Skip to content

Reverse proxy configurations

Claude edited this page Sep 25, 2026 · 3 revisions

MeTube can serve HTTPS itself, or run behind a reverse proxy for HTTPS termination or authentication.

Built-in HTTPS

Mount a certificate and key into the container and point MeTube at them:

services:
  metube:
    image: ghcr.io/alexta69/metube
    container_name: metube
    restart: unless-stopped
    ports:
      - "8081:8081"
    volumes:
      - /path/to/downloads:/downloads
      - /path/to/ssl/crt:/ssl/crt.pem
      - /path/to/ssl/key:/ssl/key.pem
    environment:
      - HTTPS=true
      - CERTFILE=/ssl/crt.pem
      - KEYFILE=/ssl/key.pem

Behind a reverse proxy

When serving under a subdirectory, set URL_PREFIX accordingly. MeTube uses WebSocket (Socket.IO) for real-time updates, so the proxy must pass the Upgrade/Connection headers — the examples below all do.

NGINX

location /metube/ {
        proxy_pass http://metube:8081;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
}

Apache

Contributed by PIE-yt. Source here.

# For putting in your Apache sites site.conf
# Serves MeTube under a /metube/ subdir (http://yourdomain.com/metube/)
<Location /metube/>
    ProxyPass http://localhost:8081/ retry=0 timeout=30
    ProxyPassReverse http://localhost:8081/
</Location>

<Location /metube/socket.io>
    RewriteEngine On
    RewriteCond %{QUERY_STRING} transport=websocket    [NC]
    RewriteRule /(.*) ws://localhost:8081/socket.io/$1 [P,L]
    ProxyPass http://localhost:8081/socket.io retry=0 timeout=30
    ProxyPassReverse http://localhost:8081/socket.io
</Location>

Caddy

The following example Caddyfile gets a reverse proxy going behind caddy.

example.com {
  route /metube/* {
    uri strip_prefix metube
    reverse_proxy metube:8081
  }
}

swag (with Authelia)

The linuxserver/swag image includes ready-made snippets for MeTube in subfolder and subdomain modes, plus Authelia for authentication.

Why no built-in authentication?

MeTube deliberately has no login system (see #931): authentication done right is substantial, security-sensitive complexity, and every reverse proxy above adds it in minutes with battle-tested code. Use HTTP basic auth, Authelia, or your proxy's equivalent. Anything security-related can be reported via the repository's private vulnerability reporting (see SECURITY.md).


Have a working config for another proxy (Traefik, nginx-proxy-manager, HAProxy…)? Open an issue with the snippet and it will be added here with attribution.

Clone this wiki locally