• 0 posts
  • 1 comment
Joined 8 months ago
Cake day: February 2nd, 2026
  • Just a heads up, their example Docker compose comes with a support for 50 radio stations (with 50+ ports mapped), and it isn’t meant to sit behind a reverse proxy. Below is a simplified Docker compose that I made to run a single radio station.

    services:
      azuracast:
        image: ghcr.io/azuracast/azuracast:latest
        container_name: azuracast
        restart: unless-stopped
        environment:
          AZURACAST_VERSION: latest
          AZURACAST_HTTP_PORT: "80"
          AZURACAST_SFTP_PORT: "2022"
          AZURACAST_STATION_PORTS: "8000,8005,8006"
          AUTO_ASSIGN_PORT_MIN: "8000"
          AUTO_ASSIGN_PORT_MAX: "8006"
          MYSQL_RANDOM_ROOT_PASSWORD: 1
        ports:
          - "4580:80"
          - "4522:2022"
        volumes:
          - /dir-for-db:/var/lib/mysql
          - /dir-for-stations:/var/azuracast/stations
          - /dir-for-storage:/var/azuracast/storage
          - /dir-for-music:/var/azuracast/music
        ulimits:
          nofile:
            soft: 65536
            hard: 65536
        logging:
          driver: json-file
          options:
            max-size: 1m
            max-file: "5"
    

    My nginx routes traffic to port 4580 using the subdomain I assigned for my station, and LetsEncrypt handles SSL. I use SWAG to manage all of that.

    I can’t remember why, but AZURACAST_STATION_PORTS: "8000,8005,8006" is in fact required for a single station. The Azuracast admin portal has an option to consolidate the public player and admin portal behind a single domain, so radio.example.com hits the public player and radio.example.com/login hits the admin login.

    It’s nowhere near the level of pain you have to go through to run Matrix with chat bridges on Docker, but getting all of that right and simplified was more work than I wanted it to be. Hope this helps!

    EDIT: Got carried away sharing my setup and ignored the login requirement for the player. SWAG supports adding an auth layer like Authentik. Or, as the previous commenter mentioned, you could just forego exposing to the outside web entirely and use Tailscale. Or Wireguard.