YAHLP-Public-Entra

YAHLP-Public-Entra

Docker app from auskento's Repository

Overview

YAHLP - Yet Another HomeLab Portal - Public Mode with Microsoft Entra ID

Configured for public internet deployment with:

  • HTTPS with automatic Let's Encrypt certificates
  • Microsoft Entra ID (Azure AD) OAuth 2.0 authentication
  • Requires domain name and email address
  • Requires Entra ID credentials from Azure Portal
  • Ports 80 and 443 must be port-forwarded

Setup Requirements:

  1. Create Azure App Registration in Entra ID
  2. Configure OAuth 2.0 with Redirect URI: https://your-domain.com/auth/oauth2/callback
  3. Generate Client Secret
  4. Add DNS A record pointing your domain to your server IP
  5. Ensure ports 80 and 443 are port-forwarded from router
  6. Set TEST_MODE=false once ready for production to avoid Let's Encrypt rate limiting

YAHLP - Yet Another HomeLab Portal

YAHLP Logo

A production-ready reverse proxy and dashboard for managing 19 homelab services with automatic HTTPS, flexible authentication, and customizable layouts. YAHLP sits between your browser and your services, providing unified access, health monitoring, and a beautiful interface across any device.

What YAHLP Does

Unified Access — One dashboard for all your homelab services. No more remembering IP addresses and ports.

Security — Automatic HTTPS via Let's Encrypt, centralized authentication (Basic Auth, OAuth2 with Entra/Google), and request validation. Credentials stored securely, never transmitted to services unnecessarily.

Beautiful UI — 5 responsive layouts (classic, modern, sleek, minimal, mobile) that auto-detect your device and scale perfectly. Switch layouts anytime without server restart.

Zero Downtime Management — Real-time service health checks, customizable service ordering, and theme switching without page reloads. Add or remove services without restarting the proxy.

Flexible Deployment — Run on private networks (HTTP) or expose to the internet (automatic HTTPS). Scale to any number of services.

Architecture

YAHLP runs as a single Docker container with:

  • Apache 2.4 reverse proxy (handles routing, SSL/TLS, authentication)
  • Node.js API server (service discovery, health checks, token caching)
  • Static dashboard (HTML/CSS/JS, works offline once loaded)

Services communicate directly to YAHLP; YAHLP proxies requests to your backend services on the internal Docker network or local network. See Architecture for system design details.

Deployment Modes

Private Network — Run on your internal network with HTTP or self-signed HTTPS. Good for homelab on a single LAN.

Public (Internet-Facing) — Register a domain, enable automatic HTTPS via Let's Encrypt, and expose to the internet with OAuth2 or Basic Auth. Production-grade security.

See Deployment Guide for mode selection and tradeoffs.

📦 Supported Services (19 Total)

Category Count Examples
Usenet 3 SABnzbd, NZBGet, NZBHydra
Torrents 3 Transmission, qBittorrent, Deluge
Search & Automation 6 Prowlarr, Jackett, Sonarr, Radarr, Lidarr, Whisparr
Utilities 4 Seerr, Bazarr, Tautulli, Maintainerr
Media Servers 3 Jellyfin, Emby, Plex

Each service is optionally enabled/disabled via configuration. Only enabled services appear in the dashboard.

Authentication Methods

  • No Auth — Public dashboard (private network only)
  • Basic Auth — Username/password (simple, requires HTTPS)
  • Entra ID / Azure AD — OAuth2 via Microsoft (enterprise)
  • Google OAuth — OAuth2 via Google (personal)

Authentication happens at the proxy level. Once authenticated, services receive requests without re-authentication. See Authentication Guide.

Configuration

YAHLP requires a single mounted config folder (/etc/yahlp) for everything:

  • Configuration files (yahlp.json5, sites.json5)
  • SSL certificates (automatically managed in public mode)
  • Custom dashboard templates
  • Apache access/error logs

Docker mount: -v ./config:/etc/yahlp ← Only volume needed

YAHLP uses a three-tier configuration approach:

1. Unraid Form — Essential settings only

  • Access mode, domain, email
  • Service URLs and enable/disable flags
  • Dashboard customization

2. Environment Variables — Per-deployment overrides

  • Set via -e flags or .env file
  • Override any setting (useful for testing or CI/CD)
  • Example: -e SONARR_API_KEY=abc123

3. JSON5 Configuration — Complete persistent setup

  • Auto-generated on first run with complete template
  • API keys, usernames, passwords (security: kept out of form)
  • Custom icon URLs, OAuth redirects, landing pages
  • Edit /etc/yahlp/yahlp.json5 to configure securely

Precedence: Environment variables > JSON5 file > Form defaults

See Configuration Guide for complete options.

Getting Started

Start with the Installation Guide for detailed setup instructions for Docker or Unraid.

📚 Documentation

Setup

  • Installation — Docker setup for private or public deployments, Unraid-specific guide
  • Configuration — All settings: services, auth, dashboards, SSL
  • Services — How to connect and configure each of the 19 services
  • Authentication — Auth methods: Basic, OAuth (Entra/Google), setup guides

Using & Managing

Advanced

  • Architecture — System design, component overview, data flow
  • Security — Best practices, threat model, hardening checklist, incident response
  • Development — Contributing guide, project structure, adding services

Why YAHLP?

Single Proxy — Instead of exposing each service individually to the internet or maintaining complex DNS/firewall rules, YAHLP proxies all traffic through one secure entry point.

Time Saver — No more logging into 5 different services to manage your homelab. Dashboard loads them all at once.

Beginner Friendly — Start with private network deployment (simple, no SSL), upgrade to internet-facing later (automatic HTTPS, OAuth).

Flexible — 5 layouts to choose from, enable/disable services without restart, customize service order, auto-auth to some services.

Safe — All credentials stored locally, never shared unnecessarily. Optional OAuth2 means no password storage at all.

How It Works

  1. Request comes in → Browser connects to YAHLP proxy
  2. Authentication → Proxy validates you're authorized (Basic Auth, OAuth, or none)
  3. Proxy routes → Request forwarded to appropriate backend service
  4. Response returned → Service response relayed back to browser
  5. Dashboard monitors → Health checks run in background, status shown in UI

All services run on internal Docker network or local LAN. Direct access is optional (can be disabled).

System Requirements

Minimum:

  • 512 MB RAM (lighter for small homelabs)
  • 100 MB disk (plus space for logs and certificates)
  • Docker & Docker Compose installed

Recommended:

  • 1+ GB RAM (for health checks on 10+ services)
  • 500 MB disk
  • Internal network (LAN only) OR registered domain with open ports 80/443

Scaling:

  • Supports 10+ services without issues
  • Adding more services increases RAM usage slightly
  • Each layout CSS file is ~20 KB

See Installation Guide for detailed requirements by deployment mode.

Common Questions

How do I add a new service?
Enable it in configuration (env or JSON5), provide the service URL and API key. YAHLP auto-discovers and displays it on restart. See Services Guide.

Can I run it on the internet?
Yes. Public mode handles HTTPS via Let's Encrypt and OAuth2 authentication. See Installation for public deployment.

What if a service goes down?
Dashboard shows real-time health status (🟢 online / 🔴 offline). Unreachable services display as offline but don't break the dashboard.

Can I customize the dashboard?
Yes. Choose between 5 built-in layouts, customize service ordering, create custom CSS. See Dashboard Customization.

Is my data backed up?
YAHLP stores certificates, configuration, and logs in Docker volumes. You must back these up yourself. See Backup & Restore.

What authentication methods are supported?
Basic Auth (username/password), Entra ID (Azure AD), Google OAuth, or no auth (private networks only). See Authentication Guide.

Next Steps

  1. New to YAHLP? Start with Installation Guide
  2. Already installed? See Configuration to enable services
  3. Want to customize? Check Dashboard Customization
  4. Having issues? Browse Troubleshooting Guide
  5. Interested in contributing? See Development Guide

Support & Feedback

  • Report Issues: GitHub Issues
  • Security Issues: Please email instead of using GitHub Issues
  • Feature Requests: GitHub Issues with [FEATURE] tag
  • Documentation Questions: Check the Docs folder first

License

MIT License - See LICENSE file for details


Made for homelabbers. Made simple. Made right.

Media gallery

1 / 3

Install YAHLP-Public-Entra on Unraid in a few clicks.

Find YAHLP-Public-Entra in Community Apps on your Unraid server, review the template, and click Install. Unraid handles the Docker app or plugin setup from the published template.

Open the Apps tab on your Unraid server Search Community Apps for YAHLP-Public-Entra Review the template variables and paths Click Install

Requirements

This app runs best on a dedicated IP on your LAN - not forwarding other ports to host.
Your own domain name with DNS control for Lets Encrypt certificate generation

Details

Repository
ghcr.io/auskento/yahlp
Last Updated2026-07-21
First Seen2026-07-20

Runtime arguments

Web UI
https://yourdomain.com
Network
bridge
Shell
sh
Privileged
false

Template configuration

HTTPPorttcp

HTTP

Target
80
Default
80
Value
80
HTTPSPorttcp

HTTPS

Target
443
Default
443
Value
443
Let's Encrypt Test ModeVariable

Let's Encrypt --dry-run mode (test without rate limits). WARNING: Certificates will NOT be issued. Set to false when ready for production.

Target
DASHBOARD_TEST
Default
true|false
Value
true
Domain (Public)Variable

Your domain for public mode (e.g., yahlp.yourdomain.com)

Target
DOMAIN
Email (Public)Variable

Email for Let's Encrypt notifications (public mode only)

Target
EMAIL
Dashboard NameVariable

Displayed in browser title and dashboard

Target
DASHBOARD_NAME
Default
YAHLP
Value
YAHLP
Dashboard LayoutVariable

Choose: classic, modern, sleek, minimal (If you have added custom templates you can add them here)

Target
DASHBOARD_STYLE
Default
modern
Value
modern
Accent ColorVariable

Hex color for dashboard UI accents and highlights for default templates (e.g., #00A99D, #FF5733). Leave blank for default theme color

Target
DASHBOARD_COLOR
Dashboard LandingVariable

Set the default landing page when accessing dashboard (e.g., sonarr, radarr, radarr/upcoming, seerr). Leave blank to show service grid

Target
DASHBOARD_LANDING
Service Display OrderVariable

SAB - SABnzbd, GET - NZBGet, HYD - NZBHydra, TRA - Transmission, QBI - qBittorrent, DEL - Deluge, PRO - Prowlarr, JAC - Jackett, SON - Sonarr, RAD - Radarr, LID - Lidarr, WHI - Whisparr, SEE - Seerr, BAZ - Bazarr, TAU - Tautulli, MNT - Maintainerr, JEL - Jellyfin, PLX - Plex, EMB - Emby

Target
DASHBOARD_ORDER
Default
SAB,GET,HYD,TRA,QBI,DEL,PRO,JAC,SON,RAD,LID,WHI,SEE,BAZ,TAU,MNT,JEL,PLX,EMB
Value
SAB,GET,HYD,TRA,QBI,DEL,PRO,JAC,SON,RAD,LID,WHI,SEE,BAZ,TAU,MNT,JEL,PLX,EMB
Sites Display OrderVariable

TPB - The Pirate Bay, FIL - FileList.io, HDB - HDBits, IPT - IP Torrents, 1337 - 1337x, YTS - YTS, LAT - LimeTorrents, NYA - Nyaa, PTP - PassThePopcorn, DOG - DOGnzb, DRS - DrunkenSlug, NLF - nzb.life, NFW - NZBFinder.ws, NGK - NZBgeek, PLA - nzbplanet.net, TAB - Tabula Rasa (Additional sites enabled in the sites.json5 file)

Target
DASHBOARD_SITES
Window BehaviourVariable

Jackett, Seerr, Emby and Plex do not play nice in frames, they'll either open in a new tab or popout window based on this setting

Target
DASHBOARD_WINDOWS
Default
popout|newtab
Value
popout
Authentication TypeVariable

Choose: none, basic, google, entra

Target
AUTHTYPE
Default
entra
Value
entra
Entra Client SecretVariable

From Entra App

Target
ENTRA_CLIENT_SECRET
Entra Tenant IDVariable

Your Azure Tenant ID

Target
ENTRA_TENANT_ID
Entra Crypto PassphraseVariable

Encryption passphrase for Entra

Target
ENTRA_CRYPTO_PASSPHRASE
Entra Metadata URLVariable

Entra OpenID metadata URL

Target
ENTRA_PROVIDER_METADATA_URL
Default
https://login.microsoftonline.com/<YOUR TENANT ID>/v2.0/.well-known/openid-configuration
Value
https://login.microsoftonline.com/<YOUR TENANT ID>/v2.0/.well-known/openid-configuration
Entra Client IDVariable

From Entra App

Target
ENTRA_CLIENT_ID
Enable SABnzbdVariable

SABnzbd - Usenet Client (Config - Special - url_base() to /sabnzbd)

Target
SABNZBD_ENABLED
Default
false|true
Value
false
SABnzbd URLVariable

Local internal URL for SABnzbd service (usually http://sabnzbd:8080)

Target
SABNZBD_URL
Default
http://sabnzbd:8080
Value
http://sabnzbd:8080
Enable NZBGetVariable

NZBGet - Usenet Client (Set User and Pass below to bypass NZBGet auth

Target
NZBGET_ENABLED
Default
false|true
Value
false
NZBGet URLVariable

Local internal URL for NZBGet service (usually http://nzbget:6789)

Target
NZBGET_URL
Default
http://nzbget:6789
Value
http://nzbget:6789
Enable NZBHydraVariable

NZBHydra - Usenet Meta Indexer (Config - Main - URLBase to /nzbhydra)

Target
NZBHYDRA_ENABLED
Default
false|true
Value
false
NZBHydra URLVariable

Local internal URL for NZBHydra service (usually http://nzbhydra:5076)

Target
NZBHYDRA_URL
Default
http://nzbhydra:5076
Value
http://nzbhydra:5076
Enable TransmissionVariable

Transmission - Torrent Client

Target
TRANSMISSION_ENABLED
Default
false|true
Value
false
Transmission URLVariable

Local internal URL for Transmission service (usually http://transmission:9091)

Target
TRANSMISSION_URL
Default
http://transmission:9091
Value
http://transmission:9091
Enable qBittorrentVariable

qBittorrent - Torrent Client

Target
QBITTORRENT_ENABLED
Default
false|true
Value
false
qBittorrent URLVariable

Local internal URL for qBittorrent service (check for port conflicts; default is http://qbittorrent:8080)

Target
QBITTORRENT_URL
Default
http://qbittorrent:8080
Value
http://qbittorrent:8080
Enable DelugeVariable

Deluge - Torrent Client

Target
DELUGE_ENABLED
Default
false|true
Value
false
Deluge URLVariable

Local internal URL for Deluge service (usually http://deluge:8112)

Target
DELUGE_URL
Default
http://deluge:8112
Value
http://deluge:8112
Enable SonarrVariable

Sonarr - TV Show Automation (Settings - General - URL Base to /sonarr)

Target
SONARR_ENABLED
Default
false|true
Value
false
Sonarr URLVariable

Local internal URL for Sonarr service (usually http://sonarr:8989)

Target
SONARR_URL
Default
http://sonarr:8989
Value
http://sonarr:8989
Sonarr LandingVariable

Landing page (e.g., sonarr, sonarr/calendar)

Target
SONARR_LANDING
Default
sonarr
Value
sonarr
Enable RadarrVariable

Radarr - Movie Automation ((Settings - General - URL Base to /radarr)

Target
RADARR_ENABLED
Default
false|true
Value
false
Radarr URLVariable

Local internal URL for Radarr service (usually http://radarr:7878)

Target
RADARR_URL
Default
http://radarr:7878
Value
http://radarr:7878
Radarr LandingVariable

Landing page (e.g., radarr, radarr/calendar)

Target
RADARR_LANDING
Default
radarr
Value
radarr
Enable WhisparrVariable

Whisparr - Adult Content Automation (Settings - General - URL Base to /whisparr)

Target
WHISPARR_ENABLED
Default
false|true
Value
false
Whisparr URLVariable

Local internal URL for Whisparr service (usually http://whisparr:6969)

Target
WHISPARR_URL
Default
http://whisparr:6969
Value
http://whisparr:6969
Whisparr LandingVariable

Landing page for Whisparr (e.g., whisparr, whisparr/calendar). Leave blank for default

Target
WHISPARR_LANDING
Default
whisparr
Value
whisparr
Enable LidarrVariable

Lidarr - Music Automation (Settings - General - URL Base to to /lidarr)

Target
LIDARR_ENABLED
Default
false|true
Value
false
Lidarr URLVariable

Local internal URL for Lidarr service (usually http://lidarr:8686)

Target
LIDARR_URL
Default
http://lidarr:8686
Value
http://lidarr:8686
Lidarr LandingVariable

Landing page for Lidarr (e.g., lidarr, lidarr/library). Leave blank for default

Target
LIDARR_LANDING
Default
lidarr
Value
lidarr
Enable ProwlarrVariable

Prowlarr - Indexer Manager (Settings - General - URL Base to /prowlarr)

Target
PROWLARR_ENABLED
Default
false|true
Value
false
Prowlarr URLVariable

Local internal URL for Prowlarr service (usually http://prowlarr:9696)

Target
PROWLARR_URL
Default
http://prowlarr:9696
Value
http://prowlarr:9696
Enable JackettVariable

Jackett - Indexer Aggregator (Config - Admin - url_base() to /jackett). For public mode with OAuth, configure JACKETT_OAUTH_URI in advanced settings

Target
JACKETT_ENABLED
Default
false|true
Value
false
Jackett URLVariable

Local internal URL for Jackett service (usually http://jackett:9117)

Target
JACKETT_URL
Default
http://jackett:9117
Value
http://jackett:9117
Enable SeerrVariable

Seerr - Request Manager (In public mode, uses subdomain routing). For public mode with OAuth, also set SEERR_DOMAIN and SEERR_REDIRECT_URI

Target
SEERR_ENABLED
Default
false|true
Value
false
Seerr URLVariable

Local internal URL for Seerr service

Target
SEERR_URL
Default
http://seerr:5055
Value
http://seerr:5055
Seerr DomainVariable

Subdomain for Seerr (e.g., seerr.yourdomain.com). For public mode with OAuth, also set SEERR_REDIRECT_URI to https://[SEERR_DOMAIN]/oauth2callback

Target
SEERR_DOMAIN
Enable BazarrVariable

Bazarr - Subtitle Manager (Settings - General - Base URL to /bazarr)

Target
BAZARR_ENABLED
Default
false|true
Value
false
Bazarr URLVariable

Local internal URL for Bazarr service (usually http://bazarr:6767)

Target
BAZARR_URL
Default
http://bazarr:6767
Value
http://bazarr:6767
Enable JellyfinVariable

Jellyfin - Media Server (Settings -Admin Dash - Networking - Base URL /jellyfin)

Target
JELLYFIN_ENABLED
Default
false|true
Value
false
Jellyfin URLVariable

Local internal URL for Jellyfin service (usually http://jellyfin:8096)

Target
JELLYFIN_URL
Default
http://jellyfin:8096
Value
http://jellyfin:8096
Enable EmbyVariable

Emby - Media Server (In public mode, uses subdomain routing). For public mode with OAuth, also set EMBY_DOMAIN and EMBY_REDIRECT_URI

Target
EMBY_ENABLED
Default
false|true
Value
false
Emby URLVariable

Local internal URL for Emby service

Target
EMBY_URL
Default
http://emby:8096
Value
http://emby:8096
Emby DomainVariable

Subdomain for Emby (e.g., emby.yourdomain.com). For public mode with OAuth, also set EMBY_REDIRECT_URI to https://[EMBY_DOMAIN]/oauth2callback

Target
EMBY_DOMAIN
Enable PlexVariable

Plex - Media Server (in public mode, uses subdomain routing). For public mode with OAuth, also set PLEX_DOMAIN and PLEX_REDIRECT_URI

Target
PLEX_ENABLED
Default
false|true
Value
false
Plex URLVariable

Local internal URL for Plex service (usually http://plex:32400)

Target
PLEX_URL
Default
http://plex:32400
Value
http://plex:32400
Plex DomainVariable

Subdomain for Plex (e.g., plex.yourdomain.com). For public mode with OAuth, also set PLEX_REDIRECT_URI to https://[PLEX_DOMAIN]/oauth2callback

Target
PLEX_DOMAIN
Enable TautulliVariable

Tautulli - Plex Analytics (Settings - Show Advanced - Web Interface - Enable Proxy, Set Public Domain to https://yahlp.yourdomain.com/tautulli and HTTP root to /tautulli)

Target
TAUTULLI_ENABLED
Default
false|true
Value
false
Tautulli URLVariable

Local internal URL for Tautulli service (usually http://tautulli:8181/tautulli)

Target
TAUTULLI_URL
Default
http://tautulli:8181
Value
http://tautulli:8181
Enable MaintainerrVariable

Maintainerr - Media Server Maintenance (Enable BASE_URL environment variable on its docker and set to /maintainerr)

Target
MAINTAINERR_ENABLED
Default
false|true
Value
false
Maintainerr URLVariable

Local internal URL for Maintainerr service (usually http://maintainerr:6246)

Target
MAINTAINERR_URL
Default
http://maintainerr:6246
Value
http://maintainerr:6246
PUIDVariable

User ID for file permissions (99 = nobody)

Default
99
Value
99
PGIDVariable

Group ID for file permissions (100 = users)

Default
100
Value
100
ConfigurationPathrw

Configuration folder - store the yahlp and sites JSON5 files here - ENV Variables override config settings, remove the variable settings from the form. Custom templates in the templates folder

Target
/etc/yahlp
Default
/mnt/user/appdata/yahlp
Value
/mnt/user/appdata/yahlp
TimezonePathro

Read Timezone from host

Target
/etc/localtime
Default
/etc/localtime
Value
/etc/localtime