I installed Sparkbox via the windows installer on Windows 11 machine, after the install was successful it opened on the browser (edge) but keep getting "Hmmm… can't reach this page The connection was reset. Try: Checking the connection Checking the proxy and the firewall ERRCONNECTIONRESET " Tried on Firefox and still does not connect. Any options to try?
14 replies
Majorman747 wrote:
Did a full removal of the program and data, re-installed, still same issue, checked ports/firewall, disabled firewalls, still cannot access Localhost:8443 in Chrome nor Edge.
Majorman747 wrote:
sudo sparkbox upgrade [sudo: authenticate] Password: [INFO] Upgrading SparkBox: v1.6.545 - v1.6.561 [INFO] Your settings, data, and app config are preserved across the upgrade. [OK] Installer signature verified [INFO] Handing off to the installer (upgrade mode)... / | | | | ) \ \| ' \ / | '| |/ / \ / \ \/ / ) | |) | (| | | | <| |) | () < |/| ./ \,|| ||\\/ \//\\ || The easiest, most user-friendly self-hosting stack anywhere. Created by Tom Spark | youtube.com/@TomSparkReviews [SparkBox] Running on Windows (WSL) [SparkBox] Network profile: private (default-route source IP is private/CGNAT: 192.168.0.215) [SparkBox] Data directory (media/photos/books/manga): /opt/sparkbox/data [SparkBox] Freeing host port 53 for Pi-hole (disabling systemd-resolved stub listener) [SparkBox] Something is still listening on port 53 after disabling the systemd-resolved stub. [SparkBox] Pi-hole may fail to start. Find it with: ss -tulpn | grep ':53' [SparkBox] System clock is in sync (1s off Cloudflare's reference) [SparkBox] Detected: Ubuntu 26.04 LTS [SparkBox] Installing system dependencies (detected: debian)... [SparkBox] System dependencies installed (debian). [SparkBox] Docker already installed: Docker version 29.6.2, build dfc4efb [SparkBox] WSL: this Linux machine can no longer wipe Windows-exe interop for your other distros when it stops [SparkBox] Docker Compose: 5.3.1 [SparkBox] Existing SparkBox install found (v1.6.545). Upgrading via atomic rename-swap — .env, state/, and module data are preserved. ============================================================ PREFLIGHT — here's what I found on this machine ============================================================ System: Ubuntu 26.04 LTS Hardware: standard Linux server / VPS Memory: 9706 MB Free disk: 935 GB at /opt Install to: /opt/sparkbox Timezone: Australia/Perth Clock: in sync (1s off reference) Mode: UPGRADE (your settings, data and passwords are kept) ------------------------------------------------------------ ⚠ Port 9000 (Portainer) is already in use by: 0.0.0.0: ⚠ Port 51820 (WireGuard VPN) is already in use by: users:(("docker-proxy",pid=1782,fd=8)) ⚠ Port 51821 (WireGuard web UI) is already in use by: users:(("docker-proxy",pid=1806,fd=8)) These ports are needed by SparkBox. The install will continue, but the affected service may fail to start until the conflict is resolved. For the dashboard specifically, you can pick another port by setting SBDASHBOARDPORT (e.g. SBDASHBOARDPORT=9443) before installing, or in /opt/sparkbox/.env afterwards followed by 'sudo sparkbox up'. ============================================================ [SparkBox] Downloading SparkBox... [SparkBox] Verifying release integrity... [SparkBox] SHA256 digest verified [SparkBox] ed25519 signature verified [SparkBox] Stopping running containers for a safe upgrade snapshot... Container sb-wg-easy Removing Container sb-wg-easy Removed Network sparkboxsbvpn Removing Network sparkboxsbvpn Removed [OK] SparkBox stopped. [SparkBox] Containers still running after 'sparkbox down' — stopping them directly: sb-filebrowser [SparkBox] Upgrade applied atomically. Rollback copy preserved at /opt/sparkbox.rollback-1786870032 until health probe confirms success. [SparkBox] SparkBox downloaded to /opt/sparkbox [SparkBox] SparkBox installed to /opt/sparkbox [SparkBox] Configuring firewall (UFW)... [SparkBox] Opening module ports in UFW (parsed from modules//docker-compose.yml)... [SparkBox] Opened 12 module ports in UFW [SparkBox] Firewall configured: SSH (22), HTTP (80), HTTPS (443), Dashboard (8443), WireGuard (51820/udp, 51821/tcp), 12 module ports [SparkBox] Setting UFW forward policy to ACCEPT (container egress)... [SparkBox] UFW forward policy set to ACCEPT (required for container egress) [SparkBox] Verifying container egress to license server (real sbproxy network)... [SparkBox] Container egress check failed — sbproxy cannot reach webhook.tomsparkbox.com. [SparkBox] Every bundled app (Jellyfin, Pi-hole, Vaultwarden, Nextcloud, etc.) [SparkBox] runs the same either way. Two things WON'T work until this is fixed: [SparkBox] - the dashboard's one-click Update (it downloads from inside a [SparkBox] container, so it fails on 'Could not resolve host'). Until then, [SparkBox] update over SSH instead — that runs on the host: sudo sparkbox upgrade [SparkBox] - optional Pro-tier license activation. [SparkBox] To fix container egress, common causes (in rough order of likelihood): [SparkBox] 1. UFW forwarding policy: grep DEFAULTFORWARDPOLICY /etc/default/ufw (should be ACCEPT) [SparkBox] 2. Run: sudo sparkbox repair-network [SparkBox] 3. If you have a custom /etc/docker/daemon.json, check its DNS settings. [SparkBox] (Only consider removing it if you didn't put it there yourself.) [SparkBox] 4. From inside dashboard: sudo docker exec sb-dashboard node -e "require('dns').lookup('webhook.tomsparkbox.com',(e,a)=console.log(e?e.code:a))" [SparkBox] iptablenat module persisted for boot (wg-easy support) [SparkBox] SSH: /etc/ssh/sshdconfig not found — skipping SSH hardening (no sshd installed) [SparkBox] fail2ban: SSH brute-force protection enabled [SparkBox] Non-interactive install detected (piped from curl). Skipping wizard. [SparkBox] Bringing up core services so the dashboard is reachable... [SparkBox] Keeping existing .env from previous install. [SparkBox] Rendering module templates... [SparkBox] Pi-hole pre-configured with NAS telemetry blocklist [SparkBox] Gotify admin password pre-seeded (plaintext saved to state/gotify-admin-password.txt) [SparkBox] FileBrowser admin password pre-seeded (applied by the container at first boot) [SparkBox] qBittorrent admin password pre-seeded (plaintext saved to state/qbittorrent-admin-password.txt) [SparkBox] qBittorrent: rewrote broken quoted @ByteArray hash in existing conf to unquoted form. [SparkBox] Boot self-heal enabled (sparkbox-boot.service runs 'sparkbox up' after every reboot) [SparkBox] Downloading and starting all apps — this is the longest step and can take 10-30+ minutes on slower connections. [SparkBox] Detailed progress is written to /tmp/tmp.uXwWAcS43q — follow it live from another terminal with: tail -f /tmp/tmp.uXwWAcS43q [SparkBox] Still working — downloading/starting apps (2 min elapsed). Not frozen; live log: tail -f /tmp/tmp.uXwWAcS43q [SparkBox] Still working — downloading/starting apps (4 min elapsed). Not frozen; live log: tail -f /tmp/tmp.uXwWAcS43q [SparkBox] Still working — downloading/starting apps (6 min elapsed). Not frozen; live log: tail -f /tmp/tmp.uXwWAcS43q [SparkBox] Still working — downloading/starting apps (8 min elapsed). Not frozen; live log: tail -f /tmp/tmp.uXwWAcS43q [SparkBox] Core services didn't start (attempt 1/3) — likely a transient Docker hiccup. Waiting 10s and retrying... [SparkBox] Still working — downloading/starting apps (10 min elapsed). Not frozen; live log: tail -f /tmp/tmp.uXwWAcS43q [SparkBox] Still working — downloading/starting apps (12 min elapsed). Not frozen; live log: tail -f /tmp/tmp.uXwWAcS43q [SparkBox] Core services didn't start (attempt 2/3) — likely a transient Docker hiccup. Waiting 10s and retrying... [SparkBox] Still working — downloading/starting apps (14 min elapsed). Not frozen; live log: tail -f /tmp/tmp.uXwWAcS43q [SparkBox] Still working — downloading/starting apps (16 min elapsed). Not frozen; live log: tail -f /tmp/tmp.uXwWAcS43q [SparkBox] Still working — downloading/starting apps (18 min elapsed). Not frozen; live log: tail -f /tmp/tmp.uXwWAcS43q [FAILURE] SparkBox installed, but Docker couldn't start the core services. [FAILURE] The most common causes are port conflicts (8443 already taken), missing /var/run/docker.sock permissions, or low disk space. [FAILURE] Last 20 lines of the sparkbox up log: Container sb-notifiarr Started Container sb-jellyfin-media Started Container sb-gluetun Started Container sb-gluetun Waiting Container sb-gluetun Waiting Container sb-gluetun Waiting Container sb-gluetun Waiting Container sb-gluetun Waiting Container sb-gluetun Waiting Container sb-gluetun Error dependency gluetun failed to start Container sb-gluetun Error dependency gluetun failed to start Container sb-gluetun Error dependency gluetun failed to start Container sb-gluetun Error dependency gluetun failed to start Container sb-gluetun Error dependency gluetun failed to start Container sb-gluetun Error dependency gluetun failed to start dependency failed to start: container sb-gluetun is unhealthy Container sb-tailscale Running Container sb-wg-easy Running [WARN] Some apps were created but never started (a dependency — usually the VPN tunnel — wasn't healthy in time). Starting them now: [OK] started byparr [FAILURE] Exact command that aborted (from the ERR trap): 2026-08-16T17:02:32+08:00 rc=1 line=14657 cmd=return ${uprc} 2026-08-16T17:02:43+08:00 rc=1 line=4283 cmd=awk '{print $2, $3}' 2026-08-16T17:08:04+08:00 rc=1 line=14657 cmd=return ${uprc} [FAILURE] Full log preserved at: /opt/sparkbox/state/install-failure-1786871284.log [FAILURE] Next steps: [FAILURE] 1. Run: /opt/sparkbox/sparkbox doctor (finds common causes automatically) [FAILURE] 2. Fix what it reports, then run: /opt/sparkbox/sparkbox up [FAILURE] 3. If you're still stuck, email support@tomsparkbox.com and attach /opt/sparkbox/state/install-failure-1786871284.log :~$ /opt/sparkbox/sparkbox doctor
Majorman747 wrote:
SparkBox Doctor Running diagnostics... [Install location] [OK] SparkBox is installed at: /opt/sparkbox [OK] Settings file (.env): /opt/sparkbox/.env [OK] Media library folder (MEDIAROOT): /opt/sparkbox/data/media [WARN] Listed more than once in .env: VPNDOT WIREGUARDMTU Only the LAST line for each of those is used, so an edit higher up the file does nothing. Collapse each one to a single line with: sudo sparkbox set-env VPNDOT <the value you want sudo sparkbox set-env WIREGUARDMTU <the value you want [Docker] [OK] Docker daemon is accessible [OK] Docker version: Docker version 29.6.2, build dfc4efb [OK] Docker Compose: 5.3.1 [Docker Socket] [OK] Docker socket exists at /var/run/docker.sock [OK] Docker socket is readable [User IDs] [INFO] Current user: dlheunis (UID=1000, GID=1000) [OK] PUID=1000 (containers run as UID 1000) [OK] PGID=1000 (containers run as GID 1000) [Container Egress] [WARN] The apps' network (sbproxy) cannot reach tomsparkbox.com. This is the network every SparkBox app runs on, including the reverse proxy — so anything that fetches from the internet (certificates, metadata, indexers, updates) will fail. It also stops the reverse proxy (sb-npm) finishing its startup: NPM downloads an IP-range list from Amazon the moment it boots, and with no way out that download never answers, so it waits there forever. The container stays 'Up (unhealthy)' and its log ends mid-line at 'Fetching IP Ranges from online services'. Nothing is wrong with NPM; fix egress below and it finishes booting. To fix container egress: 1. UFW: grep DEFAULTFORWARDPOLICY /etc/default/ufw (should be ACCEPT) 2. Run: sudo sparkbox repair-network (re-tests egress itself; exits without touching your apps if the network is not the problem) 3. If you have a custom /etc/docker/daemon.json, check its DNS settings. Re-run 'sparkbox doctor' to verify. [OK] Docker's default bridge can reach tomsparkbox.com (dashboard Update button) [Port Conflicts] [WARN] Port 80: in use by another program on this box (not SparkBox) LISTEN 0 4096 0.0.0.0:80 0.0.0.0: Affects: Nginx Proxy Manager (custom domains + HTTPS) — custom domains and automatic HTTPS stop working (apps opened by IP:port still work). Fix: move Nginx Proxy Manager (custom domains + HTTPS) to a free port (nothing is lost, it just answers somewhere else) — Dashboard → Settings → Ports → 'HTTP Port', then Save; or on the server: sudo sparkbox set-env HTTPPORT <a free port sudo sparkbox up Or leave it: the rest of SparkBox is unaffected by this one port. [WARN] Port 443: in use by another program on this box (not SparkBox) LISTEN 0 4096 0.0.0.0:443 0.0.0.0: Affects: Nginx Proxy Manager (custom domains + HTTPS) — the https:// address for your apps will not answer. Fix: move Nginx Proxy Manager (custom domains + HTTPS) to a free port (nothing is lost, it just answers somewhere else) — Dashboard → Settings → Ports → 'HTTPS Port', then Save; or on the server: sudo sparkbox set-env HTTPSPORT <a free port sudo sparkbox up Or leave it: the rest of SparkBox is unaffected by this one port. [OK] Port 8443 (the SparkBox dashboard itself): available [OK] Port 9001: in use by SparkBox (sb-portainer) [Portainer Auth] [ERROR] sb-portainer IS listening on 127.0.0.1:9001, but the connection timed out instead of connecting — that's Windows/WSL2's 'mirrored' networking mode blackholing loopback traffic, not a Portainer problem The tell: a genuinely closed port refuses instantly; this one hangs for several seconds because a Hyper-V firewall rule (or the mirrored-loopback bug itself) is silently dropping the connection instead of rejecting it. This blocks every app on this box the same way, not just Portainer — the dashboard and qBittorrent too. Fix from an administrator PowerShell: Set-NetFirewallHyperVVMSetting -Name '{40E0AC32-46A5-438A-A0B2-2B479E8F2E90}' -DefaultInboundAction Allow wsl --shutdown Still blocked? Switch back to NAT mode in %UserProfile%\.wslconfig: [wsl2] networkingMode=nat then run 'wsl --shutdown' from PowerShell and reopen your WSL distro. Full walkthrough: https://tomsparkbox.com/guides/run-sparkbox-on-windows-wsl [VPN Tunnel] [ERROR] Gluetun is unhealthy — VPN tunnel is not established Your VPN connects, but nothing inside the tunnel can look up an address, so its own health check times out and it restarts. Encrypted DNS is on by default and some VPN servers block it. That costs one setting to rule out, so try it first: sudo sparkbox set-env VPNDOT off sudo sparkbox restart media If that changes nothing, the tunnel isn't carrying traffic at all — re-check your VPN key and address, and on WireGuard try: sudo sparkbox set-env WIREGUARDMTU 1280 then 1220 Common fixes: - WIREGUARDPRIVATEKEY must be YOUR client private key (not the server PublicKey) - WIREGUARDADDRESSES needs CIDR form, e.g. 10.2.0.2/32 - SERVERCITIES must match a city in gluetun's list for your provider (leave blank to let gluetun pick) - Multi-value lists (SERVERCITIES/SERVERCOUNTRIES) take NO space after the comma: SERVERCITIES=Zurich,Singapore (not: Zurich, Singapore) Edit: sudo nano /opt/sparkbox/.env → fix offending line → sudo sparkbox restart media [Hardware Transcoding] [WARN] Hardware Transcoding is set to 'auto' but this host has NO /dev/dri -- there is no GPU for SparkBox to pass through, so everything transcodes in software This is a HOST setting, not a SparkBox one. On a generic Debian/Ubuntu install the Intel driver may not be loaded: lsmod | grep -c i915 0 means the driver is not loaded sudo apt install firmware-misc-nonfree intel-media-va-driver-non-free sudo modprobe i915 && ls -l /dev/dri On a NAS, enable GPU passthrough for Docker in the NAS settings. If this box genuinely has no usable GPU, set Hardware Transcoding to 'none' in Settings so the dashboard stops implying it is active. [OK] Nvidia GPU detected (driver responding) [WARN] Nvidia GPU present but Docker's nvidia runtime is NOT registered -- JELLYFINHWACCEL=nvidia would fall back to software transcoding Fix: install nvidia-container-toolkit, then: sudo nvidia-ctk runtime configure --runtime=docker && sudo systemctl restart docker [Media Storage] [OK] MEDIAROOT=/opt/sparkbox/data/media exists [OK] MEDIAROOT is writable [WARN] Your apps (user id 1000) can't READ what's in MEDIAROOT — common with media already on a UGREEN/UGOS NAS. [WARN] Fix (read access without taking ownership): [WARN] sudo setfacl -R -m u:1000:rX -d -m u:1000:rX '/opt/sparkbox/data/media' [WARN] (This grants access via ACLs: it survives UGOS's periodic permission [WARN] resets and doesn't change who owns your files.) [WARN] Guide: https://tomsparkbox.com/guides/use-existing-ugreen-media.html [INFO] Free space at MEDIAROOT: 935GB [System Resources] [INFO] Total RAM: 9706MB [INFO] Available RAM: 6750MB [OK] RAM looks sufficient for 5 enabled modules [INFO] Free disk at SBROOT: 935GB [Container Health] [OK] All SparkBox containers are running and passing their health checks [Tailscale Inbound Path] [WARN] Tailscale connects, but its inbound path CANNOT reach this box's apps — from a phone everything will look 'connected' and still refuse. Tailscale delivers each incoming connection by dialing 127.0.0.1:<port from where it runs, and that dial is failing. On Docker Desktop (Windows/Mac) this is the architecture: the container lives in a VM away from your apps — run SparkBox in WSL2 with native Docker instead (guide: https://tomsparkbox.com/guides/run-sparkbox-on-windows-wsl). Otherwise check the dashboard is actually listening: curl -k https://127.0.0.1:8443 [Tailscale Reachability] [INFO] Dashboard not answering on 127.0.0.1:8443 — route-shadow check not applicable (see container health above) [Windows (WSL) Networking] [OK] Running on Windows (WSL) with 192.168.0.215 — a real home-network address, so other devices can reach this box ============================================ 9 issue(s) found. Review warnings above and fix as needed. ============================================ dlheunis@DESKTOP-2QT1OT9:~$ sudo setfacl -R -m u:1000:rX -d -m u:1000:rX '/opt/sparkbox/data/media' [sudo: authenticate] Password: dlheunis@DESKTOP-2QT1OT9:~$ sudo sparkbox repair-network [INFO] Rebuilding SparkBox network and containers... [INFO] Removing sbproxy network... [INFO] Creating sbproxy network (172.20.0.0/24)...
Majorman747 wrote:
[INFO] Starting SparkBox... [INFO] Active modules: core dashboard media tailscale vpn [INFO] Prepared 2 module config dir(s) for PUID=1000 PGID=1000 [INFO] .env changed since last up — recreating the affected containers to pick up new values [INFO] Tailscale is on — allowing the tailnet range (100.64.0.0/10) back out of the VPN tunnel so the apps behind it answer remotely. [INFO] core: configuration changed — recreating its containers [+] up 1/3 ✔ Container sb-portainer Started 1.7s ⠏ Container sb-npm Starting 1.9s ⠏ Container sb-homepage Starting 1.9s Error response from daemon: failed to set up container networking: driver failed programming external connectivity on endpoint sb-homepage (4a4c0d0ff47febb7b9758b842e7b4debd025826c8cf7ba83e43cbd4362c4909e): failed to bind host port 0.0.0.0:3000/tcp: address already in use [+] up 0/1 ⠦ Container sb-dashboard Starting 0.6s Error response from daemon: failed to set up container networking: driver failed programming external connectivity on endpoint sb-dashboard (3cd445278d963a52218568c2a10272912df458a8bd4657ecc730d3e2cf614910): failed to bind host port 0.0.0.0:8443/tcp: address already in use [INFO] media: configuration changed — recreating its containers [+] up 14/14 ✔ Network sparkboxsbmedia Created 0.3s ✔ Network sparkboxsbmediainternal Created 0.3s ✔ Container sb-bazarr Started 5.7s ✔ Container sb-notifiarr Started 4.4s ✔ Container sb-seerr Started 5.6s ✘ Container sb-gluetun Error dependency gluetun failed to start 292.4s ✔ Container sb-jellyfin-media Started 3.9s ✔ Container sb-deunhealth Started 0.4s ✔ Container sb-sonarr Created 0.1s ✔ Container sb-qbittorrent Created 0.1s ✔ Container sb-byparr Created 0.1s ✔ Container sb-sabnzbd Created 0.1s ✔ Container sb-prowlarr Created 0.1s ✔ Container sb-radarr Created 0.1s dependency failed to start: container sb-gluetun is unhealthy [+] up 1/1 ✔ Container sb-tailscale Started 0.2s [+] up 2/2 ✔ Network sparkboxsbvpn Created 0.6s ✔ Container sb-wg-easy Started 3.9s [WARN] Dashboard couldn't claim port 8443 (stale reservation after an update) — clearing it and retrying... [INFO] core: configuration changed — recreating its containers [+] up 1/3 ⠸ Container sb-homepage Starting 2.8s ✔ Container sb-portainer Started 2.8s ⠼ Container sb-npm Starting 2.8s Error response from daemon: failed to set up container networking: driver failed programming external connectivity on endpoint sb-homepage (0a44ac273349c20f1ffafc109ea07ac3290f05e6ad134734e8acaf000bbfea2f): failed to bind host port 0.0.0.0:3000/tcp: address already in use [+] up 0/1 ⠙ Container sb-dashboard Starting 1.0s Error response from daemon: failed to set up container networking: driver failed programming external connectivity on endpoint sb-dashboard (5643330da23789a882ef4f6df40fe03b9870834752c20b79cf6a569646306068): failed to bind host port 0.0.0.0:8443/tcp: address already in use [INFO] media: configuration changed — recreating its containers [+] up 11/12 ✔ Container sb-bazarr Started 13.8s ✔ Container sb-jellyfin-media Started 13.8s ✔ Container sb-deunhealth Started 6.9s ✔ Container sb-seerr Started 13.8s ⠧ Container sb-gluetun Waiting 53.9s ✔ Container sb-notifiarr Started 13.3s ✔ Container sb-byparr Recreated 0.1s ✔ Container sb-sonarr Recreated 0.2s ✔ Container sb-radarr Recreated
Chris wrote:
Hey Majorman747 — I'm sorry this sat unanswered. The upgrade and the up output you pasted are good signs: the containers are starting. First, the classic Windows catch: SparkBox runs inside WSL, and Windows shuts that Linux side down about a minute after the last terminal closes — taking the dashboard with it, which reads as ERRCONNECTIONRESET. The installer adds a start-with-Windows task to hold it open; if that didn't land, the box sleeps whenever the window closes. Open the SparkBox terminal, run sudo sparkbox status, and paste the Container Status table (look for sb-dashboard). With that window still open, try http://localhost:8443 again. If it shows running but the browser still resets, I'll flag it to Tom.
Majorman747 wrote:
SparkBox v1.6.561 - Self-Hosted Privacy Stack Created by Tom Spark | youtube.com/@TomSparkReviews Network profile: private Module Status: ○ adguard (disabled) - AdGuard Home ○ audiobookshelf (disabled) - Audiobookshelf ○ authelia (disabled) - Authelia ○ backup (disabled) - Backups ○ bookstack (disabled) - BookStack ○ budget (disabled) - Actual Budget ○ changedetection (disabled) - Changedetection.io ○ cloud (disabled) - Cloud Storage ○ coolercontrol (disabled) - CoolerControl ● core (enabled) - Core Infrastructure ● dashboard (enabled) - TomSparkBox Dashboard ○ ebooks (disabled) - Ebooks & Comics ○ emby (disabled) - Emby ○ ersatztv (disabled) - ErsatzTV ○ files (disabled) - File Browser ○ freshrss (disabled) - FreshRSS ○ frigate (disabled) - Frigate NVR ○ games (disabled) - Game Servers ○ ghost (disabled) - Ghost ○ gitea (disabled) - Gitea ○ gotify (disabled) - Gotify ○ hearth (disabled) - Hearth Chat ○ homarr (disabled) - Homarr ○ homeassistant (disabled) - Home Assistant ○ immich (disabled) - Immich ○ jellyfin (disabled) - Jellyfin ○ jellystat (disabled) - Jellystat ○ linkding (disabled) - Linkding ○ localai (disabled) - Local AI ○ matrix (disabled) - Matrix Chat ○ mealie (disabled) - Mealie ● media (enabled) - Media Center ○ metrics (disabled) - Metrics & Dashboards ○ monitoring (disabled) - Monitoring ○ n8n (disabled) - n8n ○ navidrome (disabled) - Navidrome ○ paperless (disabled) - Paperless-ngx ○ photoprism (disabled) - PhotoPrism ○ pihole (disabled) - Pi-hole ○ pinchflat (disabled) - Pinchflat ○ plex (disabled) - Plex ○ searxng (disabled) - SearXNG ○ speedtest (disabled) - Speedtest Tracker ○ stablediffusion (disabled) - Stable Diffusion ○ stirling-pdf (disabled) - Stirling PDF ○ syncthing (disabled) - Syncthing ● tailscale (enabled) - Tailscale ○ tdarr (disabled) - Tdarr ○ tunarr (disabled) - Tunarr ○ unpackerr (disabled) - Unpackerr ○ vaultwarden (disabled) - Vaultwarden ● vpn (enabled) - Remote Access VPN ○ webapp (disabled) - Web App ○ wordpress (disabled) - WordPress Container Status: NAMES STATUS PORTS f979a7f64409sb-sonarr Created dd9175bc5a11sb-radarr Created 0160c60694d8sb-prowlarr Created 638b8a4725eesb-byparr Created sb-jellyfin-media Created d32f2da02c2dsb-bazarr Created sb-seerr Created sb-notifiarr Created sb-deunhealth Created sb-gluetun Created sb-npm Created sb-portainer Up 8 seconds 8000/tcp, 9443/tcp, 0.0.0.0:9001-9000/tcp, [::]:9001-9000/tcp sb-homepage Created sb-sabnzbd Up 19 seconds (healthy) sb-qbittorrent Up 19 seconds (healthy) sb-sonarr Up 19 seconds (healthy) sb-radarr Up 19 seconds (healthy) sb-prowlarr Up 19 seconds (healthy) sb-byparr Up 19 seconds (health: starting) sb-bazarr Up 34 seconds (health: starting) 0.0.0.0:6767-6767/tcp, [::]:6767-6767/tcp sb-dashboard Up 34 seconds (healthy) sb-wg-easy Up 34 seconds (health: starting) 0.0.0.0:51820-51820/udp, [::]:51820-51820/udp, 0.0.0.0:51821-51821/tcp, [::]:51821-51821/tcp sb-tailscale Up 34 seconds (healthy) sb-filebrowser Exited (128) 29 hours ago [WARN] These apps are NOT running: bbcdf76ec81dsb-qbittorrent 3f2b138388adsb-sabnzbd f979a7f64409sb-sonarr dd9175bc5a11sb-radarr 0160c60694d8sb-prowlarr 638b8a4725eesb-byparr jellyfin-media d32f2da02c2dsb-bazarr seerr notifiarr deunhealth gluetun npm homepage byparr filebrowser [WARN] Bring them back: sudo sparkbox up [WARN] Still down after that: sudo sparkbox doctor dlheunis@DESKTOP-2QT1OT9:~$ sudo sparkbox up [ERROR] Another SparkBox task (pid 4042) is still running (started 79s ago). [ERROR] Wait for it to finish. If the process is actually gone, delete the lock: rm /opt/sparkbox/state/operation.lock dlheunis@DESKTOP-2QT1OT9:~$ sudo sparkbox up [ERROR] Another SparkBox task (pid 4042) is still running (started 94s ago). [ERROR] Wait for it to finish. If the process is actually gone, delete the lock: rm /opt/sparkbox/state/operation.lock dlheunis@DESKTOP-2QT1OT9:~$ sudo sparkbox doctor
Majorman747 wrote:
parkBox v1.6.561 - Self-Hosted Privacy Stack Created by Tom Spark | youtube.com/@TomSparkReviews Network profile: private SparkBox Doctor Running diagnostics... [Install location] [OK] SparkBox is installed at: /opt/sparkbox [OK] Settings file (.env): /opt/sparkbox/.env [OK] Media library folder (MEDIAROOT): /opt/sparkbox/data/media [WARN] Listed more than once in .env: VPNDOT WIREGUARDMTU Only the LAST line for each of those is used, so an edit higher up the file does nothing. Collapse each one to a single line with: sudo sparkbox set-env VPNDOT <the value you want sudo sparkbox set-env WIREGUARDMTU <the value you want [Docker] [OK] Docker daemon is accessible [OK] Docker version: Docker version 29.6.2, build dfc4efb [OK] Docker Compose: 5.3.1 [Docker Socket] [OK] Docker socket exists at /var/run/docker.sock [OK] Docker socket is readable [User IDs] [INFO] Current user: root (UID=0, GID=0) [OK] PUID=1000 (containers run as UID 1000) [OK] PGID=1000 (containers run as GID 1000) [Container Egress] [WARN] The apps' network (sbproxy) cannot reach tomsparkbox.com. This is the network every SparkBox app runs on, including the reverse proxy — so anything that fetches from the internet (certificates, metadata, indexers, updates) will fail. It also stops the reverse proxy (sb-npm) finishing its startup: NPM downloads an IP-range list from Amazon the moment it boots, and with no way out that download never answers, so it waits there forever. The container stays 'Up (unhealthy)' and its log ends mid-line at 'Fetching IP Ranges from online services'. Nothing is wrong with NPM; fix egress below and it finishes booting. To fix container egress: 1. UFW: grep DEFAULTFORWARDPOLICY /etc/default/ufw (should be ACCEPT) 2. Run: sudo sparkbox repair-network (re-tests egress itself; exits without touching your apps if the network is not the problem) 3. If you have a custom /etc/docker/daemon.json, check its DNS settings. Re-run 'sparkbox doctor' to verify. [OK] Docker's default bridge can reach tomsparkbox.com (dashboard Update button) [Port Conflicts] [WARN] Port 80: in use by another program on this box (not SparkBox) LISTEN 0 4096 0.0.0.0:80 0.0.0.0: Affects: Nginx Proxy Manager (custom domains + HTTPS) — custom domains and automatic HTTPS stop working (apps opened by IP:port still work). Fix: move Nginx Proxy Manager (custom domains + HTTPS) to a free port (nothing is lost, it just answers somewhere else) — Dashboard → Settings → Ports → 'HTTP Port', then Save; or on the server: sudo sparkbox set-env HTTPPORT <a free port sudo sparkbox up Or leave it: the rest of SparkBox is unaffected by this one port. [WARN] Port 443: in use by another program on this box (not SparkBox) LISTEN 0 4096 0.0.0.0:443 0.0.0.0: Affects: Nginx Proxy Manager (custom domains + HTTPS) — the https:// address for your apps will not answer. Fix: move Nginx Proxy Manager (custom domains + HTTPS) to a free port (nothing is lost, it just answers somewhere else) — Dashboard → Settings → Ports → 'HTTPS Port', then Save; or on the server: sudo sparkbox set-env HTTPSPORT <a free port sudo sparkbox up Or leave it: the rest of SparkBox is unaffected by this one port. [OK] Port 8443 (the SparkBox dashboard itself): available [OK] Port 9001: in use by SparkBox (sb-portainer) [Portainer Auth] [ERROR] sb-portainer IS listening on 127.0.0.1:9001, but the connection timed out instead of connecting — that's Windows/WSL2's 'mirrored' networking mode blackholing loopback traffic, not a Portainer problem The tell: a genuinely closed port refuses instantly; this one hangs for several seconds because a Hyper-V firewall rule (or the mirrored-loopback bug itself) is silently dropping the connection instead of rejecting it. This blocks every app on this box the same way, not just Portainer — the dashboard and qBittorrent too. Fix from an administrator PowerShell: Set-NetFirewallHyperVVMSetting -Name '{40E0AC32-46A5-438A-A0B2-2B479E8F2E90}' -DefaultInboundAction Allow wsl --shutdown Still blocked? Switch back to NAT mode in %UserProfile%\.wslconfig: [wsl2] networkingMode=nat then run 'wsl --shutdown' from PowerShell and reopen your WSL distro. Full walkthrough: https://tomsparkbox.com/guides/run-sparkbox-on-windows-wsl [VPN Tunnel] [WARN] Gluetun is still starting — re-run doctor in 30s if media stack hasn't come up [Hardware Transcoding] [WARN] Hardware Transcoding is set to 'auto' but this host has NO /dev/dri -- there is no GPU for SparkBox to pass through, so everything transcodes in software This is a HOST setting, not a SparkBox one. On a generic Debian/Ubuntu install the Intel driver may not be loaded: lsmod | grep -c i915 0 means the driver is not loaded sudo apt install firmware-misc-nonfree intel-media-va-driver-non-free sudo modprobe i915 && ls -l /dev/dri On a NAS, enable GPU passthrough for Docker in the NAS settings. If this box genuinely has no usable GPU, set Hardware Transcoding to 'none' in Settings so the dashboard stops implying it is active. [Media Storage] [OK] MEDIAROOT=/opt/sparkbox/data/media exists [OK] MEDIAROOT is writable [OK] Your apps (user id 1000) can read your media library [INFO] Free space at MEDIAROOT: 935GB [System Resources] [INFO] Total RAM: 9706MB [INFO] Available RAM: 6683MB [OK] RAM looks sufficient for 5 enabled modules [INFO] Free disk at SBROOT: 935GB [Container Health] [ERROR] sb-filebrowser crashed (exit code 128) Try: sudo sparkbox up (and 'sparkbox logs <name' to see why a container is unhappy) [Tailscale Inbound Path] [WARN] Tailscale connects, but its inbound path CANNOT reach this box's apps — from a phone everything will look 'connected' and still refuse. Tailscale delivers each incoming connection by dialing 127.0.0.1:<port from where it runs, and that dial is failing. On Docker Desktop (Windows/Mac) this is the architecture: the container lives in a VM away from your apps — run SparkBox in WSL2 with native Docker instead (guide: https://tomsparkbox.com/guides/run-sparkbox-on-windows-wsl). Otherwise check the dashboard is actually listening: curl -k https://127.0.0.1:8443 [Tailscale Reachability] [INFO] Dashboard not answering on 127.0.0.1:8443 — route-shadow check not applicable (see container health above) [Windows (WSL) Networking] [OK] Running on Windows (WSL) with 169.254.83.107 — a real home-network address, so other devices can reach this box ============================================ 7 issue(s) found. Review warnings above and fix as needed. ============================================
Chris wrote:
Your doctor run already found it — scroll up to the [Portainer Auth] ERROR in that same output. It says Windows/WSL2's 'mirrored' networking mode is silently blackholing loopback traffic, which blocks every app on the box, the dashboard included. That's the ERRCONNECTIONRESET you've been fighting, and nothing is wrong with SparkBox itself. The fix is printed right there. In an administrator PowerShell, run: Set-NetFirewallHyperVVMSetting -Name '{40E0AC32-46A5-438A-A0B2-2B479E8F2E90}' -DefaultInboundAction Allow wsl --shutdown Then reopen Ubuntu, run sudo sparkbox up, and try http://localhost:8443 again. If it still resets, reply and I'll walk you through switching WSL back to NAT mode.
Majorman747 wrote:
" / | | | | ) \ \| ' \ / | '| |/ / \ / \ \/ / ) | |) | (| | | | <| |) | () < |/| ./ \,|| ||\\/ \//\\ || SparkBox v1.6.561 - Self-Hosted Privacy Stack Created by Tom Spark | youtube.com/@TomSparkReviews Network profile: private [INFO] Starting SparkBox... [INFO] Active modules: core dashboard media tailscale vpn [INFO] Prepared 2 module config dir(s) for PUID=1000 PGID=1000 [OK] Tailscale: clamped forwarded TCP MSS to tunnel PMTU (fixes remote-stream freeze). [INFO] Tailscale is on — allowing the tailnet range (100.64.0.0/10) back out of the VPN tunnel so the apps behind it answer remotely. [+] up 3/3 ✔ Container sb-homepage Running 0.0s ✔ Container sb-npm Running 0.0s ✔ Container sb-portainer Running 0.0s [+] up 12/12 ✔ Container sb-radarr Running 0.0s ✔ Container sb-byparr Running 0.0s ✔ Container sb-seerr Running 0.0s ✔ Container sb-jellyfin-media Running 0.0s ✔ Container sb-bazarr Running 0.0s ✔ Container sb-notifiarr Running 0.0s ✔ Container sb-deunhealth Running 0.0s ✔ Container sb-prowlarr Running 0.0s ✔ Container sb-sabnzbd Running 0.0s ✔ Container sb-qbittorrent Running 0.0s ✔ Container sb-gluetun Healthy 3.1s ✔ Container sb-sonarr Running 0.0s [+] up 1/1 ✔ Container sb-tailscale Running 0.0s [+] up 1/1 ✔ Container sb-wg-easy Running 0.0s [OK] SparkBox is running! [qbit-seed-limits] couldn't sign in to qBittorrent — skipping for now (retries on the next 'sparkbox up'; 'sudo sparkbox reset-password qbit' if it persists). [INFO] Checking the media apps' wiring in the background (re-links qBittorrent/Prowlarr if it broke)... Service URLs: Core Infrastructure: Nginx Proxy Manager: http://192.168.0.215:81 Portainer: http://192.168.0.215:9000 Homepage: http://192.168.0.215:3000 TomSparkBox Dashboard: TomSparkBox Dashboard: http://192.168.0.215:8443 Media Center: qBittorrent: http://192.168.0.215:8089 Prowlarr: http://192.168.0.215:8181 Sonarr: http://192.168.0.215:8989 Radarr: http://192.168.0.215:7878 Bazarr: http://192.168.0.215:6767 Jellyfin (media bundle): http://192.168.0.215:8096 Seerr: http://192.168.0.215:5055 Lidarr: http://192.168.0.215:8686 SABnzbd (Usenet): http://192.168.0.215:8186 FlareSolverr: http://192.168.0.215:No Notifiarr: http://192.168.0.215:5454 Remote Access VPN: WireGuard: http://192.168.0.215:51821" Still no login through the above ip-addresses and localhost using edge.
Chris wrote:
The good news is your SparkBox is completely healthy — that paste shows every container up and the VPN tunnel green, so this is the Windows↔WSL network layer, not SparkBox itself. The mirrored-networking mode your box is using can silently drop loopback traffic (your connection reset), and the firewall tweak doesn't always clear it. The reliable fix is switching WSL to NAT mode: 1. In Windows, open C:\Users\<you\.wslconfig and change networkingMode=mirrored to networkingMode=nat, then save. 2. In an administrator PowerShell run: wsl --shutdown 3. Reopen Ubuntu, run: sudo sparkbox up 4. Try http://localhost:8443 in Edge. That's the default mode most WSL boxes use, and localhost forwarding is solid there. If it still won't load, reply and I'll flag it to Tom.
Majorman747 wrote:
I changed to nat, didnt work did another doctor report SparkBox v1.6.561 - Self-Hosted Privacy Stack Created by Tom Spark | youtube.com/@TomSparkReviews Network profile: private [INFO] Starting SparkBox... [INFO] Active modules: core dashboard media tailscale vpn [INFO] Tailscale is on — allowing the tailnet range (100.64.0.0/10) back out of the VPN tunnel so the apps behind it answer remotely. [+] up 3/3 ✔ Container sb-portainer Running 0.0s ✔ Container sb-homepage Running 0.0s ✔ Container sb-npm Running 0.0s [+] up 12/12 ✔ Container sb-radarr Running 0.0s ✔ Container sb-sonarr Running 0.0s ✔ Container sb-seerr Running 0.0s ✔ Container sb-qbittorrent Running 0.0s ✔ Container sb-bazarr Running 0.0s ✔ Container sb-jellyfin-media Running 0.0s ✔ Container sb-byparr Running 0.0s ✔ Container sb-sabnzbd Running 0.0s ✔ Container sb-deunhealth Running 0.0s ✔ Container sb-gluetun Healthy 0.6s ✔ Container sb-prowlarr Running 0.0s ✔ Container sb-notifiarr Running 0.0s [+] up 1/1 ✔ Container sb-tailscale Running 0.0s [+] up 1/1 ✔ Container sb-wg-easy Running 0.0s [OK] SparkBox is running! [qbit-seed-limits] couldn't sign in to qBittorrent — skipping for now (retries on the next 'sparkbox up'; 'sudo sparkbox reset-password qbit' if it persists). [INFO] Auto-firing arr-bootstrap in the background (~90-180s)... [INFO] Jellyfin + Seerr credentials will appear in the launcher modals when ready. Service URLs: Core Infrastructure: Nginx Proxy Manager: http://172.30.63.139:81 Portainer: http://172.30.63.139:9000 Homepage: http://172.30.63.139:3000 TomSparkBox Dashboard: TomSparkBox Dashboard: http://172.30.63.139:8443 Media Center: qBittorrent: http://172.30.63.139:8089 Prowlarr: http://172.30.63.139:8181 Sonarr: http://172.30.63.139:8989 Radarr: http://172.30.63.139:7878 Bazarr: http://172.30.63.139:6767 Jellyfin (media bundle): http://172.30.63.139:8096 Seerr: http://172.30.63.139:5055 Lidarr: http://172.30.63.139:8686 SABnzbd (Usenet): http://172.30.63.139:8186 FlareSolverr: http://172.30.63.139:No Notifiarr: http://172.30.63.139:5454 Remote Access VPN: WireGuard: http://172.30.63.139:51821 [WARN] Windows (WSL) box: 172.30.63.139 only works on this PC — phones, TVs and consoles cannot reach it Windows keeps its built-in Linux on a private network of its own, so the addresses above resolve from this PC and nowhere else. Anything else on your home Wi-Fi will fail to connect no matter what is typed in. It is not a wrong password, a bad user account or a Jellyfin fault — the device never gets there. Best fix — put SparkBox on your home network (needs Windows 11 22H2 or newer). On Windows, save a file called .wslconfig in your user folder (C:\Users\<you) containing exactly: [wsl2] networkingMode=mirrored Then in PowerShell (right-click, Run as administrator): wsl --shutdown Set-NetFirewallHyperVVMSetting -Name '{40E0AC32-46A5-438A-A0B2-2B479E8F2E90}' -DefaultInboundAction Allow Reopen Ubuntu, run 'sudo sparkbox up', then 'sparkbox urls' again. The addresses will change to your PC's normal home-network address and every device in the house can use them. On Windows 10, or mirrored mode won't stick? Forward the ports from Windows instead — once per app you want on the TV, in an administrator PowerShell (Jellyfin's 8096 shown; repeat with each port listed above): netsh interface portproxy add v4tov4 listenaddress=0.0.0.0 listenport=8096 connectport=8096 connectaddress=172.30.63.139 New-NetFirewallRule -DisplayName 'SparkBox 8096' -Direction Inbound -Protocol TCP -LocalPort 8096 -Action Allow Then point the TV at your PC's home-network address (PowerShell: ipconfig), not at 172.30.63.139. Heads-up: 172.30.63.139 is reassigned every time Windows restarts, so the forwarding has to be redone when it changes — mirrored mode does not. Full walkthrough: https://tomsparkbox.com/guides/run-sparkbox-on-windows-wsl dlheunis@DESKTOP-2QT1OT9:~$ sudo tomsparkbox doctor sudo: 'tomsparkbox': command not found dlheunis@DESKTOP-2QT1OT9:~$ sudo tomsparkbox docter sudo: 'tomsparkbox': command not found dlheunis@DESKTOP-2QT1OT9:~$ sparkbox doctor SparkBox v1.6.561 - Self-Hosted Privacy Stack Created by Tom Spark | youtube.com/@TomSparkReviews Network profile: private SparkBox Doctor Running diagnostics... [Install location] [OK] SparkBox is installed at: /opt/sparkbox [OK] Settings file (.env): /opt/sparkbox/.env [OK] Media library folder (MEDIAROOT): /opt/sparkbox/data/media [WARN] Listed more than once in .env: VPNDOT WIREGUARDMTU Only the LAST line for each of those is used, so an edit higher up the file does nothing. Collapse each one to a single line with: sudo sparkbox set-env VPNDOT <the value you want sudo sparkbox set-env WIREGUARDMTU <the value you want [Docker] [OK] Docker daemon is accessible [OK] Docker version: Docker version 29.6.2, build dfc4efb [OK] Docker Compose: 5.3.1 [Docker Socket] [OK] Docker socket exists at /var/run/docker.sock [OK] Docker socket is readable [User IDs] [INFO] Current user: dlheunis (UID=1000, GID=1000) [OK] PUID=1000 (containers run as UID 1000) [OK] PGID=1000 (containers run as GID 1000) [Container Egress] [OK] Apps can reach webhook.tomsparkbox.com over sbproxy (their real network) [OK] Docker's default bridge can reach tomsparkbox.com (dashboard Update button) [Port Conflicts] [WARN] Port 80: in use by another program on this box (not SparkBox) LISTEN 0 4096 0.0.0.0:80 0.0.0.0: Affects: Nginx Proxy Manager (custom domains + HTTPS) — custom domains and automatic HTTPS stop working (apps opened by IP:port still work). Fix: move Nginx Proxy Manager (custom domains + HTTPS) to a free port (nothing is lost, it just answers somewhere else) — Dashboard → Settings → Ports → 'HTTP Port', then Save; or on the server: sudo sparkbox set-env HTTPPORT <a free port sudo sparkbox up Or leave it: the rest of SparkBox is unaffected by this one port. [OK] Port 443: in use by SparkBox (sb-npm) [OK] Port 8443 (the SparkBox dashboard itself): available [OK] Port 9001: in use by SparkBox (sb-portainer) [Portainer Auth] [OK] Portainer admin login verified (HTTP 200) [VPN Tunnel] [OK] Gluetun tunnel is healthy [Hardware Transcoding] [WARN] Hardware Transcoding is set to 'auto' but this host has NO /dev/dri -- there is no GPU for SparkBox to pass through, so everything transcodes in software This is a HOST setting, not a SparkBox one. On a generic Debian/Ubuntu install the Intel driver may not be loaded: lsmod | grep -c i915 0 means the driver is not loaded sudo apt install firmware-misc-nonfree intel-media-va-driver-non-free sudo modprobe i915 && ls -l /dev/dri On a NAS, enable GPU passthrough for Docker in the NAS settings. If this box genuinely has no usable GPU, set Hardware Transcoding to 'none' in Settings so the dashboard stops implying it is active. [OK] Nvidia GPU detected (driver responding) [WARN] Nvidia GPU present but Docker's nvidia runtime is NOT registered -- JELLYFINHWACCEL=nvidia would fall back to software transcoding Fix: install nvidia-container-toolkit, then: sudo nvidia-ctk runtime configure --runtime=docker && sudo systemctl restart docker [Media Storage] [OK] MEDIAROOT=/opt/sparkbox/data/media exists [OK] MEDIAROOT is writable [WARN] Your apps (user id 1000) can't READ what's in MEDIAROOT — common with media already on a UGREEN/UGOS NAS. [WARN] Fix (read access without taking ownership): [WARN] sudo setfacl -R -m u:1000:rX -d -m u:1000:rX '/opt/sparkbox/data/media' [WARN] (This grants access via ACLs: it survives UGOS's periodic permission [WARN] resets and doesn't change who owns your files.) [WARN] Guide: https://tomsparkbox.com/guides/use-existing-ugreen-media.html [INFO] Free space at MEDIAROOT: 935GB [System Resources] [INFO] Total RAM: 9706MB [INFO] Available RAM: 7410MB [OK] RAM looks sufficient for 5 enabled modules [INFO] Free disk at SBROOT: 935GB [Container Health] [ERROR] sb-filebrowser crashed (exit code 128) Try: sudo sparkbox up (and 'sparkbox logs <name' to see why a container is unhappy)
Majorman747 wrote:
[Tailscale Inbound Path] [WARN] Tailscale connects, but its inbound path CANNOT reach this box's apps — from a phone everything will look 'connected' and still refuse. Tailscale delivers each incoming connection by dialing 127.0.0.1:<port from where it runs, and that dial is failing. On Docker Desktop (Windows/Mac) this is the architecture: the container lives in a VM away from your apps — run SparkBox in WSL2 with native Docker instead (guide: https://tomsparkbox.com/guides/run-sparkbox-on-windows-wsl). Otherwise check the dashboard is actually listening: curl -k https://127.0.0.1:8443 [Tailscale Reachability] [INFO] Dashboard not answering on 127.0.0.1:8443 — route-shadow check not applicable (see container health above) [Windows (WSL) Networking] [WARN] Windows (WSL) box: 172.30.63.139 only works on this PC — phones, TVs and consoles cannot reach it Windows keeps its built-in Linux on a private network of its own, so the addresses above resolve from this PC and nowhere else. Anything else on your home Wi-Fi will fail to connect no matter what is typed in. It is not a wrong password, a bad user account or a Jellyfin fault — the device never gets there. Best fix — put SparkBox on your home network (needs Windows 11 22H2 or newer). On Windows, save a file called .wslconfig in your user folder (C:\Users\<you) containing exactly: [wsl2] networkingMode=mirrored Then in PowerShell (right-click, Run as administrator): wsl --shutdown Set-NetFirewallHyperVVMSetting -Name '{40E0AC32-46A5-438A-A0B2-2B479E8F2E90}' -DefaultInboundAction Allow Reopen Ubuntu, run 'sudo sparkbox up', then 'sparkbox urls' again. The addresses will change to your PC's normal home-network address and every device in the house can use them. On Windows 10, or mirrored mode won't stick? Forward the ports from Windows instead — once per app you want on the TV, in an administrator PowerShell (Jellyfin's 8096 shown; repeat with each port listed above): netsh interface portproxy add v4tov4 listenaddress=0.0.0.0 listenport=8096 connectport=8096 connectaddress=172.30.63.139 New-NetFirewallRule -DisplayName 'SparkBox 8096' -Direction Inbound -Protocol TCP -LocalPort 8096 -Action Allow Then point the TV at your PC's home-network address (PowerShell: ipconfig), not at 172.30.63.139. Heads-up: 172.30.63.139 is reassigned every time Windows restarts, so the forwarding has to be redone when it changes — mirrored mode does not. Full walkthrough: https://tomsparkbox.com/guides/run-sparkbox-on-windows-wsl ============================================ 8 issue(s) found. Review warnings above and fix as needed. ============================================
Majorman747 wrote:
FOUND THE ROUTE CAUSE! Was using the same machine on WSL before windows installer was available, so there was pre-existing WSL server which could be overlapping. So did a via WSL sudo /opt/sparkbox/sparkbox reset --nuke --yes sudo rm -rf /opt/sparkbox sudo rm -f /usr/local/bin/sparkbox and did a full uninstall via windows program remover, restarted and re-installed, now working. Sorry for wasting your time!
Chris wrote:
No apology needed, Majorman747 — five days of steady debugging isn't wasted time, and you landed on the exact kind of root cause that's hard to spot from the outside: a leftover WSL SparkBox from before the Windows installer existed, overlapping the new install. That's a genuinely useful catch, and I'm noting it so the team can flag it for other Windows users who hit the same wall. Really glad it's running now — enjoy it, and I'm here if anything else wobbles.