05-riffado.md
kstack: book: Centerpoint Home Lab chapter: AI & Automation page: Riffado tags: [riffado, audio, podcast, ai, media]
Overview
emptyRiffado (formerly known as OpenPlaud) is a self-hosted AI audio and podcast
management application. It handles audio file storage, playback, and AI-assisted
processing within the homelab ecosystem.
Audio files are stored on the Ceph OSD volume (1TB_Vol1) rather than the system
NVMe, keeping large media off the primary drive.
Access
https://riffado.home.local
LAN access via Step-CA TLS
External
https://riffado.jeeves5454.ddns.net
Internet-facing — Authentik SSO + GeoBlock + CrowdSec
Containers in This Stack
riffado
ghcr.io/riffado/riffado:latest
Application server
riffado-db
postgres:16-alpine
PostgreSQL database backend
Configuration
Compose project: ai-stack
Environment Variables
APP_URL
https://riffado.jeeves5454.ddns.net
HOSTNAME
0.0.0.0
DATABASE_URL
postgresql://postgres:**REDACTED**@riffado-db:5432/riffado
DEFAULT_STORAGE_TYPE
local
LOCAL_STORAGE_PATH
/app/storage
DISABLE_REGISTRATION
true
BETTER_AUTH_SECRET
REDACTED
ENCRYPTION_KEY
REDACTED
NODE_ENV
production
DISABLE_REGISTRATION=true prevents new accounts from being created — access is
limited to pre-provisioned users and gated by Authentik on the external route.
Traefik Labels
# External route
traefik.http.routers.riffado-ext.rule: Host(`riffado.jeeves5454.ddns.net`)
traefik.http.routers.riffado-ext.entrypoints: websecure
traefik.http.routers.riffado-ext.tls.certresolver: letsencrypt
traefik.http.routers.riffado-ext.middlewares: authentik-auth@docker,plex-geoblock@file,crowdsec-bouncer@file
traefik.http.routers.riffado-ext.service: riffado-svc
# Internal route
traefik.http.routers.riffado-int.rule: Host(`riffado.home.local`)
traefik.http.routers.riffado-int.entrypoints: websecure
traefik.http.routers.riffado-int.tls.certresolver: step-ca
traefik.http.routers.riffado-int.service: riffado-svc
traefik.http.services.riffado-svc.loadbalancer.server.port: 3000
Volumes / Bind Mounts
/media/jeeves/1TB_Vol1/docker/riffado/audio
/app/storage
Audio file storage (Ceph OSD)
Audio files are stored on the Ceph-managed OSD volume (nvme2n1, mounted at
/media/jeeves/1TB_Vol1). This keeps large audio files off the system NVMe and
on the dedicated storage volume.
Sub-section: PostgreSQL Database
riffado-db is a dedicated Postgres 16-alpine sidecar managing all Riffado
application state: user accounts, playlists, audio metadata, and processing
history. It is not shared with any other service.
/home/jeeves/docker/riffado/db
/var/lib/postgresql/data
PostgreSQL data files
The database container is on the riffado-internal network only — it is never
exposed to traefik-net.
Networks
traefik-net
Exposes the Riffado web UI
riffado-internal
riffado ↔ riffado-db communication
Dependencies
riffado-db (must be healthy before riffado starts)
Authentik for SSO on external route
Ceph OSD volume must be mounted at /media/jeeves/1TB_Vol1 before the container
starts, otherwise the audio storage path is unavailable
Notes / Gotchas
APP_URL must match the externally accessible URL. Changing this after initial
setup requires updating any stored links.
The BETTER_AUTH_SECRET and ENCRYPTION_KEY must remain constant — changing
them invalidates all existing sessions and encrypted data.
Last Updated: 2026-06-16