How to install Jellyfin on a Synology NAS with Container Manager

Updated ยท 5 min read

Your movies are already on the NAS, so running Jellyfin on Synology right next to them makes sense. This guide sets it up with Container Manager on DSM 7.2, with permissions and video conversion done properly from the start.

Check your model first

Jellyfin's own Synology instructions ask for DSM 7.0 or newer and the Container Manager package from Package Center. Container Manager runs on most "plus" and x86 models; some entry-level ARM models don't offer it at all. Open Package Center and search for it: if it isn't there, your model can't run containers.

Then look up your model's processor on Synology's spec page. It decides how well Jellyfin converts video. An Intel Celeron with integrated graphics, such as the J4125 in the DS920+, can use Intel Quick Sync. AMD Ryzen models such as the DS923+ have no integrated graphics, so conversion runs on the processor. That's fine when your devices play files directly, and slow when they don't.

There is also a Jellyfin package from SynoCommunity, a third-party package source you can add to Package Center. It works, but this guide uses Container Manager, which runs Jellyfin's official image and is the route Jellyfin's documentation describes.

Set it up, step by step

  1. Install Container Manager. In Package Center, install Container Manager. It creates a shared folder called docker.
  2. Make Jellyfin's folders. In File Station, create docker/jellyfin, and inside it config and cache. On disk these are /volume1/docker/jellyfin/config and /volume1/docker/jellyfin/cache.
  3. Pick the user Jellyfin runs as. Use a DSM user that can read your media shares and write to docker/jellyfin. Turn on SSH in Control Panel > Terminal & SNMP, sign in, and run id yourname. Note the numbers after uid= and gid=; the first user created on a NAS is often 1026, and the users group is 100.
  4. Create a project. In Container Manager, open Project and click Create. Name it jellyfin, set the path to /docker/jellyfin, choose to create a docker-compose.yml, and paste the file below with your own numbers and share names.
  5. Start it. Finish the wizard. Container Manager downloads the image and starts the container.
  6. Run the first-run wizard. From a computer at home, open http://<NAS address>:8096, create the administrator with a strong password, and add libraries using the paths inside the container, such as /media/movies.
services:
  jellyfin:
    image: jellyfin/jellyfin:latest
    container_name: jellyfin
    user: "1026:100"
    ports:
      - "8096:8096"
    volumes:
      - /volume1/docker/jellyfin/config:/config
      - /volume1/docker/jellyfin/cache:/cache
      - /volume1/video/movies:/media/movies:ro
      - /volume1/video/shows:/media/shows:ro
    restart: unless-stopped

The :ro on the media lines mounts them read-only. Jellyfin can still read and play everything; it just can't change or delete your files. If you want Jellyfin to save artwork next to your media, drop :ro from those lines.

Tip: if the container starts but the libraries are empty, it's nearly always permissions. The user in user: needs read access to the media shares; check it in Control Panel > Shared Folder > Edit > Permissions.

The compose file uses bridge networking with one published port, which is enough for the web page and the apps. Jellyfin's documentation says host networking is needed for DLNA and for finding HDHomeRun tuners automatically. If you need those, replace the ports: lines with network_mode: host.

Intel Quick Sync on Synology

On a model with Intel graphics, check over SSH that the device exists:

ls -ln /dev/dri

If you see renderD128, add these lines to the service, using the group number shown as the owner group of renderD128:

    devices:
      - /dev/dri:/dev/dri
    group_add:
      - "937"

The 937 is only an example: use the number from your own listing. Without the right group, a non-root container can see the device but isn't allowed to use it. If /dev/dri doesn't exist, leave these lines out entirely, or the project won't start. Then in Jellyfin's Dashboard, choose Intel QuickSync (QSV) or VAAPI as the hardware acceleration and tick only the formats your chip handles. Jellyfin hardware transcoding explains how to tell which those are.

Ports 80 and 443 belong to DSM

DSM serves its own pages on ports 80 and 443, so never map anything else to them on the NAS. Jellyfin doesn't need them: it lives on 8096. For watching away from home, the safe options are HTTPS in front of Jellyfin (DSM's reverse proxy can do this, under Login Portal > Advanced), or a private network such as Tailscale. Jellyfin with an HTTPS certificate covers the first.

Careful: don't forward port 8096 from your router to the NAS. It's plain HTTP, so passwords and video would cross the internet unencrypted, straight to a box that also holds your files.

Questions

Can my Synology NAS run Jellyfin?

If Package Center offers Container Manager on your model, yes. Whether it can convert video quickly depends on the processor: Intel models with integrated graphics can use Quick Sync, others convert on the processor.

What user should the Jellyfin container run as on Synology?

A DSM user that can read your media shares and write to the docker/jellyfin folder. Find its numbers with id over SSH and put them in user: in the compose file.

Why is my Jellyfin library empty on Synology?

Usually the container's user can't read the media share, or the library points at a NAS path instead of the path inside the container, such as /media/movies.

The one-click way: Reelhost

Reelhost's Docker edition runs in a container next to Jellyfin and you use it from a browser on port 8099. On Synology, sign in to Reelhost's registry over SSH first, then create a Project with its compose file under /volume1/docker/. Give both containers the same /dev/dri and Reelhost's video speed check turns on VAAPI after testing it. The free key covers the check-up and previews; applying fixes needs Core, and watching away from home needs Complete or Yearly. Because DSM owns 443, for a web address you publish Reelhost's 443 on another port, such as 8443, and forward your router's 443 to it.

The check-up is free and changes nothing. Every fix is previewed, backed up and reversible.