BLACKFYRE
MG—01
LANG
←
ALL POSTS
05 · Writing / 2025
21 OCT 2025 · 9 MIN READ

Building a Complete Self-Hosted Media Automation Suite with Podman Quadlets

A guide to a containerised media automation setup using the Arr stack, Podman Quadlets and systemd on Fedora Server.

CONTENTS
13 +

Introduction

In the age of streaming services and digital media, managing a personal media library has become increasingly complex. This article documents the creation of a complete self-hosted media automation suite that automatically discovers, downloads, organises and serves your media collection, while maintaining the highest standards of security and reliability.

The solution leverages the powerful “Arr” ecosystem — a collection of applications designed to work together seamlessly — deployed using Podman Quadlets, a modern container orchestration approach that integrates natively with systemd. This setup provides enterprise-grade reliability while remaining lightweight and maintainable for home lab deployments.

Enlarge imageDiagram: a user reaches the server through the firewall; Traefik routes the traffic on to Sonarr, Radarr and Prowlarr
FIG. 1Every request comes in through the firewall and Traefik.

Architecture overview

The Arr ecosystem

At its core, this setup implements the complete Arr workflow:

Prowlarr (indexer manager) → Sonarr / Radarr / Lidarr / Readarr (media managers) → qBittorrent (download client) → Bazarr (subtitles) → Jellyfin (media server)

Core components:

ServicePortRole
Prowlarr9696The central indexer manager with 200+ preconfigured torrent trackers
Sonarr8989TV show automation and library management
Radarr7878Film discovery, download and organisation
Lidarr8686Music library automation
Readarr8787Ebook and audiobook management
qBittorrent8080Primary BitTorrent client for media downloads
Bazarr6767Subtitle automation for films and TV shows

Media servers and services:

ServicePortRole
Jellyfin8096Open-source media streaming server
Audiobookshelf13378Specialised audiobook and podcast server
ConvertX3000Self-hosted file format converter supporting 1000+ formats
ThinkDashboard8082Lightweight bookmark dashboard with keyboard shortcuts

Infrastructure services:

ServicePortRole
Traefik80/443Reverse proxy with automatic SSL via Let’s Encrypt
n8n5678Workflow automation platform for custom integrations
PostgreSQL5432Database backend for n8n and other services
Jaeger16686Distributed tracing for performance monitoring
RustDesk21115–21119Self-hosted remote desktop solution

Why Podman Quadlets?

Traditional container orchestration often involves complex YAML files and external orchestrators. Podman Quadlets take a different approach by integrating directly with systemd, providing:

  1. Native systemd integration: services behave like traditional system services
  2. Dependency management: proper startup ordering through systemd directives
  3. Resource management: leverage systemd’s resource controls and monitoring
  4. Security: rootless containers with SELinux integration
  5. Simplicity: no external orchestrator required

Deployment architecture

Container network design

The entire suite runs within a single Podman network (arr-suite) using the subnet 10.89.0.0/16. This approach provides:

  • Network isolation: services communicate internally without exposing unnecessary ports
  • Service discovery: containers can reach each other by name
  • Security: external access is controlled through the Traefik reverse proxy
  • Monitoring: centralised traffic analysis and logging

Storage strategy

The setup uses a three-tier storage approach:

  1. Configuration storage: /home/user/arr-suite/config/ — persistent service configurations
  2. Media library: /mnt/nas/media/ — final organised media storage
  3. Download staging: /mnt/nas/downloads/ — temporary download processing area

This separation ensures data durability while allowing for efficient content processing workflows.

Security model

Security is implemented through multiple layers:

  • Rootless containers: all services run without root privileges
  • SELinux integration: file access controlled via SELinux contexts (:z flags)
  • Network segmentation: internal communication only, external access via Traefik
  • Automated SSL: Let’s Encrypt certificates with automatic renewal
  • Firewall integration: automated firewall rule management

Key implementation details

Quadlet configuration structure

Each service is defined through a .container file that follows systemd unit file syntax:

quadlets/sonarr.container
INI
1[Unit]
2Description=sonarr container
3Wants=network-online.target
4After=network-online.target arr-suite-network.service qbittorrent.service prowlarr.service
5Requires=arr-suite-network.service qbittorrent.service prowlarr.service
6
7[Container]
8Image=lscr.io/linuxserver/sonarr:latest
9ContainerName=sonarr
10PublishPort=8989:8989
11Network=arr-suite.network
12Volume=/home/user/arr-suite/config/sonarr:/config:z
13Volume=/mnt/nas/media:/media:z
14Volume=/mnt/nas/downloads:/downloads:z
15Environment=PUID=1000
16Environment=PGID=1000
17Environment=TZ=Europe/Budapest
18Label=io.containers.autoupdate=registry
19Label=traefik.enable=true
20Label=traefik.http.routers.sonarr.rule=Host(`sonarr.my-address.noip.me`)
21Label=traefik.http.routers.sonarr.tls=true
22Label=traefik.http.routers.sonarr.tls.certresolver=letsencrypt
23Label=traefik.http.services.sonarr.loadbalancer.server.port=8989
24Label=traefik.http.routers.sonarr.middlewares=default-headers@file
25
26[Service]
27Restart=always
28
29[Install]
30WantedBy=default.target

Automatic service discovery

The system includes intelligent dependency resolution that automatically determines the startup order based on Requires and After directives. The management script analyses these relationships and starts services in the correct sequence.

Reverse proxy integration

Traefik provides sophisticated routing through container labels:

  • Automatic SSL: Let’s Encrypt certificates for *.my-address.noip.me
  • Subdomain routing: each service is accessible via a dedicated subdomain
  • Security headers: automatic security middleware application
  • Dynamic configuration: services auto-register when containers start

Infrastructure automation

The setup includes several automation components:

  • Traefik configuration generator: automatically creates the dynamic routing config from container labels
  • DNS management: updates external DNS records for dynamic IP addresses
  • Service health monitoring: comprehensive status checking and alerting
  • Automatic updates: container images update automatically via registry labels

Security hardening

fail2ban integration: optional enhanced security through Traefik’s fail2ban plugin:

  • Automatic IP blocking for repeated authentication failures
  • Protection against brute-force attacks on administrative interfaces
  • Configurable ban duration and retry thresholds
  • Integration with the system’s fail2ban for coordinated defence
  • Real-time threat detection and response

Advanced features

Specialised content handling

Multi-format support: ConvertX provides universal file conversion:

  • 1000+ supported formats, including documents, images and videos
  • A self-hosted alternative to online conversion services
  • Integration with the media workflow for format standardisation

Workflow automation

n8n integration: the workflow platform enables custom automation:

  • API integration with all Arr services
  • Custom notification workflows
  • Advanced content processing rules
  • PostgreSQL backend for workflow persistence

Custom scripts: automated maintenance and configuration:

  • Dynamic Traefik configuration generation
  • DNS record management for dynamic IPs
  • Service health monitoring and alerting
  • Automated backup and restore procedures

Performance monitoring

Jaeger tracing: comprehensive performance analysis:

  • Distributed request tracing across services
  • Performance bottleneck identification
  • API call monitoring and optimisation
  • Historical performance trend analysis

Management and operations

Service management

The setup includes a comprehensive management script (setup-quadlets.sh) that serves as the central control point for the entire arr-suite infrastructure. This intelligent script automatically discovers services from Quadlet definitions and provides sophisticated dependency management.

Automatic service discovery: the script dynamically discovers all services by scanning the quadlets/ directory for .container and .network files, eliminating the need for manual service registration.

Intelligent dependency resolution: by parsing the Requires and After directives in Quadlet files, the script builds a dependency graph and determines the optimal startup order, ensuring services start only after their dependencies are ready.

Comprehensive operations:

setup-quadlets.sh
SHELL
# Initial setup and configuration
$./setup-quadlets.sh setup
# Creates systemd symlinks, reloads daemon, opens firewall ports
# Service lifecycle management
$./setup-quadlets.sh start|stop|restart
# Handles services in correct dependency order
# Health and status monitoring
$./setup-quadlets.sh status
# Shows systemd status, port exposure, and service descriptions
# Network diagnostics
$./setup-quadlets.sh ports # List all exposed ports
$./setup-quadlets.sh urls # Generate service URLs for quick access
# Individual service operations
$./setup-quadlets.sh logs # View service logs
$./setup-quadlets.sh shell # Access container shell
$./setup-quadlets.sh inspect # Container inspection

Advanced capabilities

Firewall integration: automatically detects required ports from the Quadlet PublishPort directives and manages firewalld rules, ensuring security while maintaining functionality.

Error handling: robust error checking with coloured output for clear status indication — red for errors, green for success, yellow for warnings.

Batch operations: supports operating on all services simultaneously while respecting dependency ordering, preventing race conditions during startup and shutdown.

Validation: pre-flight checks ensure systemd can parse Quadlet files before attempting operations, catching configuration errors early.

Script architecture

The management script follows several key design principles:

  • Declarative configuration: all service definitions live in Quadlet files — the script discovers and acts on this configuration rather than maintaining separate service lists.
  • Idempotent operations: running setup multiple times produces the same result, making it safe to re-run for updates or troubleshooting.
  • Fail-fast design: operations stop immediately on errors with clear diagnostic messages, preventing cascading failures.
  • Dependency-aware: all operations respect service dependencies, whether starting services, stopping them, or performing maintenance tasks.

The script automatically handles complex scenarios like:

  • Services with circular dependencies (detection and graceful handling)
  • Network services that must start before container services
  • Proper cleanup during shutdown to avoid resource leaks
  • Automatic systemd daemon reloads when Quadlet files change

Firewall integration

Automatic firewall management ensures security while maintaining functionality:

  • Port analysis: automatic detection of required ports from Quadlet definitions
  • Rule generation: dynamic firewall rule creation and management
  • Security validation: verification that only necessary ports are exposed

Configuration management

Each service maintains persistent configuration through dedicated directories:

config/
TEXT
1config/
2├── sonarr/ # TV show management configuration
3├── radarr/ # Film management configuration
4├── prowlarr/ # Indexer definitions and settings
5├── qbittorrent/ # Download client settings
6├── traefik/ # Reverse proxy configuration
7└── jellyfin/ # Media server preferences

Scalability and maintenance

Horizontal scaling

The architecture supports easy expansion:

  • Additional services: new Arr applications can be added via additional Quadlet files
  • Geographic distribution: services can be distributed across multiple nodes
  • Load balancing: Traefik supports multiple backend instances

Maintenance procedures

Automated updates: services update automatically via container registry labels:

INI
1Label=io.containers.autoupdate=registry

Backup strategy: configuration data is separated from container images:

  • Configuration directories can be backed up independently
  • Container images are pulled fresh during updates
  • Database backups are handled automatically for PostgreSQL

Health monitoring: comprehensive service health checks:

  • systemd-native service monitoring
  • Traefik health check integration
  • Custom monitoring scripts for application-specific metrics

Security considerations

Container security

Rootless operation: all containers run without root privileges:

  • Reduced attack surface
  • Limited system access
  • User namespace isolation

SELinux integration: fine-grained access controls:

  • File system access restrictions via :z volume labels
  • Network policy enforcement
  • Process isolation and monitoring

Network security

Zero-trust architecture: no service trusts any other by default:

  • All communication through authenticated channels
  • Network segmentation through container networks
  • Traffic monitoring and logging

SSL/TLS everywhere: end-to-end encryption:

  • Automatic Let’s Encrypt certificate management
  • HTTPS enforcement for all services
  • Internal service communication encryption

Access control

Reverse proxy security: centralised security policy enforcement:

  • Authentication middleware for administrative interfaces
  • Rate limiting and DDoS protection
  • Security header injection
  • Optional fail2ban plugin integration for automated IP blocking on suspicious activity

Performance optimisation

Resource allocation

Memory management: optimised container resource limits:

  • Service-specific memory allocations
  • Swap usage monitoring and optimisation
  • Garbage collection tuning for media processing

Storage optimisation: efficient data handling:

  • Separate volumes for different data types
  • Optimised filesystem choices for media storage
  • Automatic cleanup of temporary processing files

Network performance

Internal communication: optimised service-to-service communication:

  • Container network performance tuning
  • Connection pooling for database services
  • Caching strategies for API endpoints

Troubleshooting and diagnostics

Logging strategy

Centralised logging: comprehensive log management:

  • systemd journal integration
  • Application-specific log files
  • Log rotation and retention policies

Diagnostic tools: built-in troubleshooting capabilities:

  • Service dependency visualisation
  • Network connectivity testing
  • Performance profiling tools

Common issues and solutions

Service startup problems: dependency resolution issues:

  • Automatic dependency order resolution
  • Service health check validation
  • Configuration validation tools

Network connectivity: inter-service communication problems:

  • Network topology visualisation
  • Port conflict detection and resolution
  • DNS resolution debugging

Future enhancements

Enhanced monitoring: additional observability features:

  • Metrics collection and visualisation
  • Alerting and notification systems
  • Performance trend analysis

Backup and recovery: comprehensive data protection:

  • Automated configuration backups
  • Media library checksumming and validation
  • Disaster recovery procedures

Advanced automation: extended workflow capabilities:

  • Machine learning for content recommendations
  • Advanced content processing pipelines
  • Integration with external media databases

Conclusion

This media automation suite represents a modern approach to self-hosted media management, combining the power of the Arr ecosystem with the reliability of systemd and the security of containerised deployment. The use of Podman Quadlets provides a unique balance between simplicity and enterprise-grade features, making it suitable for both home lab enthusiasts and production deployments.

The architecture’s modular design ensures easy maintenance and expansion, while the comprehensive automation reduces operational overhead. Security is built in from the ground up, with multiple layers of protection ensuring your media collection remains safe and accessible.

Whether you’re building a personal media server or deploying infrastructure for a small organisation, this setup provides a solid foundation that can grow with your needs while maintaining the highest standards of reliability and security.

Resources and further reading

I’ve created a template repository at codeberg.org/blackfyre/arr-suite for your scrutiny!

TAGS
Podman
systemd
Self-hosting
Linux
06 · CONTACT

Have a system that needs building?

GET IN TOUCH → PROJECTS →
PRODUCT DATA SHEET
MG—01
BLACKFYRE
S/N MG-1985-1027
Miklós Galicz — Golang Advocate · Solution Architect
MODEL
MG—01 "Miklós Galicz"
SERIES
1985
ORIGIN
Nagykovácsi, Hungary
FUNCTION
Senior Full Stack Engineer · Solution Architect
CORE LANGUAGES
Go · PHP · JavaScript
SPOKEN
Hungarian · English · German
SERVICE LIFE
~20 years in software, ongoing
POWER SUPPLY
Coffee, 2–4 cups / day
DIMENSIONS
1 × human, standard size
OPERATING TEMP.
Calm under production incidents
CONNECTIVITY
[email protected] · github.com/blackfyre · linkedin.com/in/galiczmiklos
Less, but better. Specifications subject to continuous improvement.
● ● ●
MG—01 · SERIES 1985
№ MG-1985-1027
CERTIFICATE OF OPERATION
Certified Operator
Has located every documented feature of the MG—01 without reading the manual. Probably.
TIME
—
FEATURES
—
DATE
—
SIGNED
Miklós Galicz