex/transcode'
  movies:
    device: 'movies'
  tv:
    device: 'tv'

Makejail:

# Makejail

ARG tag=latest

OPTION container=boot
OPTION overwrite=force
OPTION from=ghcr.io/daemonless/plex:${tag}

Save the files above, then run appjail-director up.

Warning

Exposing ports in AppJail means that your service can be reached from remote hosts. If that is not your intention, do not expose the ports and communicate with the service using the jail's IPv4 address or hostname assigned by the virtual network.

To avoid exposing ports, just remove the expose option in your appjail-director.yml or from your command-line arguments.

Podman CLI

podman run -d --name plex \
  -p 32400:32400 \
  -e PUID=1000 \
  -e PGID=1000 \
  -e TZ=UTC \
  -e VERSION=container \
  -e PLEX_CLAIM= \
  -e ADVERTISE_IP= \
  -e ALLOWED_NETWORKS= \
  -v /path/to/containers/plex:/config \
  -v /path/to/containers/plex/transcode:/transcode # optional \
  -v /path/to/movies:/movies \
  -v /path/to/tv:/tv \
  ghcr.io/daemonless/plex:latest

Save as run.sh, then run sh run.sh.

AppJail

appjail oci run -Pd \
  -o overwrite=force \
  -o container="args:--pull" \
  -o virtualnet=":<random> default" \
  -o nat \
  -o expose="32400:32400 proto:tcp" \
  -e PUID=1000 \
  -e PGID=1000 \
  -e TZ=UTC \
  -e VERSION=container \
  -e PLEX_CLAIM= \
  -e ADVERTISE_IP= \
  -e ALLOWED_NETWORKS= \
  -o fstab="/path/to/containers/plex /config <pseudofs>" \
  -o fstab="/path/to/containers/plex/transcode /transcode <pseudofs>" \ # optional
  -o fstab="/path/to/movies /movies <pseudofs>" \
  -o fstab="/path/to/tv /tv <pseudofs>" \
  ghcr.io/daemonless/plex:latest plex

Save the files above, then run sh run.sh.

Warning

Exposing ports in AppJail means that your service can be reached from remote hosts. If that is not your intention, do not expose the ports and communicate with the service using the jail's IPv4 address or hostname assigned by the virtual network.

To avoid exposing ports, just remove the expose option in your appjail-director.yml or from your command-line arguments.

Bastille

Warning

Bastille's OCI support is experimental. It requires buildah and shares the host network stack (inherit). Mount volumes with --volume HOST JAIL; without it, image-declared volumes are stored under ${bastille_volumesdir}/${jail}.

services:
  plex:
    name: plex
    image: "ghcr.io/daemonless/plex:latest"
    network:
      - mode: host
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=UTC
      - VERSION=container
      - PLEX_CLAIM=
      - ADVERTISE_IP=
      - ALLOWED_NETWORKS=
    volumes:
      - "/path/to/containers/plex:/config"
      - "/path/to/containers/plex/transcode:/transcode"
      - "/path/to/movies:/movies"
      - "/path/to/tv:/tv"

Save as bastille-compose.yml, then run bastille up. Or via CLI:

bastille create -O \
  --env PUID=1000 \
  --env PGID=1000 \
  --env TZ=UTC \
  --env VERSION=container \
  --env PLEX_CLAIM= \
  --env ADVERTISE_IP= \
  --env ALLOWED_NETWORKS= \
  --volume /path/to/containers/plex /config \
  --volume /path/to/containers/plex/transcode /transcode \
  --volume /path/to/movies /movies \
  --volume /path/to/tv /tv \
  plex ghcr.io/daemonless/plex:latest inherit

Ansible

- name: Deploy plex
  containers.podman.podman_container:
    name: plex
    image: "ghcr.io/daemonless/plex:latest"
    state: started
    restart_policy: always
    env:
      PUID: "1000"
      PGID: "1000"
      TZ: "UTC"
      VERSION: "container"
      PLEX_CLAIM: ""
      ADVERTISE_IP: ""
      ALLOWED_NETWORKS: ""
    ports:
      - "32400:32400"
    volumes:
      - "/path/to/containers/plex:/config"
      - "/path/to/containers/plex/transcode:/transcode" # optional
      - "/path/to/movies:/movies"
      - "/path/to/tv:/tv"

Save as plex-deploy.yaml, then run ansible-playbook plex-deploy.yaml.

Access at: http://localhost:32400

Parameters

Environment Variables

Variable Default Description
PUID 1000 User ID for the application process
PGID 1000 Group ID for the application process
TZ UTC Timezone for the container
VERSION container Plex update channel (container, public, plexpass)
PLEX_CLAIM `` Claim token — get one at https://plex.tv/claim
ADVERTISE_IP `` URLs clients should use to reach the server, comma-separated, e.g. http://192.168.1.10:32400 (bridge networking)
ALLOWED_NETWORKS `` Networks allowed in without signing in, comma-separated, e.g. 192.168.1.0/24

Volumes

Path Description
/config Configuration directory
/transcode Transcode directory (Optional)
/movies Movie library
/tv TV series library

Ports

Port Protocol Description
32400 TCP Web UI

First-time setup

An unclaimed Plex server only accepts its setup wizard from 127.0.0.1; from anywhere else it answers "Not authorized". Set one of these before the first start:

  • ALLOWED_NETWORKS to your LAN (e.g. 192.168.1.0/24), then open http://<host>:32400/web, sign in and finish the wizard. Devices on those networks can use Plex without signing in.
  • PLEX_CLAIM to a token from https://plex.tv/claim. The container claims the server on first start; then sign in at http://<host>:32400/web. Tokens expire 4 minutes after you get one: fetch it right before the first start.

Set ADVERTISE_IP to the address clients should use (e.g. http://192.168.1.10:32400), so Plex doesn't advertise its container-internal IP.

PLEX_CLAIM, ADVERTISE_IP and ALLOWED_NETWORKS work as in the official Plex image.

Host networking (optional)

network_mode: host (--network host) additionally lets Plex apps on your LAN discover the server (GDM) and enables DLNA. Use it instead of the 32400 port mapping where your platform supports it.

Architectures: amd64 User: bsd (UID/GID via PUID/PGID, defaults to 1000:1000) Base: FreeBSD 15


Need help? Join our Discord community.

About

Personal media server that organizes and streams your movie, TV, and music collections to all your devices.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages