Homelab operations

Running Tidefetch as a long-lived service on a NAS, mini PC, VM or small cluster. The baseline is one instance, persistent config and download storage, a strong password, and TLS or a VPN for anything beyond the LAN.

Topology

LAN / VPN clients
       │
       ▼
TLS reverse proxy :443
       │ private network
       ▼
tidefetch serve :8210 ──loopback RPC──> aria2
       │
       ├── /config     config, session, history, password hash
       └── /downloads  finished and partial files

The container image keeps aria2's RPC on loopback; never publish port 6800. Ports 6881 TCP and UDP are optional and only improve inbound BitTorrent connectivity.

Pick a platform guide: Docker and Podman, Docker Swarm, Kubernetes and k3s, Unraid or bare metal with systemd.

Storage

Choose paths covered by your backup policy and hand them to UID/GID 1000, which the image runs as:

sudo mkdir -p /srv/tidefetch/config /srv/downloads
sudo chown -R 1000:1000 /srv/tidefetch/config /srv/downloads
sudo chmod 700 /srv/tidefetch/config
  • On NFS, confirm that root squashing and UID mapping still let UID 1000 create, rename and delete files; aria2 renames files on completion.
  • Avoid SMB/CIFS for in-progress downloads when a local filesystem or NFS is available. If CIFS is unavoidable, mount it on the host with uid=1000,gid=1000 before starting the container.
  • Put in-progress downloads on SSD when you expect many concurrent writes, and move finished files afterwards if needed.
  • Keep file-allocation=none, the default, on copy-on-write or thin-provisioned storage.

Networking

Port Protocol Required Purpose
8210 TCP Yes Web UI and HTTP API
6881 TCP Optional Incoming BitTorrent peers
6881 UDP Optional DHT and UDP trackers
6800 TCP Never publish Internal aria2 RPC

Forward 6881 TCP and UDP from your router only if you use BitTorrent and want inbound peers. Never forward 8210 to the internet without TLS and a password.

For remote access, a VPN such as Tailscale or WireGuard is simpler and safer than a public port. For a public hostname, follow Reverse proxy and TLS.

Secrets

Prefer a password file over an environment variable, so the password never shows in docker inspect or ps:

sudo mkdir -p /opt/tidefetch/secrets
openssl rand -base64 36 | sudo tee /opt/tidefetch/secrets/web_password >/dev/null
sudo chmod 600 /opt/tidefetch/secrets/web_password

Mount it and set TIDEFETCH_PASSWORD_FILE, as in the Compose secrets example.

Backups

/config is small and irreplaceable: it holds the settings, the bcrypt password hash, the RPC secret, the aria2 session and the download history. Stop the service first so aria2 flushes its session, then archive it:

docker compose stop tidefetch
sudo tar -C /srv/tidefetch -czf "tidefetch-config-$(date +%F).tar.gz" config
docker compose start tidefetch

For a named volume:

docker run --rm \
  -v tidefetch-config:/source:ro \
  -v "$PWD:/backup" \
  alpine tar -C /source -czf /backup/tidefetch-config.tar.gz .

Back up /downloads according to what the files are worth; partial downloads can be recreated. Data and persistence lists every file.

Restore

docker compose down
sudo rm -rf /srv/tidefetch/config/*
sudo tar -C /srv/tidefetch/config -xzf tidefetch-config-2026-01-31.tar.gz --strip-components=1
sudo chown -R 1000:1000 /srv/tidefetch/config
docker compose up -d
docker compose logs tidefetch       # aria2 should report the restored session

Upgrades and rollback

Pin production deployments to a release tag rather than latest, using any tag from the releases page:

image: ghcr.io/thre4dripper/tidefetch:0.1.0
docker compose pull
docker compose up -d
docker image prune -f

Roll back by restoring the previous tag and running docker compose up -d again. The config format is forward-compatible, but take a config backup before crossing a major version.

Health and monitoring

The image's health check requests / every 30 seconds:

docker inspect --format '{{json .State.Health}}' tidefetch
docker stats tidefetch

An external monitor can check https://tidefetch.example.com/. A 200 proves the server is up; the signed-in UI separately shows whether aria2 is connected. Do not poll aggressively: Tidefetch already runs one efficient poll loop against aria2 and fans updates out to every browser.

Tuning

  • Limit concurrent downloads and per-download connections on low-power CPUs (Settings → Transfer).
  • Keep the browser and the Tidefetch server on the same LAN when the aria2 daemon is remote.
  • Raise the container memory limit above 512 MB only for very large queues or heavy torrent metadata.

Platform notes

Unraid. Use the template and follow Unraid. Map /config to an appdata share and /downloads to the download share.

TrueNAS SCALE. Create a custom app with the GHCR image, one replica, port 8210 and two dataset mounts owned by UID/GID 1000. Keep the app on a fixed image tag and store the password in a Kubernetes Secret.

Synology Container Manager. Create a project from the Compose example. Map /config to /volume1/docker/tidefetch and /downloads to a download shared folder. Set ownership from an SSH shell if the UI cannot assign UID 1000.

Proxmox. Run Tidefetch in a small VM or an unprivileged LXC with Docker or Podman. For LXC bind mounts, map container UID 1000 to a writable host UID rather than making the container privileged.

k3s and Kubernetes. One replica on ReadWriteOnce storage; see Kubernetes and k3s. Horizontal replicas are neither needed nor safe against one aria2 session volume.