All apps · 0 apps
YAHLP-Public-Basic
Docker app from auskento's Repository
Overview
YAHLP - Yet Another HomeLab Portal - Public Mode with basic Auth
Configured for public internet deployment with:
- HTTPS with automatic Let's Encrypt certificates
- Basic authentication (username/password)
- Requires domain name and email address
- Ports 80 and 443 must be port-forwarded
Setup Requirements:
- Add DNS A record pointing your domain to your server IP (Seerr, Emby, Plex will need subdomains setup)
- Ensure ports 80 and 443 are port-forwarded from router
- Configure basic auth credentials (format: user:pass or user1:pass1|user2:pass2)
- Set TEST_MODE=false once ready for production to avoid Let's Encrypt rate limiting
Readme
View on GitHubYAHLP - Yet Another HomeLab Portal

A production-ready reverse proxy and dashboard for managing 19 homelab services with automatic HTTPS, flexible authentication, and customizable layouts. YAHLP sits between your browser and your services, providing unified access, health monitoring, and a beautiful interface across any device.
What YAHLP Does
Unified Access — One dashboard for all your homelab services. No more remembering IP addresses and ports.
Security — Automatic HTTPS via Let's Encrypt, centralized authentication (Basic Auth, OAuth2 with Entra/Google), and request validation. Credentials stored securely, never transmitted to services unnecessarily.
Beautiful UI — 5 responsive layouts (classic, modern, sleek, minimal, mobile) that auto-detect your device and scale perfectly. Switch layouts anytime without server restart.
Zero Downtime Management — Real-time service health checks, customizable service ordering, and theme switching without page reloads. Add or remove services without restarting the proxy.
Flexible Deployment — Run on private networks (HTTP) or expose to the internet (automatic HTTPS). Scale to any number of services.
Architecture
YAHLP runs as a single Docker container with:
- Apache 2.4 reverse proxy (handles routing, SSL/TLS, authentication)
- Node.js API server (service discovery, health checks, token caching)
- Static dashboard (HTML/CSS/JS, works offline once loaded)
Services communicate directly to YAHLP; YAHLP proxies requests to your backend services on the internal Docker network or local network. See Architecture for system design details.
Deployment Modes
Private Network — Run on your internal network with HTTP or self-signed HTTPS. Good for homelab on a single LAN.
Public (Internet-Facing) — Register a domain, enable automatic HTTPS via Let's Encrypt, and expose to the internet with OAuth2 or Basic Auth. Production-grade security.
See Deployment Guide for mode selection and tradeoffs.
📦 Supported Services (19 Total)
| Category | Count | Examples |
|---|---|---|
| Usenet | 3 | SABnzbd, NZBGet, NZBHydra |
| Torrents | 3 | Transmission, qBittorrent, Deluge |
| Search & Automation | 6 | Prowlarr, Jackett, Sonarr, Radarr, Lidarr, Whisparr |
| Utilities | 4 | Seerr, Bazarr, Tautulli, Maintainerr |
| Media Servers | 3 | Jellyfin, Emby, Plex |
Each service is optionally enabled/disabled via configuration. Only enabled services appear in the dashboard.
Authentication Methods
- No Auth — Public dashboard (private network only)
- Basic Auth — Username/password (simple, requires HTTPS)
- Entra ID / Azure AD — OAuth2 via Microsoft (enterprise)
- Google OAuth — OAuth2 via Google (personal)
Authentication happens at the proxy level. Once authenticated, services receive requests without re-authentication. See Authentication Guide.
Configuration
YAHLP requires a single mounted config folder (/etc/yahlp) for everything:
- Configuration files (
yahlp.json5,sites.json5) - SSL certificates (automatically managed in public mode)
- Custom dashboard templates
- Apache access/error logs
Docker mount: -v ./config:/etc/yahlp ← Only volume needed
YAHLP uses a three-tier configuration approach:
1. Unraid Form — Essential settings only
- Access mode, domain, email
- Service URLs and enable/disable flags
- Dashboard customization
2. Environment Variables — Per-deployment overrides
- Set via
-eflags or.envfile - Override any setting (useful for testing or CI/CD)
- Example:
-e SONARR_API_KEY=abc123
3. JSON5 Configuration — Complete persistent setup
- Auto-generated on first run with complete template
- API keys, usernames, passwords (security: kept out of form)
- Custom icon URLs, OAuth redirects, landing pages
- Edit
/etc/yahlp/yahlp.json5to configure securely
Precedence: Environment variables > JSON5 file > Form defaults
See Configuration Guide for complete options.
Getting Started
Start with the Installation Guide for detailed setup instructions for Docker or Unraid.
📚 Documentation
Setup
- Installation — Docker setup for private or public deployments, Unraid-specific guide
- Configuration — All settings: services, auth, dashboards, SSL
- Services — How to connect and configure each of the 19 services
- Authentication — Auth methods: Basic, OAuth (Entra/Google), setup guides
Using & Managing
- Dashboard Customization — Layouts, themes, service ordering, custom CSS
- Custom Services — Add optional services via VirtualHost files without code changes
- Troubleshooting — Common issues, error messages, solutions
- Upgrading — Version updates, breaking changes, rollback procedures
- Backup & Restore — Data persistence, disaster recovery, test procedures
- Unraid Deployment — Unraid-specific installation and configuration
Advanced
- Architecture — System design, component overview, data flow
- Security — Best practices, threat model, hardening checklist, incident response
- Development — Contributing guide, project structure, adding services
Why YAHLP?
Single Proxy — Instead of exposing each service individually to the internet or maintaining complex DNS/firewall rules, YAHLP proxies all traffic through one secure entry point.
Time Saver — No more logging into 5 different services to manage your homelab. Dashboard loads them all at once.
Beginner Friendly — Start with private network deployment (simple, no SSL), upgrade to internet-facing later (automatic HTTPS, OAuth).
Flexible — 5 layouts to choose from, enable/disable services without restart, customize service order, auto-auth to some services.
Safe — All credentials stored locally, never shared unnecessarily. Optional OAuth2 means no password storage at all.
How It Works
- Request comes in → Browser connects to YAHLP proxy
- Authentication → Proxy validates you're authorized (Basic Auth, OAuth, or none)
- Proxy routes → Request forwarded to appropriate backend service
- Response returned → Service response relayed back to browser
- Dashboard monitors → Health checks run in background, status shown in UI
All services run on internal Docker network or local LAN. Direct access is optional (can be disabled).
System Requirements
Minimum:
- 512 MB RAM (lighter for small homelabs)
- 100 MB disk (plus space for logs and certificates)
- Docker & Docker Compose installed
Recommended:
- 1+ GB RAM (for health checks on 10+ services)
- 500 MB disk
- Internal network (LAN only) OR registered domain with open ports 80/443
Scaling:
- Supports 10+ services without issues
- Adding more services increases RAM usage slightly
- Each layout CSS file is ~20 KB
See Installation Guide for detailed requirements by deployment mode.
Common Questions
How do I add a new service?
Enable it in configuration (env or JSON5), provide the service URL and API key. YAHLP auto-discovers and displays it on restart. See Services Guide.
Can I run it on the internet?
Yes. Public mode handles HTTPS via Let's Encrypt and OAuth2 authentication. See Installation for public deployment.
What if a service goes down?
Dashboard shows real-time health status (🟢 online / 🔴 offline). Unreachable services display as offline but don't break the dashboard.
Can I customize the dashboard?
Yes. Choose between 5 built-in layouts, customize service ordering, create custom CSS. See Dashboard Customization.
Is my data backed up?
YAHLP stores certificates, configuration, and logs in Docker volumes. You must back these up yourself. See Backup & Restore.
What authentication methods are supported?
Basic Auth (username/password), Entra ID (Azure AD), Google OAuth, or no auth (private networks only). See Authentication Guide.
Next Steps
- New to YAHLP? Start with Installation Guide
- Already installed? See Configuration to enable services
- Want to customize? Check Dashboard Customization
- Having issues? Browse Troubleshooting Guide
- Interested in contributing? See Development Guide
Support & Feedback
- Report Issues: GitHub Issues
- Security Issues: Please email instead of using GitHub Issues
- Feature Requests: GitHub Issues with
[FEATURE]tag - Documentation Questions: Check the Docs folder first
License
MIT License - See LICENSE file for details
Made for homelabbers. Made simple. Made right.
Media gallery
1 / 3Install YAHLP-Public-Basic on Unraid in a few clicks.
Find YAHLP-Public-Basic in Community Apps on your Unraid server, review the template, and click Install. Unraid handles the Docker app or plugin setup from the published template.
Requirements
Your own domain name with DNS control for Lets Encrypt certificate generation
Settings here are saved to yahlp.json5 on first run and are then overrides - if they exist, they take precedence over the config file
Categories
Related apps
Explore more like this
Explore allDetails
Runtime arguments
- Web UI
https://yourdomain.com- Network
bridge- Shell
bash- Privileged
- false
Template configuration
HTTP
- Target
- 80
- Default
- 80
- Value
- 80
HTTPS
- Target
- 443
- Default
- 443
- Value
- 443
public=subdomain-based routing with OAuth support (HTTPS via Let's Encrypt); private=folder-based routing with basic auth (HTTP on internal network)
- Target
- ACCESS_MODE
- Default
- public|private
- Value
- public
Your domain for public mode (e.g., yahlp.yourdomain.com)
- Target
- DOMAIN
Email for Let's Encrypt notifications (public mode only)
- Target
Let's Encrypt --dry-run mode (test without rate limits). WARNING: Certificates will NOT be issued. Set to false when ready for production.
- Target
- DASHBOARD_TEST
- Default
- true|false
- Value
- true
Displayed in browser title and dashboard
- Target
- DASHBOARD_NAME
- Default
- YAHLP
- Value
- YAHLP
Choose: classic, modern, sleek, minimal (If you have added custom templates you can add them here)
- Target
- DASHBOARD_STYLE
- Default
- modern
- Value
- modern
Hex color for dashboard UI accents and highlights for default templates (e.g., #00A99D, #FF5733). Leave blank for default theme color
- Target
- DASHBOARD_COLOR
Set the default landing page when accessing dashboard (e.g., sonarr, radarr, radarr/upcoming, seerr). Leave blank to show service grid
- Target
- DASHBOARD_LANDING
SAB - SABnzbd, GET - NZBGet, HYD - NZBHydra, TRA - Transmission, QBI - qBittorrent, DEL - Deluge, PRO - Prowlarr, JAC - Jackett, SON - Sonarr, RAD - Radarr, LID - Lidarr, WHI - Whisparr, SEE - Seerr, BAZ - Bazarr, TAU - Tautulli, MNT - Maintainerr, JEL - Jellyfin, PLX - Plex, EMB - Emby
- Target
- DASHBOARD_ORDER
- Default
- SAB,GET,HYD,TRA,QBI,DEL,PRO,JAC,SON,RAD,LID,WHI,SEE,BAZ,TAU,MNT,JEL,PLX,EMB
- Value
- SAB,GET,HYD,TRA,QBI,DEL,PRO,JAC,SON,RAD,LID,WHI,SEE,BAZ,TAU,MNT,JEL,PLX,EMB
TPB - The Pirate Bay, FIL - FileList.io, HDB - HDBits, IPT - IP Torrents, 1337 - 1337x, YTS - YTS, LAT - LimeTorrents, NYA - Nyaa, PTP - PassThePopcorn, DOG - DOGnzb, DRS - DrunkenSlug, NLF - nzb.life, NFW - NZBFinder.ws, NGK - NZBgeek, PLA - nzbplanet.net, TAB - Tabula Rasa (Additional sites enabled in the sites.json5 file)
- Target
- DASHBOARD_SITES
Jackett, Seerr, Emby and Plex do not play nice in frames, they'll either open in a new tab or popout window based on this setting
- Target
- DASHBOARD_WINDOWS
- Default
- popout|newtab
- Value
- popout
Choose: none, basic, google, entra
- Target
- AUTHTYPE
- Default
- basic
- Value
- none
Format: user:pass or user1:pass1|user2:pass2
- Target
- BASIC_AUTH_CREDENTIALS
SABnzbd - Usenet Client (Config - Special - url_base() to /sabnzbd)
- Target
- SABNZBD_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for SABnzbd service (usually http://sabnzbd:8080)
- Target
- SABNZBD_URL
- Default
- http://sabnzbd:8080
- Value
- http://sabnzbd:8080
NZBGet - Usenet Client (Set User and Pass below to bypass NZBGet auth
- Target
- NZBGET_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for NZBGet service (usually http://nzbget:6789)
- Target
- NZBGET_URL
- Default
- http://nzbget:6789
- Value
- http://nzbget:6789
NZBHydra - Usenet Meta Indexer (Config - Main - URLBase to /nzbhydra)
- Target
- NZBHYDRA_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for NZBHydra service (usually http://nzbhydra:5076)
- Target
- NZBHYDRA_URL
- Default
- http://nzbhydra:5076
- Value
- http://nzbhydra:5076
Transmission - Torrent Client
- Target
- TRANSMISSION_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Transmission service (usually http://transmission:9091)
- Target
- TRANSMISSION_URL
- Default
- http://transmission:9091
- Value
- http://transmission:9091
qBittorrent - Torrent Client
- Target
- QBITTORRENT_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for qBittorrent service (check for port conflicts; default is http://qbittorrent:8080)
- Target
- QBITTORRENT_URL
- Default
- http://qbittorrent:8080
- Value
- http://qbittorrent:8080
Deluge - Torrent Client
- Target
- DELUGE_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Deluge service (usually http://deluge:8112)
- Target
- DELUGE_URL
- Default
- http://deluge:8112
- Value
- http://deluge:8112
Sonarr - TV Show Automation (Settings - General - URL Base to /sonarr)
- Target
- SONARR_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Sonarr service (usually http://sonarr:8989)
- Target
- SONARR_URL
- Default
- http://sonarr:8989
- Value
- http://sonarr:8989
Landing page (e.g., sonarr, sonarr/calendar)
- Target
- SONARR_LANDING
- Default
- sonarr
- Value
- sonarr
Radarr - Movie Automation ((Settings - General - URL Base to /radarr)
- Target
- RADARR_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Radarr service (usually http://radarr:7878)
- Target
- RADARR_URL
- Default
- http://radarr:7878
- Value
- http://radarr:7878
Landing page (e.g., radarr, radarr/calendar)
- Target
- RADARR_LANDING
- Default
- radarr
- Value
- radarr
Whisparr - Adult Content Automation (Settings - General - URL Base to /whisparr)
- Target
- WHISPARR_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Whisparr service (usually http://whisparr:6969)
- Target
- WHISPARR_URL
- Default
- http://whisparr:6969
- Value
- http://whisparr:6969
Landing page for Whisparr (e.g., whisparr, whisparr/calendar). Leave blank for default
- Target
- WHISPARR_LANDING
- Default
- whisparr
- Value
- whisparr
Lidarr - Music Automation (Settings - General - URL Base to to /lidarr)
- Target
- LIDARR_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Lidarr service (usually http://lidarr:8686)
- Target
- LIDARR_URL
- Default
- http://lidarr:8686
- Value
- http://lidarr:8686
Landing page for Lidarr (e.g., lidarr, lidarr/library). Leave blank for default
- Target
- LIDARR_LANDING
- Default
- lidarr
- Value
- lidarr
Prowlarr - Indexer Manager (Settings - General - URL Base to /prowlarr)
- Target
- PROWLARR_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Prowlarr service (usually http://prowlarr:9696)
- Target
- PROWLARR_URL
- Default
- http://prowlarr:9696
- Value
- http://prowlarr:9696
Jackett - Indexer Aggregator (Config - Admin - url_base() to /jackett).
- Target
- JACKETT_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Jackett service (usually http://jackett:9117)
- Target
- JACKETT_URL
- Default
- http://jackett:9117
- Value
- http://jackett:9117
Seerr - Request Manager (In public mode, uses subdomain routing).
- Target
- SEERR_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Seerr service
- Target
- SEERR_URL
- Default
- http://seerr:5055
- Value
- http://seerr:5055
Subdomain for Seerr (e.g., seerr.yourdomain.com).
- Target
- SEERR_DOMAIN
Bazarr - Subtitle Manager (Settings - General - Base URL to /bazarr)
- Target
- BAZARR_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Bazarr service (usually http://bazarr:6767)
- Target
- BAZARR_URL
- Default
- http://bazarr:6767
- Value
- http://bazarr:6767
Jellyfin - Media Server (Settings -Admin Dash - Networking - Base URL /jellyfin)
- Target
- JELLYFIN_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Jellyfin service (usually http://jellyfin:8096)
- Target
- JELLYFIN_URL
- Default
- http://jellyfin:8096
- Value
- http://jellyfin:8096
Emby - Media Server (In public mode, uses subdomain routing).
- Target
- EMBY_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Emby service
- Target
- EMBY_URL
- Default
- http://emby:8096
- Value
- http://emby:8096
Subdomain for Emby (e.g., emby.yourdomain.com).
- Target
- EMBY_DOMAIN
Plex - Media Server (in public mode, uses subdomain routing). For public mode with OAuth, also set PLEX_DOMAIN and PLEX_REDIRECT_URI
- Target
- PLEX_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Plex service (usually http://plex:32400)
- Target
- PLEX_URL
- Default
- http://plex:32400
- Value
- http://plex:32400
Subdomain for Plex (e.g., plex.yourdomain.com).
- Target
- PLEX_DOMAIN
Tautulli - Plex Analytics (Settings - Show Advanced - Web Interface - Enable Proxy, Set Public Domain to https://yourdomain.com/tautulli and HTTP root to /tautulli)
- Target
- TAUTULLI_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Tautulli service (usually http://tautulli:8181)
- Target
- TAUTULLI_URL
- Default
- http://tautulli:8181
- Value
- http://tautulli:8181
Maintainerr - Media Server Maintenance (Enable BASE_URL environment variable on its docker and set to /maintainerr)
- Target
- MAINTAINERR_ENABLED
- Default
- false|true
- Value
- false
Local internal URL for Maintainerr service (usually http://maintainerr:6246)
- Target
- MAINTAINERR_URL
- Default
- http://maintainerr:6246
- Value
- http://maintainerr:6246
User ID for file permissions (99 = nobody)
- Default
- 99
- Value
- 99
Group ID for file permissions (100 = users)
- Default
- 100
- Value
- 100
Configuration folder - store the yahlp and sites JSON5 files here - ENV Variables override config settings, remove the variable settings from the form. Custom templates in the templates folder
- Target
- /etc/yahlp
- Default
- /mnt/user/appdata/yahlp
- Value
- /mnt/user/appdata/yahlp
Read Timezone from host
- Target
- /etc/localtime
- Default
- /etc/localtime
- Value
- /etc/localtime