Jump to content

Self-Hosted Apps on PMSS

From Pulsed Media Wiki


Every Pulsed Media seedbox includes rootless Docker, so an application that PMSS does not install itself can still run inside your account. This page lists 39 such applications by category, with the facts that decide whether and how each one fits: its container image, how it runs under a URL path, whether it has a login of its own, and what it needs without Docker. The facts come from each project's own documentation, read on 7 October 2026; Pulsed Media has not tested these applications, only the proxy method most of them use.

Running an application that PMSS does not install

The same four steps apply to every application below that runs under a path; the own-hostname ones are listed after the steps, and Deleterr has no web interface. The full instructions are on Rootless DOCKER and Lighttpd Custom Configuration.

  1. Run the container bound to loopback. Publish its port on 127.0.0.1 only, for example -p 127.0.0.1:9090:80, using an unused port above 1024 (check with ss -tlnp). This keeps the application off the internet. It does not keep it private on the server: other accounts on the same server can connect to 127.0.0.1 too, so the application's own login is what protects it.
  2. Add a proxy fragment in ~/.lighttpd/custom.d/ for /user-USERNAME/APPNAME/. The application is then at https://SERVER.pulsedmedia.com/user-USERNAME/APPNAME/ over HTTPS.
  3. Pick the fragment variant from the table. An application with a base-path setting gets that setting set to /user-USERNAME/APPNAME and a fragment without map-urlpath; a few take the full address instead, or need a trailing slash, as their row says. An application documented as working behind path stripping keeps map-urlpath. Where the column says Not documented, start with map-urlpath; if the page loads without styling or its links jump to the server root, the application needs a base-path setting or its own hostname. Always keep "upgrade" => "enable": many applications use WebSockets for live pages and players, and they hang without it.
  4. Secure the application before you open it up. Other accounts on the server can reach it on 127.0.0.1 from its first start, so secure it straight away. Where it takes its admin user and password as settings, set them before the first start. Otherwise start with the fragment that keeps your panel login in front, without auth.require = (), then create your account, change any default password and close open signups. After that, add auth.require = () so the application's own login page is reached; an application that uses HTTP basic auth needs this, or its login loops. Never use an option that switches login off for local or private addresses: requests through the proxy and connections from other accounts both arrive from such an address, so the option switches the login off for everyone. If the Login column says None or Not stated, check whether the application has a login at all; without one, any account on the same server can open it. On a shared server, run an application with no login only if nothing in it would matter if another customer read or changed it.

Every account has a memory limit set by its plan. The torrent clients and every container share it, along with the account's CPU. Where a project documents a memory minimum, the table shows it; Immich, Storyteller and PhotoPrism need several gigabytes, which the plan's limit has to cover. Applications that need several containers are easiest to run with Docker Compose where your server has it (docker compose version); publish only the web port, as 127.0.0.1:PORT:PORT, and leave database and cache containers unpublished, because every account on the server can reach a port published on 127.0.0.1.

Applications that their documentation says must run at the root of their own hostname do not fit the /user-USERNAME/APPNAME/ pattern. They are listed so you can see that before you start. Pulsed Media has not documented a tested setup for them.

Applications that existing pages already cover are not listed here: the torrent clients, the stack that Install Media Stack installs (Jellyfin, Sonarr, Radarr, Prowlarr, SABnzbd, Autobrr, Cloudplow), and the containers listed on Pulsed Media Seedbox and Storage Features, such as Lidarr and Bazarr. OpenClaw, the self-hosted AI agent, has its own PMSS installer instead of a container: see OpenClaw on PMSS.

The Path column says how to serve the application under /user-USERNAME/APPNAME/. Login is the application's own default. Without Docker is what the project ships for running directly on Linux; on Pulsed Media servers that runs as your user, so anything that needs a system package or root is not an option. A program run this way listens wherever its own settings say, and some listen on every address by default, which puts them on the internet: set its listen address to 127.0.0.1 and an unused port above 1024, then follow steps 2 to 4. Python 3 and PHP are installed on every server, at versions that depend on its Debian release (for example PHP 8.2 on Debian 12); Java, .NET and Node.js are not part of the server's package set, so those runtimes have to be unpacked into your home directory. "Not documented" and "Not stated" mean the project's documentation does not say, so such an application may or may not work under a path.

Media servers and live TV

Application What it does Path Login Without Docker Notes
Tunarr
chrisbenincasa/tunarr
Builds live-TV channels from a Jellyfin, Plex or Emby library or local media Not documented None Linux binary No login yet (upstream issue #1032 is open), so any account on the same server can open it
Channels DVR
fancybits/channels-dvr
Records live TV from tuners, IPTV or TV Everywhere for the Channels apps Not documented Not stated Vendor installer Closed-source commercial product; 512 MB RAM minimum, 1 GB recommended; needs a TV source
Threadfin
fyb3roptik/threadfin
Presents M3U/XMLTV playlists as a TV tuner to Jellyfin, Plex or Emby Not documented Not stated Linux binary No release since 11 September 2025
Koel
phanan/koel
Streams your own music collection in the browser, with playlists Not documented Yes Linux binary (bundles its own PHP) Creates a default admin account with a published password; change it first
mStream
lscr.io/linuxserver/mstream (community image)
Music streaming server with a web player and mobile apps Not documented Optional, off by default Linux binary Open to anyone who reaches it until you create a user

Comics, books and audiobooks

Application What it does Path Login Without Docker Notes
Komga
gotson/komga
Comics, manga and ebook server with a web reader and OPDS feeds Set SERVER_SERVLET_CONTEXTPATH Yes Java jar (JRE 17+) —
Ubooquity
lscr.io/linuxserver/ubooquity (community image)
Comic and ebook server with a browser reader and OPDS feed Not documented Not stated Java jar Freeware, non-commercial use only; no release since 10 August 2025
Calibre
lscr.io/linuxserver/calibre
The full Calibre ebook manager, shown as a desktop in the browser Set SUBFOLDER with leading and trailing slash Optional basic auth, off by default Linux binary (isolated install, no root, Debian 12+; the command-line tools and calibre-server run without a desktop) The image needs --shm-size=1gb; its desktop has a terminal with passwordless sudo, so set CUSTOM_USER and PASSWORD before you start it
Calibre-Web Automated
crocodilestick/calibre-web-automated
Web library for a Calibre collection that imports and converts books dropped in a folder Not documented Yes Not offered Default login admin/admin123; files in the import folder are deleted after processing
BookLore
ghcr.io/booklore-app/booklore
Ebook and comic library with shelves, a web reader and device sync Own hostname only Yes Not offered Needs a MariaDB container; in maintenance mode upstream
Grimmory
grimmory/grimmory
Community fork of BookLore for ebooks, comics and audiobooks Own hostname only Yes Not offered Needs a MariaDB container
Storyteller
registry.gitlab.com/storyteller-platform/storyteller
Aligns an audiobook with its ebook so the text follows the narration Not documented Yes Not offered 8 GB RAM and up to 4 cores per upstream

Downloads and requests

Application What it does Path Login Without Docker Notes
qui
ghcr.io/autobrr/qui
One web interface for several qBittorrent instances, with automation rules Set QUI__BASE_URL Yes Linux binary The first visitor creates the account: create it with qui create-user before the first start, or right after it
JDownloader 2
jlesage/jdownloader-2 (community image)
Download manager for direct links and file-hosting sites Not documented Optional, off by default (in the image) Java jar Before you start it, set WEB_AUTHENTICATION=1 with WEB_AUTHENTICATION_USERNAME and WEB_AUTHENTICATION_PASSWORD, and WEB_AUTHENTICATION_ALLOW_INSECURE=1 because the proxy reaches the container over plain HTTP
slskd
slskd/slskd
Web client for the Soulseek network Set SLSKD_URL_BASE Yes .NET binary Default login slskd/slskd; set SLSKD_USERNAME and SLSKD_PASSWORD before you start it
Seerr
ghcr.io/seerr-team/seerr
Media request manager for Jellyfin, Plex and Emby; successor of Overseerr and Jellyseerr Own hostname only Yes, via the media server's accounts Node.js 22 build —
DroppedNeedle
droppedneedle/droppedneedle
Music requests that drive your own slskd or SABnzbd; formerly Musicseerr Not documented Yes Not offered The first account created is the admin: create it right after the first start
ReadMeABook
ghcr.io/kikootwo/readmeabook
Audiobook requests: searches, downloads, merges chapters and imports Not documented Yes Not offered One image with PostgreSQL and Redis inside

Library automation

Application What it does Path Login Without Docker Notes
Scryer
ghcr.io/scryer-media/scryer
One program for movie, TV and anime automation Set SCRYER_BASE_PATH Form login; turn it on with SCRYER_AUTH_ENABLED=true and set SCRYER_ADMIN_PASSWORD Linux binary Set them before you start it; pre-1.0; heavy CPU and disk for the first hours after install
Medusa
pymedusa/medusa
TV library manager in the Sick-Beard family Set web_root Optional, off by default Python 3.9+ Starts with no login: set web_username and web_password right after the first start
SickGear
lscr.io/linuxserver/sickgear (community image)
TV and anime library manager in the Sick-Beard family Set web_root Not stated Python 3 —
Headphones
lscr.io/linuxserver/headphones (deprecated image)
Music library downloader, predecessor of Lidarr Set http_root Optional, off by default Python 3 No commit on its main branch since June 2025; the image gets no updates
Mylar3
lscr.io/linuxserver/mylar3
Follows comic series and fetches new issues Set http_root Optional, off by default Python 3 No release since 17 August 2025
Bindery
ghcr.io/vavallee/bindery
Follows authors and fetches new ebooks and audiobooks Set BINDERY_URL_BASE Yes Linux binary The first visitor creates the admin account: create it right after the first start; sends a daily anonymous telemetry ping unless disabled
Profilarr
ghcr.io/dictionarry-hub/profilarr
Builds and syncs quality profiles to Sonarr and Radarr Not documented Yes Not offered —

Library maintenance and transcoding

Application What it does Path Login Without Docker Notes
Maintainerr
ghcr.io/maintainerr/maintainerr
Rule-based cleanup of old titles in Plex, Jellyfin or Emby Set BASE_PATH None Not offered Deletes media by design; no login, so any account on the same server can open it and read the media-server and *arr credentials it stores
Cleanuparr
ghcr.io/cleanuparr/cleanuparr
Clears stalled and failed downloads from download queues Set BASE_PATH Yes .NET 10 Deletes downloads by design
Deleterr
ghcr.io/rfsbraz/deleterr
Scheduled deletion of watched or stale media by rules No web interface — Python 3.9+ Deletes media by design; needs Plex and Tautulli
Tdarr
ghcr.io/haveagitgat/tdarr
Transcodes or remuxes a library in batches with FFmpeg or HandBrake Path stripping (keep map-urlpath) Optional, off by default Linux binary Set auth to true before you start it, then set the login right after the first start; proprietary licence; transcoding runs on the CPU and is heavy
Unmanic
josh5/unmanic
Watches a library and runs plugin-driven FFmpeg jobs Not documented None Python 3.8+ Plugins can run any command, and it has no login, so any account on the same server can run commands as you through it
tinyMediaManager
tinymediamanager/tinymediamanager
Scrapes metadata and artwork, writes NFO files, renames Not documented Optional, off by default Java Some features need the paid PRO tier

Photos, files and passwords

Application What it does Path Login Without Docker Notes
Immich
ghcr.io/immich-app/immich-server
Photo and video library with phone backup Own hostname only Yes Not offered Four containers; 6 GB RAM minimum, 8 GB recommended; the first user registered is the admin
PhotoPrism
photoprism/photoprism
Indexes, tags and searches photos and videos Own hostname (sub-path is experimental upstream) Yes Linux binary 3 GB RAM and 2 cores minimum; MariaDB container; upstream advises against a hard memory limit, and every account has one
Copyparty
copyparty/ac
File server with resumable uploads, search, thumbnails and share links --rp-loc, no map-urlpath Optional, off by default Python 3 (one file) Without accounts, anyone can read and write the shared folder
Vaultwarden
vaultwarden/server
Password-manager server for the Bitwarden apps and extensions Full address, including the path, in DOMAIN; no map-urlpath Yes Not offered as a release Signups are open by default; close them after creating your account

Dashboards, chat and desktop

Application What it does Path Login Without Docker Notes
Organizr
organizr/organizr
Puts other apps behind one login as tabs Not documented for the Docker image; path stripping is documented for the non-Docker install Yes PHP with the SQLite extension (Debian 12 servers) The Docker image has not been rebuilt since December 2023
The Lounge
lscr.io/linuxserver/thelounge
Always-on IRC client in the browser Path stripping (keep map-urlpath) Yes Node.js 22+ Set reverseProxy: true in its config
Mattermost
mattermost/mattermost-team-edition
Team chat with channels, direct messages and file sharing Full address, including the path, in SiteURL; no map-urlpath Yes Linux binary Needs PostgreSQL 14+; 2 GB RAM for up to 1,000 users
Webtop
lscr.io/linuxserver/webtop
A full Linux desktop in a browser tab Set SUBFOLDER with leading and trailing slash Optional basic auth, off by default Not offered A desktop with a terminal: set CUSTOM_USER and PASSWORD before you start it; upstream calls this login suitable only for a trusted local network

At Pulsed Media

Rootless Docker is part of every Pulsed Media seedbox plan, so each application above runs inside your account as your user, and the ones that run under a path are reached over HTTPS through your own web server. On 7 October 2026 Pulsed Media tested that path on a live server with a throwaway account and a test container: the documented proxy fragment carried plain requests and WebSocket upgrades, the container received the full path when map-urlpath was removed, and leaving out auth.require = () kept the panel login in front of its web address. PMSS itself installs the media stack (Jellyfin, Sonarr, Radarr, Prowlarr, SABnzbd and more) with one command, and its torrent clients from the panel.

Every application here runs on the same storage that holds your torrents, so a library manager, a transcoder or a photo server works on the files where they already are. Seedbox plans differ in RAM, so check a heavy application's memory minimum in the table against the plan you are on or considering; Seedbox and Storage Box Resource Tiers lists the numbers.

Troubleshooting

  • 502 Bad Gateway, a login loop or a page that loads but never goes live: see the troubleshooting section of Lighttpd Custom Configuration.
  • The container keeps stopping: read docker logs NAME, and compare the application's documented memory minimum in the table with your plan's memory. An application that needs more than the plan leaves free does not run reliably.
  • docker run says the port is already allocated: another process uses it; pick a different port.

See also