Improve very slow library scans on Jellyfin 10.11 / 12 on spinning media

submitted by edited
Improve very slow library scans on Jellyfin 10.11 / 12 on spinning media

I’ve been trying to upgrade from 10.10 to 10.11 for a while now, as the Android TV app keeps nagging me, and every attempt ended with impossibly long library scan times.

After some thorough investigation, it appeared that a Home Videos type collection causes unending scan (yet to be solved), but also that Jellyfin does a lot of writes to the config directory (either database or metadata or both). Mine’s on spinning media part of a ZFS pool. I tried a few performance tuning options, such as testing the config dir with recordsize (similar to block size) of 4K, 8K, 64K, 128K and library scans fell from 30-40 minutes down to 8-13min with 4K-64K. The ZFS tuning wiki suggest 64K recordsize with LZ4 compression for SQLite workloads such as Jellyfin. That seems to work as well as 4K and 8K but likely is faster when reading thumbnails and such.

Note that upgrading to 12-rc3, which is supposed to speed up library scans did not improve scan times for me. Optimizing config/database write speed did. I cross-checked the culprit by experimenting with moving the config dir to NVMe and RAM. Both of those got the scan times down to 8-9 minutes compared to the optimized spinning media’s 12-13.

So if you had upgraded (or about to) to 10.11 your library scans are (about to get) dog slow and your Jellyfin’s config dir resides on spinning media, optimize its write performance for SQLite.

82
501

Back to main discussion

Parent comment

Let’scrypt and port forward. Sprinkle on some free ddns with a sync script/job to keep ddns pointing to your real public IP. Can even roll in some headscale if you’re feeling adventurous

Feeling adventurous is exactly what you need if you decide to expose Jellyfin to the Internet (a reverse proxy adds nothing to security)

Jellyfin doesn’t open up your network unless you specifically allow remote access exactly like Plex. The only difference is Jellyfin doesn’t have the encrypted tunnel built in- you need to know it needs it and add it yourself.

Plex has had bugs that allowed remote access into your home’s Plex server. https://nvd.nist.gov/vuln/detail/CVE-2025-34158

That poster specifically said if you open jellyfin up to the internet ……

Reading comprehension and Jellyfin stanning don’t go well together

He said an encrypted tunnel does nothing. I don’t even run Jellyfin but that statement is false.

An encrypted tunnel and a reverse proxy are two very different things. He (I) never talked about a tunnel and neither did the comment I (he) responded to

The reason to run the reverse proxy with Jellyfin is for the encryption. It’s written in the documentation that way. It’s why I still run Plex. I never finished getting through their steps to get the reverse proxy setup for the encryption.

It’s like I said you use a car to go to work and you reply AKSUALLY a car runs on TIRES. The OP didn’t say CAR.





Which Plex does by default. He doesn’t understand that running Plex at home opens itself up to the Internet. I specifically referenced a CVE that let hackers into your home if you ran Plex.

His claim that securing Jellyfin with an encrypted tunnel does nothing is false.

He never claimed that in the comment you replied to.

Plex doesn’t open a port to the internet at large, unsecured no less, like jellyfin does.

You obviously don’t use Plex to claim it doesn’t need an open port for remote access:

https://support.plex.tv/articles/201543147-what-network-ports-do-i-need-to-allow-through-my-firewall/

I already posted a CVE that allowed hackers access to a Plex server running at home.

OK so you don’t understand networking, don’t understand how Plex works, don’t understand how that CVE does nothing of the sort, and have poor reading comprehension skills.

I’d hate to be your poor server.

I quoted Plex documentation where it explains in detail that you need port 32400 OPEN for remote access. https://support.plex.tv/articles/200289506-remote-access/

I linked the CVE but here is the plain language version because you didn’t read what I linked:

https://www.howtogeek.com/over-300k-plex-servers-are-still-vulnerable-to-attackers-despite-emails/

“The flaw has been assigned a CVSS score of 10.0, the highest possible level of severity. This score indicates that the vulnerability can be exploited remotely over the internet, is easy to execute, and requires no authentication or interaction from the server’s owner. A successful attack could result in a total loss of confidentiality, integrity, and availability. An attacker could access, modify, or delete a user’s private media files, or even disable the entire Plex server. "

What the fuck is wrong with you?










Insert image