Homelab
Plex Client Addresses
Telling Plex Who Its Clients Are Behind Envoy Gateway: A Direct LAN Path and the Local Networks Preference as Code
Overview
Plex decides whether a viewer is local or remote from the address at the other end of the connection. Put a reverse proxy in front of it and every viewer becomes the proxy. The whole household then reads as remote, and the LAN Networks list stops meaning anything. This is the second time this server has lost its clients' addresses. The first was Kubernetes translating them behind a LoadBalancer, fixed by pinning traffic to the node running Plex[^1]. The Gateway broke it again by a different mechanism, and a forwarded header does not fix it, because the classification never reads the header.
So this appendix does two things. It gives the LAN door back a direct path to Plex, so household viewers arrive as themselves. And it writes the local-network rule into Plex's own preferences, because an address only counts as local if the server agrees. Tunnel and tailnet viewers keep arriving as cluster addresses, which keeps them remote.
Having trouble? See v2.18.1 for reference.
This article isn't ready yet
Check back soon for the full article.