Set up your Navarre server on a Linux box
A mini PC, an old laptop, a home server - anything with Docker on it. This is the same file the NAS path uses, plus one line in a terminal. The app still writes the recipe, finds the server, and builds your libraries for you.
What you need
- A Linux machine that stays on, with a 64-bit Intel or AMD processor (x86-64; the server does not run on ARM boards such as a Raspberry Pi), and with
dockerand thedocker composeplugin. The plugin matters:docker-composewith a hyphen is the old Python script and is a different program. - A folder of films it can read. It is mounted read-only: this server cannot write to, move, rename, or delete anything in your media, ever.
- An empty folder for the server's own data. Back that one up. It is the only thing here that cannot be rebuilt.
- Any Navarre app to drive it, from the download page.
Paths with a space in them are refused rather than quoted, and the app names the folder to rename.
The setup, start to finish
- Any Navarre appOpen Navarre, choose Set up Navarre, then On a Linux box.
- Any Navarre appTell it where your films live and where the data folder should be - the paths as that machine sees them, like
/srv/media. - Any Navarre appNavarre writes the file and shows it to you with a Copy button. It holds no passwords, and it explains every line it contains.
- Linux boxSave it as
docker-compose.ymlon that machine, then run this in the same folder:docker compose up -d
- Any Navarre appPress I have started it. Navarre finds the new server on your home network by itself: the file uses the machine's own network, which is what makes that work with nothing typed anywhere.
- Any Navarre appChoose your name and password, in the app. It goes straight to your own server over your home network and is never written to a file. Write it down where the rest of your passwords live: there is no admin web page and no password-reset email.
- Any Navarre appNavarre shows you every folder it found, with a proposed library beside it and how many files are in it. Rename one, change what kind it is, or leave it out. Then it builds your libraries and connects the server to your Navarre account, which switches on artwork and details for anything your folders do not already describe.
- TV and phoneOpen Navarre on your other devices. They find the server on the home network by themselves, and you sign in with the name and password from step 6.
What is in the file
You never have to type it. Your own copy will name your folders and your time zone; everything else is the same on every machine:
services:
navarre-server:
# The exact version of Navarre's server this app knows. Never "latest": a
# moving name means your server changes underneath you on a restart you did
# not ask for.
image: "ghcr.io/navarredr/navarre-server:2.0.6"
container_name: "navarre-server"
# Starts again after a crash or a reboot - but stays stopped if you stop it.
restart: "unless-stopped"
# Shares this box's network, which is what lets the Navarre app find this
# server on your home network without you typing an address anywhere.
network_mode: "host"
# The safety block. The server gives up every special permission Linux would
# normally hand it, keeps only the one that lets it READ your films whoever
# owns them, cannot gain more later, and runs with its own filesystem locked
# read-only.
cap_drop: ["ALL"]
cap_add: ["DAC_READ_SEARCH"]
security_opt: ["no-new-privileges:true"]
read_only: true
tmpfs: ["/tmp:rw,noexec,nosuid,size=256m"]
# A ceiling, so this server can never crowd out everything else on the box.
mem_limit: "3g"
memswap_limit: "3g"
# <folder on your box> : <where the server sees it>
# The first one is the server's own data - back it up. Every other one is a
# folder of yours, mounted "ro", which means READ-ONLY.
volumes: ["/srv/navarre-data:/config", "/srv/media:/media:ro"]
environment:
# Leaves the setup window open on a brand-new data folder, so the Navarre
# app can finish the setup for you. It closes for good the moment it does.
NAVARRE_SETUP: "wizard"
# The folders above, so the server knows where to look for your films.
NAVARRE_MEDIA_MOUNTS: "/media"
# Your time zone, so "played last night" means last night.
TZ: "Etc/UTC"
- No user or group ids. There is no PUID and no PGID to work out. The server does not run as you: it keeps exactly one Linux permission, the one that lets it read your files whoever owns them, and it has no write access to your media at all.
- The version is pinned, never
latest. That is how you update and how you go back: see Updating. - Hardware conversion on a Linux host with the right Intel graphics is a per-host step, not a default. Your server says whether it can tell, under Settings → Your server, and prints the one check that proves the machine can do it at all.
Watching away from home, with no PC in the house
The setup has one more step, and it adds a second service to the same file. That helper gives your server its own encrypted web address through your own free Tailscale account - no port forwarding, no reverse proxy, no certificate, and no router change. It is pinned the same way:
navarre-companion:
# The exact version of this part Navarre knows. Never "latest", for the same
# reason the server above is pinned.
image: "ghcr.io/navarredr/navarre-companion:1.1.5"
container_name: "navarre-companion"
It mounts no folder of yours at all, and it keeps none of the extra permissions the server keeps, because unlike the server it never reads your films. Watching away from home is the one-time unlock; everything on your own network is included with the apps.
Keeping it running
- It comes back by itself after a reboot or a crash, and stays down if you stop it on purpose. That is the
restartline. - Its log is
docker compose logs navarre-server, and a rolling copy lives in the data folder underlogs/. - Back up the data folder. Your server can also take a nightly copy of it by itself - Settings → Your server shows whether that is on.
- Choose your container paths once and leave them alone. Every film takes its identity from the path the server sees, so changing the right-hand side of a volume line is what loses a resume position. Moving the drive itself is free: change the left-hand side only.
Stuck anywhere? The Help & FAQ covers the questions people actually hit, and support@navarre.tv reaches a human. Moving in from another server? Moving from Jellyfin brings your people and their watch history with you.