Hello there,
I put together a small Usenet setup with thick containers and would like to have your opinion about what should and shouldn't be behind a VPN to connect to the outside.
Container:
SABnzbd; no VPN, but SSL
Jellyseerr; no VPN
Jellyfin;
Radarr; has VPN
Sonarr; has VPN
Readarr; has VPN
I think most people will tell you that there's no need to use a VPN with Usenet. I personally do not. However, if one was to put any of the containers behind the VPN, I think that SABnzbd would be the one to do it with.
I'm not a Usenet expert so feel free to correct me.
With Usenet there's no real reason to have any of your services behind a VPN unless you're using torrents as a backup method to grab files. Even then, you should only be putting your torrent client behind a VPN.
Here's my basic setup. I have a container that I call dl1. This has qbitorrent, sabnzbd, and a VPN client. This container only accepts connections from my local subnet or connections from the VPN interface. Everything else, *arrs, etc are separate containers that communicate with the dl1 container. Total seperarion and totally secure. I administer everything from tailscale if I'm not on the local net
Unless you're also running a torrent client, you don't really need a VPN at all. The *arrs aren't doing anything that needs to be hidden, and Usenet is fine with just SSL.