CONTENTS13 +
Introduction
In the age of streaming services and digital media, managing a personal media library has become increasingly complex. This article documents the creation of a complete self-hosted media automation suite that automatically discovers, downloads, organises and serves your media collection, while maintaining the highest standards of security and reliability.
The solution leverages the powerful “Arr” ecosystem — a collection of applications designed to work together seamlessly — deployed using Podman Quadlets, a modern container orchestration approach that integrates natively with systemd. This setup provides enterprise-grade reliability while remaining lightweight and maintainable for home lab deployments.
Architecture overview
The Arr ecosystem
At its core, this setup implements the complete Arr workflow:
Prowlarr (indexer manager) → Sonarr / Radarr / Lidarr / Readarr (media managers) → qBittorrent (download client) → Bazarr (subtitles) → Jellyfin (media server)
Core components:
| Service | Port | Role |
|---|---|---|
| Prowlarr | 9696 | The central indexer manager with 200+ preconfigured torrent trackers |
| Sonarr | 8989 | TV show automation and library management |
| Radarr | 7878 | Film discovery, download and organisation |
| Lidarr | 8686 | Music library automation |
| Readarr | 8787 | Ebook and audiobook management |
| qBittorrent | 8080 | Primary BitTorrent client for media downloads |
| Bazarr | 6767 | Subtitle automation for films and TV shows |
Media servers and services:
| Service | Port | Role |
|---|---|---|
| Jellyfin | 8096 | Open-source media streaming server |
| Audiobookshelf | 13378 | Specialised audiobook and podcast server |
| ConvertX | 3000 | Self-hosted file format converter supporting 1000+ formats |
| ThinkDashboard | 8082 | Lightweight bookmark dashboard with keyboard shortcuts |
Infrastructure services:
| Service | Port | Role |
|---|---|---|
| Traefik | 80/443 | Reverse proxy with automatic SSL via Let’s Encrypt |
| n8n | 5678 | Workflow automation platform for custom integrations |
| PostgreSQL | 5432 | Database backend for n8n and other services |
| Jaeger | 16686 | Distributed tracing for performance monitoring |
| RustDesk | 21115–21119 | Self-hosted remote desktop solution |
Why Podman Quadlets?
Traditional container orchestration often involves complex YAML files and external orchestrators. Podman Quadlets take a different approach by integrating directly with systemd, providing:
- Native systemd integration: services behave like traditional system services
- Dependency management: proper startup ordering through systemd directives
- Resource management: leverage systemd’s resource controls and monitoring
- Security: rootless containers with SELinux integration
- Simplicity: no external orchestrator required
Deployment architecture
Container network design
The entire suite runs within a single Podman network (arr-suite) using the subnet 10.89.0.0/16. This approach provides:
- Network isolation: services communicate internally without exposing unnecessary ports
- Service discovery: containers can reach each other by name
- Security: external access is controlled through the Traefik reverse proxy
- Monitoring: centralised traffic analysis and logging
Storage strategy
The setup uses a three-tier storage approach:
- Configuration storage:
/home/user/arr-suite/config/— persistent service configurations - Media library:
/mnt/nas/media/— final organised media storage - Download staging:
/mnt/nas/downloads/— temporary download processing area
This separation ensures data durability while allowing for efficient content processing workflows.
Security model
Security is implemented through multiple layers:
- Rootless containers: all services run without root privileges
- SELinux integration: file access controlled via SELinux contexts (
:zflags) - Network segmentation: internal communication only, external access via Traefik
- Automated SSL: Let’s Encrypt certificates with automatic renewal
- Firewall integration: automated firewall rule management
Key implementation details
Quadlet configuration structure
Each service is defined through a .container file that follows systemd unit file syntax:
1[Unit]2Description=sonarr container3Wants=network-online.target4After=network-online.target arr-suite-network.service qbittorrent.service prowlarr.service5Requires=arr-suite-network.service qbittorrent.service prowlarr.service67[Container]8Image=lscr.io/linuxserver/sonarr:latest9ContainerName=sonarr10PublishPort=8989:898911Network=arr-suite.network12Volume=/home/user/arr-suite/config/sonarr:/config:z13Volume=/mnt/nas/media:/media:z14Volume=/mnt/nas/downloads:/downloads:z15Environment=PUID=100016Environment=PGID=100017Environment=TZ=Europe/Budapest18Label=io.containers.autoupdate=registry19Label=traefik.enable=true20Label=traefik.http.routers.sonarr.rule=Host(`sonarr.my-address.noip.me`)21Label=traefik.http.routers.sonarr.tls=true22Label=traefik.http.routers.sonarr.tls.certresolver=letsencrypt23Label=traefik.http.services.sonarr.loadbalancer.server.port=898924Label=traefik.http.routers.sonarr.middlewares=default-headers@file2526[Service]27Restart=always2829[Install]30WantedBy=default.target
Automatic service discovery
The system includes intelligent dependency resolution that automatically determines the startup order based on Requires and After directives. The management script analyses these relationships and starts services in the correct sequence.
Reverse proxy integration
Traefik provides sophisticated routing through container labels:
- Automatic SSL: Let’s Encrypt certificates for
*.my-address.noip.me - Subdomain routing: each service is accessible via a dedicated subdomain
- Security headers: automatic security middleware application
- Dynamic configuration: services auto-register when containers start
Infrastructure automation
The setup includes several automation components:
- Traefik configuration generator: automatically creates the dynamic routing config from container labels
- DNS management: updates external DNS records for dynamic IP addresses
- Service health monitoring: comprehensive status checking and alerting
- Automatic updates: container images update automatically via registry labels
Security hardening
fail2ban integration: optional enhanced security through Traefik’s fail2ban plugin:
- Automatic IP blocking for repeated authentication failures
- Protection against brute-force attacks on administrative interfaces
- Configurable ban duration and retry thresholds
- Integration with the system’s fail2ban for coordinated defence
- Real-time threat detection and response
Advanced features
Specialised content handling
Multi-format support: ConvertX provides universal file conversion:
- 1000+ supported formats, including documents, images and videos
- A self-hosted alternative to online conversion services
- Integration with the media workflow for format standardisation
Workflow automation
n8n integration: the workflow platform enables custom automation:
- API integration with all Arr services
- Custom notification workflows
- Advanced content processing rules
- PostgreSQL backend for workflow persistence
Custom scripts: automated maintenance and configuration:
- Dynamic Traefik configuration generation
- DNS record management for dynamic IPs
- Service health monitoring and alerting
- Automated backup and restore procedures
Performance monitoring
Jaeger tracing: comprehensive performance analysis:
- Distributed request tracing across services
- Performance bottleneck identification
- API call monitoring and optimisation
- Historical performance trend analysis
Management and operations
Service management
The setup includes a comprehensive management script (setup-quadlets.sh) that serves as the central control point for the entire arr-suite infrastructure. This intelligent script automatically discovers services from Quadlet definitions and provides sophisticated dependency management.
Automatic service discovery: the script dynamically discovers all services by scanning the quadlets/ directory for .container and .network files, eliminating the need for manual service registration.
Intelligent dependency resolution: by parsing the Requires and After directives in Quadlet files, the script builds a dependency graph and determines the optimal startup order, ensuring services start only after their dependencies are ready.
Comprehensive operations:
# Initial setup and configuration$./setup-quadlets.sh setup# Creates systemd symlinks, reloads daemon, opens firewall ports# Service lifecycle management$./setup-quadlets.sh start|stop|restart# Handles services in correct dependency order# Health and status monitoring$./setup-quadlets.sh status# Shows systemd status, port exposure, and service descriptions# Network diagnostics$./setup-quadlets.sh ports # List all exposed ports$./setup-quadlets.sh urls # Generate service URLs for quick access# Individual service operations$./setup-quadlets.sh logs # View service logs$./setup-quadlets.sh shell # Access container shell$./setup-quadlets.sh inspect # Container inspection
Advanced capabilities
Firewall integration: automatically detects required ports from the Quadlet PublishPort directives and manages firewalld rules, ensuring security while maintaining functionality.
Error handling: robust error checking with coloured output for clear status indication — red for errors, green for success, yellow for warnings.
Batch operations: supports operating on all services simultaneously while respecting dependency ordering, preventing race conditions during startup and shutdown.
Validation: pre-flight checks ensure systemd can parse Quadlet files before attempting operations, catching configuration errors early.
Script architecture
The management script follows several key design principles:
- Declarative configuration: all service definitions live in Quadlet files — the script discovers and acts on this configuration rather than maintaining separate service lists.
- Idempotent operations: running setup multiple times produces the same result, making it safe to re-run for updates or troubleshooting.
- Fail-fast design: operations stop immediately on errors with clear diagnostic messages, preventing cascading failures.
- Dependency-aware: all operations respect service dependencies, whether starting services, stopping them, or performing maintenance tasks.
The script automatically handles complex scenarios like:
- Services with circular dependencies (detection and graceful handling)
- Network services that must start before container services
- Proper cleanup during shutdown to avoid resource leaks
- Automatic systemd daemon reloads when Quadlet files change
Firewall integration
Automatic firewall management ensures security while maintaining functionality:
- Port analysis: automatic detection of required ports from Quadlet definitions
- Rule generation: dynamic firewall rule creation and management
- Security validation: verification that only necessary ports are exposed
Configuration management
Each service maintains persistent configuration through dedicated directories:
1config/2├── sonarr/ # TV show management configuration3├── radarr/ # Film management configuration4├── prowlarr/ # Indexer definitions and settings5├── qbittorrent/ # Download client settings6├── traefik/ # Reverse proxy configuration7└── jellyfin/ # Media server preferences
Scalability and maintenance
Horizontal scaling
The architecture supports easy expansion:
- Additional services: new Arr applications can be added via additional Quadlet files
- Geographic distribution: services can be distributed across multiple nodes
- Load balancing: Traefik supports multiple backend instances
Maintenance procedures
Automated updates: services update automatically via container registry labels:
1Label=io.containers.autoupdate=registry
Backup strategy: configuration data is separated from container images:
- Configuration directories can be backed up independently
- Container images are pulled fresh during updates
- Database backups are handled automatically for PostgreSQL
Health monitoring: comprehensive service health checks:
- systemd-native service monitoring
- Traefik health check integration
- Custom monitoring scripts for application-specific metrics
Security considerations
Container security
Rootless operation: all containers run without root privileges:
- Reduced attack surface
- Limited system access
- User namespace isolation
SELinux integration: fine-grained access controls:
- File system access restrictions via
:zvolume labels - Network policy enforcement
- Process isolation and monitoring
Network security
Zero-trust architecture: no service trusts any other by default:
- All communication through authenticated channels
- Network segmentation through container networks
- Traffic monitoring and logging
SSL/TLS everywhere: end-to-end encryption:
- Automatic Let’s Encrypt certificate management
- HTTPS enforcement for all services
- Internal service communication encryption
Access control
Reverse proxy security: centralised security policy enforcement:
- Authentication middleware for administrative interfaces
- Rate limiting and DDoS protection
- Security header injection
- Optional fail2ban plugin integration for automated IP blocking on suspicious activity
Performance optimisation
Resource allocation
Memory management: optimised container resource limits:
- Service-specific memory allocations
- Swap usage monitoring and optimisation
- Garbage collection tuning for media processing
Storage optimisation: efficient data handling:
- Separate volumes for different data types
- Optimised filesystem choices for media storage
- Automatic cleanup of temporary processing files
Network performance
Internal communication: optimised service-to-service communication:
- Container network performance tuning
- Connection pooling for database services
- Caching strategies for API endpoints
Troubleshooting and diagnostics
Logging strategy
Centralised logging: comprehensive log management:
- systemd journal integration
- Application-specific log files
- Log rotation and retention policies
Diagnostic tools: built-in troubleshooting capabilities:
- Service dependency visualisation
- Network connectivity testing
- Performance profiling tools
Common issues and solutions
Service startup problems: dependency resolution issues:
- Automatic dependency order resolution
- Service health check validation
- Configuration validation tools
Network connectivity: inter-service communication problems:
- Network topology visualisation
- Port conflict detection and resolution
- DNS resolution debugging
Future enhancements
Enhanced monitoring: additional observability features:
- Metrics collection and visualisation
- Alerting and notification systems
- Performance trend analysis
Backup and recovery: comprehensive data protection:
- Automated configuration backups
- Media library checksumming and validation
- Disaster recovery procedures
Advanced automation: extended workflow capabilities:
- Machine learning for content recommendations
- Advanced content processing pipelines
- Integration with external media databases
Conclusion
This media automation suite represents a modern approach to self-hosted media management, combining the power of the Arr ecosystem with the reliability of systemd and the security of containerised deployment. The use of Podman Quadlets provides a unique balance between simplicity and enterprise-grade features, making it suitable for both home lab enthusiasts and production deployments.
The architecture’s modular design ensures easy maintenance and expansion, while the comprehensive automation reduces operational overhead. Security is built in from the ground up, with multiple layers of protection ensuring your media collection remains safe and accessible.
Whether you’re building a personal media server or deploying infrastructure for a small organisation, this setup provides a solid foundation that can grow with your needs while maintaining the highest standards of reliability and security.
Resources and further reading
- Podman Quadlets documentation
- Arr application documentation
- Traefik reverse proxy guide
- systemd service management
I’ve created a template repository at codeberg.org/blackfyre/arr-suite for your scrutiny!