networks: emby_sascha_network: enable_ipv6: false name: emby_sascha_network services: wireguard: image: lscr.io/linuxserver/wireguard:latest container_name: wireguard cap_add: - NET_ADMIN - SYS_MODULE environment: - PUID=1000 - PGID=1000 - TZ=Europe/Berlin - INTERNAL_CONTROL_MODS=true - NETWORK_INTERFACES=eth0 - LOCAL_NETWORK=10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,172.18.0.0/16 volumes: - /app-config/wireguard/:/config - /lib/modules:/lib/modules # Notwendig für WireGuard im Kernel ports: - 0.0.0.0:8096:8096 # SABnzbd Web-UI Port wird hier nach außen gereicht sysctls: - net.ipv4.conf.all.src_valid_mark=1 restart: unless-stopped emby: image: lscr.io/linuxserver/emby:latest container_name: emby volumes: - /app-config/emby:/config - /app-config/emby_backup:/backup - data:/data tmpfs: - /tmp:size=8G,mode=1777 environment: - TZ=Europe/Berlin - PUID=1000 - PGID=1000 - NVIDIA_DRIVER_CAPABILITIES=all - NVIDIA_VISIBLE_DEVICES=all restart: unless-stopped devices: - /dev/nvidia0:/dev/nvidia0 - /dev/nvidiactl:/dev/nvidiactl - /dev/nvidia-uvm:/dev/nvidia-uvm - /dev/nvidia-uvm-tools:/dev/nvidia-uvm-tools - /dev/dri/renderD128:/dev/dri/renderD128 deploy: resources: reservations: devices: - driver: nvidia count: all capabilities: [gpu] ports: - "8096:8096" network_mode: "service:wireguard" volumes: data: name: emby_data driver: local driver_opts: device: :/volume1/nas o: addr=192.168.5.100,nolock,soft,rw type: nfs