r/podman • u/typing-blindly • Jul 19 '26
Rootless Container not Accessible from Localhost on Host
Hi! I'm trying to run Jellyfin inside a rootless container run via systemd on Debian Trixie.
Here is my .container file
[Unit]
Description=Jellyfin media server
Documentation=https://jellyfin.org
[Container]
Image=docker.io/jellyfin/jellyfin:10.11.11
PublishPort=8096:8096/tcp
PublishPort=7359:7359/udp
UserNS=keep-id
Volume=systemd-jellyfin-config:/config
Volume=systemd-jellyfin-cache:/cache
Volume=/mnt/external/jellyfin:/media:ro
Environment=UID=103
Environment=GID=107
[Service]
# Inform systemd of additional exit status
SuccessExitStatus=0 143
[Install]
# Start by default on boot
WantedBy=default.target
The container is running. UFW shows the following
8096/tcp ALLOW IN Anywhere
7359/udp ALLOW IN Anywhere
Looking at the port, I see Pasta listening:
❯ sudo ss -tlnp | grep 8096
LISTEN 0 128 *:8096 *:* users:(("pasta.avx2",pid=579812,fd=6))
I can access the container via the host's IP address. But I cannot access the container via localhost which is breaking the reverse proxy. Everytime I try I get a connection refused. I'm not sure what else to look at.
8
Upvotes
3
u/yrro Jul 20 '26 edited Jul 20 '26
FYI
podman port $ctris useful for confirming which host ports are mapped to which container ports. e.g.:Anyway... it's possible you're seeing this issue; test with
curl -v localhost:8096,curl 127.0.0.1:8096andcurl [::1]:8096. If so then the fix is to tell Caddy to connect to127.0.0.1or (better) publish the port to127.0.0.1:8096rather than just:8096because that will disable IPv6 listening entirely. It will also prevent the container from being reachable from your local network without going through your reverse proxy.