Self-Hosted Apps on PMSS
Every Pulsed Media seedbox includes rootless Docker, so an application that PMSS does not install itself can still run inside your account. This page lists 39 such applications by category, with the facts that decide whether and how each one fits: its container image, how it runs under a URL path, whether it has a login of its own, and what it needs without Docker. The facts come from each project's own documentation, read on 7 October 2026; Pulsed Media has not tested these applications, only the proxy method most of them use.
Running an application that PMSS does not install
The same four steps apply to every application below that runs under a path; the own-hostname ones are listed after the steps, and Deleterr has no web interface. The full instructions are on Rootless DOCKER and Lighttpd Custom Configuration.
- Run the container bound to loopback. Publish its port on
127.0.0.1only, for example-p 127.0.0.1:9090:80, using an unused port above 1024 (check withss -tlnp). This keeps the application off the internet. It does not keep it private on the server: other accounts on the same server can connect to127.0.0.1too, so the application's own login is what protects it. - Add a proxy fragment in
~/.lighttpd/custom.d/for/user-USERNAME/APPNAME/. The application is then athttps://SERVER.pulsedmedia.com/user-USERNAME/APPNAME/over HTTPS. - Pick the fragment variant from the table. An application with a base-path setting gets that setting set to
/user-USERNAME/APPNAMEand a fragment withoutmap-urlpath; a few take the full address instead, or need a trailing slash, as their row says. An application documented as working behind path stripping keepsmap-urlpath. Where the column says Not documented, start withmap-urlpath; if the page loads without styling or its links jump to the server root, the application needs a base-path setting or its own hostname. Always keep"upgrade" => "enable": many applications use WebSockets for live pages and players, and they hang without it. - Secure the application before you open it up. Other accounts on the server can reach it on
127.0.0.1from its first start, so secure it straight away. Where it takes its admin user and password as settings, set them before the first start. Otherwise start with the fragment that keeps your panel login in front, withoutauth.require = (), then create your account, change any default password and close open signups. After that, addauth.require = ()so the application's own login page is reached; an application that uses HTTP basic auth needs this, or its login loops. Never use an option that switches login off for local or private addresses: requests through the proxy and connections from other accounts both arrive from such an address, so the option switches the login off for everyone. If the Login column says None or Not stated, check whether the application has a login at all; without one, any account on the same server can open it. On a shared server, run an application with no login only if nothing in it would matter if another customer read or changed it.
Every account has a memory limit set by its plan. The torrent clients and every container share it, along with the account's CPU. Where a project documents a memory minimum, the table shows it; Immich, Storyteller and PhotoPrism need several gigabytes, which the plan's limit has to cover. Applications that need several containers are easiest to run with Docker Compose where your server has it (docker compose version); publish only the web port, as 127.0.0.1:PORT:PORT, and leave database and cache containers unpublished, because every account on the server can reach a port published on 127.0.0.1.
Applications that their documentation says must run at the root of their own hostname do not fit the /user-USERNAME/APPNAME/ pattern. They are listed so you can see that before you start. Pulsed Media has not documented a tested setup for them.
Applications that existing pages already cover are not listed here: the torrent clients, the stack that Install Media Stack installs (Jellyfin, Sonarr, Radarr, Prowlarr, SABnzbd, Autobrr, Cloudplow), and the containers listed on Pulsed Media Seedbox and Storage Features, such as Lidarr and Bazarr. OpenClaw, the self-hosted AI agent, has its own PMSS installer instead of a container: see OpenClaw on PMSS.
The Path column says how to serve the application under /user-USERNAME/APPNAME/. Login is the application's own default. Without Docker is what the project ships for running directly on Linux; on Pulsed Media servers that runs as your user, so anything that needs a system package or root is not an option. A program run this way listens wherever its own settings say, and some listen on every address by default, which puts them on the internet: set its listen address to 127.0.0.1 and an unused port above 1024, then follow steps 2 to 4. Python 3 and PHP are installed on every server, at versions that depend on its Debian release (for example PHP 8.2 on Debian 12); Java, .NET and Node.js are not part of the server's package set, so those runtimes have to be unpacked into your home directory. "Not documented" and "Not stated" mean the project's documentation does not say, so such an application may or may not work under a path.
Media servers and live TV
| Application | What it does | Path | Login | Without Docker | Notes |
|---|---|---|---|---|---|
Tunarrchrisbenincasa/tunarr |
Builds live-TV channels from a Jellyfin, Plex or Emby library or local media | Not documented | None | Linux binary | No login yet (upstream issue #1032 is open), so any account on the same server can open it |
Channels DVRfancybits/channels-dvr |
Records live TV from tuners, IPTV or TV Everywhere for the Channels apps | Not documented | Not stated | Vendor installer | Closed-source commercial product; 512 MB RAM minimum, 1 GB recommended; needs a TV source |
Threadfinfyb3roptik/threadfin |
Presents M3U/XMLTV playlists as a TV tuner to Jellyfin, Plex or Emby | Not documented | Not stated | Linux binary | No release since 11 September 2025 |
Koelphanan/koel |
Streams your own music collection in the browser, with playlists | Not documented | Yes | Linux binary (bundles its own PHP) | Creates a default admin account with a published password; change it first |
mStreamlscr.io/linuxserver/mstream (community image) |
Music streaming server with a web player and mobile apps | Not documented | Optional, off by default | Linux binary | Open to anyone who reaches it until you create a user |
Comics, books and audiobooks
| Application | What it does | Path | Login | Without Docker | Notes |
|---|---|---|---|---|---|
Komgagotson/komga |
Comics, manga and ebook server with a web reader and OPDS feeds | Set SERVER_SERVLET_CONTEXTPATH |
Yes | Java jar (JRE 17+) | — |
Ubooquitylscr.io/linuxserver/ubooquity (community image) |
Comic and ebook server with a browser reader and OPDS feed | Not documented | Not stated | Java jar | Freeware, non-commercial use only; no release since 10 August 2025 |
Calibrelscr.io/linuxserver/calibre |
The full Calibre ebook manager, shown as a desktop in the browser | Set SUBFOLDER with leading and trailing slash |
Optional basic auth, off by default | Linux binary (isolated install, no root, Debian 12+; the command-line tools and calibre-server run without a desktop) | The image needs --shm-size=1gb; its desktop has a terminal with passwordless sudo, so set CUSTOM_USER and PASSWORD before you start it
|
Calibre-Web Automatedcrocodilestick/calibre-web-automated |
Web library for a Calibre collection that imports and converts books dropped in a folder | Not documented | Yes | Not offered | Default login admin/admin123; files in the import folder are deleted after processing |
BookLoreghcr.io/booklore-app/booklore |
Ebook and comic library with shelves, a web reader and device sync | Own hostname only | Yes | Not offered | Needs a MariaDB container; in maintenance mode upstream |
Grimmorygrimmory/grimmory |
Community fork of BookLore for ebooks, comics and audiobooks | Own hostname only | Yes | Not offered | Needs a MariaDB container |
Storytellerregistry.gitlab.com/storyteller-platform/storyteller |
Aligns an audiobook with its ebook so the text follows the narration | Not documented | Yes | Not offered | 8 GB RAM and up to 4 cores per upstream |
Downloads and requests
| Application | What it does | Path | Login | Without Docker | Notes |
|---|---|---|---|---|---|
quighcr.io/autobrr/qui |
One web interface for several qBittorrent instances, with automation rules | Set QUI__BASE_URL |
Yes | Linux binary | The first visitor creates the account: create it with qui create-user before the first start, or right after it
|
JDownloader 2jlesage/jdownloader-2 (community image) |
Download manager for direct links and file-hosting sites | Not documented | Optional, off by default (in the image) | Java jar | Before you start it, set WEB_AUTHENTICATION=1 with WEB_AUTHENTICATION_USERNAME and WEB_AUTHENTICATION_PASSWORD, and WEB_AUTHENTICATION_ALLOW_INSECURE=1 because the proxy reaches the container over plain HTTP
|
slskdslskd/slskd |
Web client for the Soulseek network | Set SLSKD_URL_BASE |
Yes | .NET binary | Default login slskd/slskd; set SLSKD_USERNAME and SLSKD_PASSWORD before you start it
|
Seerrghcr.io/seerr-team/seerr |
Media request manager for Jellyfin, Plex and Emby; successor of Overseerr and Jellyseerr | Own hostname only | Yes, via the media server's accounts | Node.js 22 build | — |
DroppedNeedledroppedneedle/droppedneedle |
Music requests that drive your own slskd or SABnzbd; formerly Musicseerr | Not documented | Yes | Not offered | The first account created is the admin: create it right after the first start |
ReadMeABookghcr.io/kikootwo/readmeabook |
Audiobook requests: searches, downloads, merges chapters and imports | Not documented | Yes | Not offered | One image with PostgreSQL and Redis inside |
Library automation
| Application | What it does | Path | Login | Without Docker | Notes |
|---|---|---|---|---|---|
Scryerghcr.io/scryer-media/scryer |
One program for movie, TV and anime automation | Set SCRYER_BASE_PATH |
Form login; turn it on with SCRYER_AUTH_ENABLED=true and set SCRYER_ADMIN_PASSWORD |
Linux binary | Set them before you start it; pre-1.0; heavy CPU and disk for the first hours after install |
Medusapymedusa/medusa |
TV library manager in the Sick-Beard family | Set web_root |
Optional, off by default | Python 3.9+ | Starts with no login: set web_username and web_password right after the first start
|
SickGearlscr.io/linuxserver/sickgear (community image) |
TV and anime library manager in the Sick-Beard family | Set web_root |
Not stated | Python 3 | — |
Headphoneslscr.io/linuxserver/headphones (deprecated image) |
Music library downloader, predecessor of Lidarr | Set http_root |
Optional, off by default | Python 3 | No commit on its main branch since June 2025; the image gets no updates |
Mylar3lscr.io/linuxserver/mylar3 |
Follows comic series and fetches new issues | Set http_root |
Optional, off by default | Python 3 | No release since 17 August 2025 |
Binderyghcr.io/vavallee/bindery |
Follows authors and fetches new ebooks and audiobooks | Set BINDERY_URL_BASE |
Yes | Linux binary | The first visitor creates the admin account: create it right after the first start; sends a daily anonymous telemetry ping unless disabled |
Profilarrghcr.io/dictionarry-hub/profilarr |
Builds and syncs quality profiles to Sonarr and Radarr | Not documented | Yes | Not offered | — |
Library maintenance and transcoding
| Application | What it does | Path | Login | Without Docker | Notes |
|---|---|---|---|---|---|
Maintainerrghcr.io/maintainerr/maintainerr |
Rule-based cleanup of old titles in Plex, Jellyfin or Emby | Set BASE_PATH |
None | Not offered | Deletes media by design; no login, so any account on the same server can open it and read the media-server and *arr credentials it stores |
Cleanuparrghcr.io/cleanuparr/cleanuparr |
Clears stalled and failed downloads from download queues | Set BASE_PATH |
Yes | .NET 10 | Deletes downloads by design |
Deleterrghcr.io/rfsbraz/deleterr |
Scheduled deletion of watched or stale media by rules | No web interface | — | Python 3.9+ | Deletes media by design; needs Plex and Tautulli |
Tdarrghcr.io/haveagitgat/tdarr |
Transcodes or remuxes a library in batches with FFmpeg or HandBrake | Path stripping (keep map-urlpath) |
Optional, off by default | Linux binary | Set auth to true before you start it, then set the login right after the first start; proprietary licence; transcoding runs on the CPU and is heavy
|
Unmanicjosh5/unmanic |
Watches a library and runs plugin-driven FFmpeg jobs | Not documented | None | Python 3.8+ | Plugins can run any command, and it has no login, so any account on the same server can run commands as you through it |
tinyMediaManagertinymediamanager/tinymediamanager |
Scrapes metadata and artwork, writes NFO files, renames | Not documented | Optional, off by default | Java | Some features need the paid PRO tier |
Photos, files and passwords
| Application | What it does | Path | Login | Without Docker | Notes |
|---|---|---|---|---|---|
Immichghcr.io/immich-app/immich-server |
Photo and video library with phone backup | Own hostname only | Yes | Not offered | Four containers; 6 GB RAM minimum, 8 GB recommended; the first user registered is the admin |
PhotoPrismphotoprism/photoprism |
Indexes, tags and searches photos and videos | Own hostname (sub-path is experimental upstream) | Yes | Linux binary | 3 GB RAM and 2 cores minimum; MariaDB container; upstream advises against a hard memory limit, and every account has one |
Copypartycopyparty/ac |
File server with resumable uploads, search, thumbnails and share links | --rp-loc, no map-urlpath |
Optional, off by default | Python 3 (one file) | Without accounts, anyone can read and write the shared folder |
Vaultwardenvaultwarden/server |
Password-manager server for the Bitwarden apps and extensions | Full address, including the path, in DOMAIN; no map-urlpath |
Yes | Not offered as a release | Signups are open by default; close them after creating your account |
Dashboards, chat and desktop
| Application | What it does | Path | Login | Without Docker | Notes |
|---|---|---|---|---|---|
Organizrorganizr/organizr |
Puts other apps behind one login as tabs | Not documented for the Docker image; path stripping is documented for the non-Docker install | Yes | PHP with the SQLite extension (Debian 12 servers) | The Docker image has not been rebuilt since December 2023 |
The Loungelscr.io/linuxserver/thelounge |
Always-on IRC client in the browser | Path stripping (keep map-urlpath) |
Yes | Node.js 22+ | Set reverseProxy: true in its config
|
Mattermostmattermost/mattermost-team-edition |
Team chat with channels, direct messages and file sharing | Full address, including the path, in SiteURL; no map-urlpath |
Yes | Linux binary | Needs PostgreSQL 14+; 2 GB RAM for up to 1,000 users |
Webtoplscr.io/linuxserver/webtop |
A full Linux desktop in a browser tab | Set SUBFOLDER with leading and trailing slash |
Optional basic auth, off by default | Not offered | A desktop with a terminal: set CUSTOM_USER and PASSWORD before you start it; upstream calls this login suitable only for a trusted local network
|
At Pulsed Media
Rootless Docker is part of every Pulsed Media seedbox plan, so each application above runs inside your account as your user, and the ones that run under a path are reached over HTTPS through your own web server. On 7 October 2026 Pulsed Media tested that path on a live server with a throwaway account and a test container: the documented proxy fragment carried plain requests and WebSocket upgrades, the container received the full path when map-urlpath was removed, and leaving out auth.require = () kept the panel login in front of its web address. PMSS itself installs the media stack (Jellyfin, Sonarr, Radarr, Prowlarr, SABnzbd and more) with one command, and its torrent clients from the panel.
Every application here runs on the same storage that holds your torrents, so a library manager, a transcoder or a photo server works on the files where they already are. Seedbox plans differ in RAM, so check a heavy application's memory minimum in the table against the plan you are on or considering; Seedbox and Storage Box Resource Tiers lists the numbers.
Troubleshooting
- 502 Bad Gateway, a login loop or a page that loads but never goes live: see the troubleshooting section of Lighttpd Custom Configuration.
- The container keeps stopping: read
docker logs NAME, and compare the application's documented memory minimum in the table with your plan's memory. An application that needs more than the plan leaves free does not run reliably. docker runsays the port is already allocated: another process uses it; pick a different port.
See also
- Rootless DOCKER — running containers in your account
- Lighttpd Custom Configuration — proxy fragments, path stripping and the panel login
- Install Media Stack — the applications PMSS installs for you
- Self-hosted media server on a seedbox — Jellyfin, Plex and Emby on a seedbox
- Custom Domains on PMSS — putting your own domain in front of your web folder