Set up your Navarre server on a Linux box

A mini PC, an old laptop, a home server - anything with Docker on it. This is the same file the NAS path uses, plus one line in a terminal. The app still writes the recipe, finds the server, and builds your libraries for you.

Doing this on something else? A NAS is one paste into its Docker app, with no terminal at all. A Windows PC is handled for you by the Windows app.

What you need

Paths with a space in them are refused rather than quoted, and the app names the folder to rename.


The setup, start to finish

  1. Any Navarre appOpen Navarre, choose Set up Navarre, then On a Linux box.
  2. Any Navarre appTell it where your films live and where the data folder should be - the paths as that machine sees them, like /srv/media.
  3. Any Navarre appNavarre writes the file and shows it to you with a Copy button. It holds no passwords, and it explains every line it contains.
  4. Linux boxSave it as docker-compose.yml on that machine, then run this in the same folder:
    docker compose up -d
  5. Any Navarre appPress I have started it. Navarre finds the new server on your home network by itself: the file uses the machine's own network, which is what makes that work with nothing typed anywhere.
  6. Any Navarre appChoose your name and password, in the app. It goes straight to your own server over your home network and is never written to a file. Write it down where the rest of your passwords live: there is no admin web page and no password-reset email.
  7. Any Navarre appNavarre shows you every folder it found, with a proposed library beside it and how many files are in it. Rename one, change what kind it is, or leave it out. Then it builds your libraries and connects the server to your Navarre account, which switches on artwork and details for anything your folders do not already describe.
  8. TV and phoneOpen Navarre on your other devices. They find the server on the home network by themselves, and you sign in with the name and password from step 6.

↑ back to the top


What is in the file

You never have to type it. Your own copy will name your folders and your time zone; everything else is the same on every machine:

services:
  navarre-server:

    # The exact version of Navarre's server this app knows. Never "latest": a
    # moving name means your server changes underneath you on a restart you did
    # not ask for.
    image: "ghcr.io/navarredr/navarre-server:2.0.6"
    container_name: "navarre-server"

    # Starts again after a crash or a reboot - but stays stopped if you stop it.
    restart: "unless-stopped"

    # Shares this box's network, which is what lets the Navarre app find this
    # server on your home network without you typing an address anywhere.
    network_mode: "host"

    # The safety block. The server gives up every special permission Linux would
    # normally hand it, keeps only the one that lets it READ your films whoever
    # owns them, cannot gain more later, and runs with its own filesystem locked
    # read-only.
    cap_drop: ["ALL"]
    cap_add: ["DAC_READ_SEARCH"]
    security_opt: ["no-new-privileges:true"]
    read_only: true
    tmpfs: ["/tmp:rw,noexec,nosuid,size=256m"]

    # A ceiling, so this server can never crowd out everything else on the box.
    mem_limit: "3g"
    memswap_limit: "3g"

    # <folder on your box> : <where the server sees it>
    # The first one is the server's own data - back it up. Every other one is a
    # folder of yours, mounted "ro", which means READ-ONLY.
    volumes: ["/srv/navarre-data:/config", "/srv/media:/media:ro"]

    environment:
      # Leaves the setup window open on a brand-new data folder, so the Navarre
      # app can finish the setup for you. It closes for good the moment it does.
      NAVARRE_SETUP: "wizard"
      # The folders above, so the server knows where to look for your films.
      NAVARRE_MEDIA_MOUNTS: "/media"
      # Your time zone, so "played last night" means last night.
      TZ: "Etc/UTC"

Watching away from home, with no PC in the house

The setup has one more step, and it adds a second service to the same file. That helper gives your server its own encrypted web address through your own free Tailscale account - no port forwarding, no reverse proxy, no certificate, and no router change. It is pinned the same way:

  navarre-companion:

    # The exact version of this part Navarre knows. Never "latest", for the same
    # reason the server above is pinned.
    image: "ghcr.io/navarredr/navarre-companion:1.1.5"
    container_name: "navarre-companion"

It mounts no folder of yours at all, and it keeps none of the extra permissions the server keeps, because unlike the server it never reads your films. Watching away from home is the one-time unlock; everything on your own network is included with the apps.


Keeping it running

Stuck anywhere? The Help & FAQ covers the questions people actually hit, and support@navarre.tv reaches a human. Moving in from another server? Moving from Jellyfin brings your people and their watch history with you.