ROUX Coming soon

YOUR LIBRARY. YOUR ROUX.

Your film collection.
Your viewing story.

Movies and series from your NAS, on your iPhone.
Find tonight’s watch, pick up where you left off,
and collect your favorite moments as cards.

Find your way to start

Synology NAS · iPhone · Share with owner approval

A PLACE FOR YOUR FILMS

ROUX
Find.
Watch.
Remember.
01 / LIBRARY
02 / PICK
03 / DECK

THE ROUX EXPERIENCE

Beyond a list of files.

Roux does not provide videos.
It helps you enjoy the works you already own.

01 / LIBRARY

Stories, not filenames.

Browse movies and series by poster, explore seasons and episodes, and pick up where you left off with Continue Watching.

02 / PICK

An easier “what to watch?”

Find something that fits your time and mood. Play what catches your eye, or move on to the next Pick.

03 / DECK

A card for every memory.

Earn Watch Cards by watching. Add ratings and short reviews, and collect your favorite movies and series in your own Deck.

LET’S GET YOU STARTED

How are you getting started?

Setting up your own NAS or joining someone else’s?
Choose the path that fits you.

FOR NAS OWNERS

From your NAS
to your first film.

Prepare your NAS on a computer,
then connect Roux on your iPhone.

Prerelease · Real NAS validation pending

For x86-64 NAS models running DSM 7.2 or later with Container Manager support. ARM models are not supported yet. Fresh installation, data-preserving updates, and recovery are still being validated on real NAS hardware.

Download NAS installation ZIP

0.11.0-rc.5 prerelease · ZIP contains settings and instructions only. No sign-in or Git commands required. Release notes, checksums, and licenses

Guide reviewed 0 / 5

Checkmarks are saved in this browser. They do not sync with the app or automatically verify your NAS.

  1. Prepare your NAS

    Check for DSM 7.2 or later, an x86-64 CPU, and Container Manager support. Have a computer for DSM setup, your video files, and an iPhone running iOS 17 or later ready.

  2. Install in DSM

    Extract the ZIP in File Station to /volume1/docker/roux and create a data folder. In Container Manager → Project → Create, select this folder and docker-compose.yml. Your NAS downloads a prebuilt image; no compilation is needed.

    Connect your media folder

    The default is /volume1/media-library. Create a shared folder or edit the YAML: to the left of /media:ro , enter your existing media folder’s actual path. Keep the read-only :ro flag. Do not use your media folder as data.

    Updating an existing installation?

    Read the full update guide →

    Stop the server and back up data and your existing YAML. Keep your media and data paths, ports, and personal key settings. Change only the image for both services to the same new version, and remove build entries. Do not overwrite your installation folder with the new ZIP. If the update fails, restore the previous image together with the pre-update data.

    Check that roux-data-init exits with code 0 and roux-server is healthy.

  3. Find and connect to your server

    On the same Wi-Fi as your NAS, allow Roux to access the local network. Choose Already installed, then select a discovered server or enter its address. After device approval, link your social account and server ownership.

    Server discovery, device approval, and ownership linking are separate steps.

  4. Prepare your library

    Check your video list. The NAS owner can add a personal TMDB key once to fetch posters and metadata. Invited members need no setup. You can browse files and play videos before connecting. Connect posters and metadata · Connect external subtitles

  5. Play your first video

    Open a video and check playback and seeking. After playback works at home, set up external HTTPS access and family invitations if needed. Do not expose DSM management ports or the Roux port directly through your router.

    Remote access is optional
YOUR SERVER, CONNECTED

Bring your server
into the app.

Start on the same Wi-Fi
for your first connection.

  1. Check that the server is running

    In DSM’s Container Manager, check that Roux is running. Connect your iPhone to the configured network and allow Roux’s Local Network access.

  2. Choose Already installed

    Find your server or enter its address on the app’s start screen. If several servers appear, check which belongs to your NAS before selecting it.

  3. Follow the approval steps

    Complete the device approval or account connection requested by the app. To invite others as an owner, also link your social account to NAS ownership.

  4. Check your library

    Check that your library and Continue Watching history appear. When updating an existing server, preserve its data instead of creating new folders or clearing it.

YOU’RE INVITED

No NAS of your own?
Join with permission.

You’ll need the app, a social account,
and the owner’s server address and join code.

The server needs to be up to date too

Joining requires an app, server, and sign-in service that support join approvals. If the request screen is missing, ask the owner to check for updates.

  1. Get the server address and code

    Ask the owner for the connection address and join code. Away from home, you need an HTTPS address reachable from outside the network.

  2. Choose I have an invitation

    Enter the address and code in the app to verify the server. Sign in with Apple or Google and request to join. The code alone does not open the library.

  3. Wait for owner approval

    The owner checks your account and chooses your library and remote access permissions. In the app, tap Check approval to see the result.

  4. Enjoy the libraries you can access

    Connect to this server to get started. Viewing history and reviews are separate for each user. The owner can remove members later.

SHARED LIBRARY. PERSONAL EXPERIENCE.

Watch together.
The owner stays in control.

Choose which libraries to share
and who can join.

Approve requests
Review each account’s request and choose library and remote access permissions.
Change the code
Invalidate the old code and unfinished requests. Already approved members keep their access.
Remove members
Revoke the account’s server access and connected device sessions.

SERVER UPDATE · 2026.09.24

Keep your history.
Update your server.

Current release: 0.11.0-rc.5
Adds OpenSubtitles authentication, subtitle downloads and connection checks. Existing library, history, Watch Cards and slabs are preserved.

Download public install ZIP

DSM 7.2+ · x86-64 · Prerelease · Setup revision 2
Fresh installation, data-preserving updates and recovery still need validation on a real NAS. Release notes, checksums & licenses

Updating an existing installation

  1. Stop and back up. Stop the Roux project in Container Manager. Copy your current YAML and entire actual data folder to a separate backup location. Keep the previous image reference. Do not use Clean or delete data.
  2. Extract the new ZIP elsewhere to compare. Do not overwrite your project with the public ZIP. Preserve media and data paths, ports, environment variables and personal key settings in your current YAML. Do not switch existing media paths to the public defaults.
  3. Update both service images. Set image for both roux-data-init and roux-server to the value below. Remove their build entries. Save and deploy the project YAML to pull the image and recreate containers. Restarting old containers alone does not update them.
Image reference for this releaseghcr.io/kyhoonx/roux-server:0.11.0-rc.5-5135a08a1e9f@sha256:094cea4ac0313281128dffc5aac9c8bdeae7c263d4f0a1c38a8cd457a6e78390
  1. Check your library and playback. The init service should exit with code 0 and the server should be healthy. Check /health for version 0.11.0-rc.5, buildId 5135a08a1e9f and your existing serverId. Check your library, history and cards, then play and seek a video.
  2. Recover with the server stopped. Inspect the error without deleting data. Restore the previous image together with its compatible backup from just before the update. Rolling back across an authentication change requires that version’s recovery instructions and pairing devices again at home.

If you received a personal update ZIP, follow its README_NAS.md. Do not mix the personal source-build process with the public image installation process. Keep existing personal keys. New installs start without a key; the owner can connect a personal TMDB key later.

OPTIONAL · NAS OWNER

Connect posters and metadata,
once per NAS.

The NAS owner adds a personal TMDB key so the server can fetch metadata directly. Invited members do not need a key.

You can connect later. The default installation starts without a key, so you can browse files and play videos first. Social sign-in is separate from TMDB setup.

  1. Get a TMDB token on a computer

    Open TMDB Settings → API, describe your actual use and accept the applicable terms. Use the long API Read Access Token, not the short API Key (v3 auth) or your password.

  2. Save it in a protected DSM folder

    Install Text Editor from Package Center. In File Station, create /volume1/docker/roux-secrets outside the Roux project. Save only the token on one line in tmdb_read_token, without .txt, quotes or a Bearer prefix.

    Keep ordinary users and guests out of this folder. The server runtime UID 65532 must be able to read the file; do not grant Everyone full control or run the server as root. The file is not automatically encrypted. Close the editor and clear your clipboard afterward. Do not enter the key in the app, website, YAML, support messages or screenshots.

  3. For a new install, choose one configuration

    If your token is ready, select docker-compose.tmdb.yml from the ZIP. To connect later, select docker-compose.yml. Each is a complete configuration; never apply both. Adjust media and secret paths to your NAS. No OpenSubtitles key or empty file is required.

  4. For an existing install, merge only the changes

    Stop the project and back up its YAML and data. Do not replace the whole configuration. Merge the partial example below, change the existing ROUX_METADATA_MODE to direct, and remove ROUX_PUBLIC_METADATA_URL if present. Do not duplicate existing secret entries. Preserve image, media/data paths, ports and other secrets.

    Where to add settings — partial example, not a complete YAML
    services:
      roux-server:
        environment:
          ROUX_METADATA_MODE: "direct"
        secrets:
          - tmdb_read_token
    secrets:
      tmdb_read_token:
        file: "/volume1/docker/roux-secrets/tmdb_read_token"

    Apply/deploy to recreate the container. Restarting alone may retain the old mounted key file. Do not use Clean or delete data.

  5. Check configuration and actual lookups separately

    Once the server is healthy, open Settings → Synology setup and checks → Check again in Roux. Detecting settings does not validate the key or confirm successful lookups. Refresh Library, check a known title/poster and play a video. Adding a key later also enriches the existing library.

Connection errors, token replacement and rollback
  • Missing file prevents startup: Check the exact path and unwanted .txt extension. To connect later, remove only the TMDB secret mount from your current YAML and redeploy in direct mode.
  • Settings not detected: Check file name, permissions, mount and container recreation.
  • Configured but no posters: Check NAS connectivity/time and token validity. Retry temporary failures later. Incorrect title matches can be corrected in the app. Do not delete data.
  • Replace a token: Replace the protected file and recreate the container. To disconnect, remove the TMDB secret mount and redeploy before revoking the token in TMDB.
  • Undo setup edits: Restore your previous YAML and redeploy with the same image/data. These setup changes require no image or database update.

Launch candidate version 1.0 build 76 is ad-free. Connect TMDB with a personal key under the provider’s terms. Any future advertising depends on separate confirmation of applicable terms. Real NAS testing of new installations, adding a key later and token rotation remains pending.

TMDB getting started · Read Access Token · Usage terms and attribution

OPTIONAL · NAS OWNER

Need more subtitles?
Connect OpenSubtitles.

Embedded subtitles, sidecar files and subtitles saved on the NAS need no account. The owner connects once only if external search and download are needed.

Invited members need no setup. External requests from the same NAS use the owner's download allowance.

  1. Prepare an OpenSubtitles.com account and API key

    Register at OpenSubtitles.com, confirm your email and obtain a key through API consumers, reviewing the terms and describing your use. Downloads require the API key and your username and password. Roux social sign-in is separate; do not use legacy .org API credentials.

    Check your OpenSubtitles account and API terms for allowance and pricing. Roux promises no fixed free quota.

  2. Store credentials only on your NAS

    Using DSM Text Editor, save one value per file in /volume1/docker/roux-secrets, outside the project: opensubtitles_api_key, opensubtitles_username and opensubtitles_password. No .txt or quotes; preserve password spaces.

    Restrict access to the administrator and necessary read access for runtime UID 65532. Never enter credentials in the app, website, YAML, email or logs. This store is not automatically encrypted; protect backups too. Close the editor and clear the clipboard after entry.

  3. Connect the server configuration

    For a new install choose one complete configuration: docker-compose.subtitles.yml (subtitles) or docker-compose.tmdb-subtitles.yml (metadata and subtitles). Prepare the required secrets first. The default configuration runs without these files.

    For an existing installation, update the server, back up YAML/data, then merge the following entries only. Preserve existing media/data paths, ports and TMDB settings; do not duplicate secret blocks.

    Where to add entries — a partial example, not a full configuration
    services:
      roux-server:
        secrets:
          - opensubtitles_api_key
          - opensubtitles_username
          - opensubtitles_password
    secrets:
      opensubtitles_api_key:
        file: "/volume1/docker/roux-secrets/opensubtitles_api_key"
      opensubtitles_username:
        file: "/volume1/docker/roux-secrets/opensubtitles_username"
      opensubtitles_password:
        file: "/volume1/docker/roux-secrets/opensubtitles_password"

    Apply/deploy to recreate the container. Do not mount secrets into the data initializer. Do not Clean or delete data.

  4. Check the connection, then try one subtitle

    Open Settings → Synology setup and checks → Check OpenSubtitles connection to verify the account and remaining downloads. This check consumes no download allowance. Counts reflect the last check. Then search your language in the player's subtitles menu, download and apply one result. Actual downloads can consume allowance. Saved subtitles use the NAS cache.

Connection errors, allowance and disconnecting

Authentication needed: check key, username/password and email confirmation. Update files and recreate the container. Rejected logins stop to prevent repeated invalid credentials.

Quota exhausted: check the reset time in your OpenSubtitles account. Rate limited: wait at least one minute. Unavailable: check NAS internet and time. Startup failure: check exact secret paths, filenames and permissions. Playback is unavailable while the server cannot start. To connect later, remove only the added OpenSubtitles secret mounts and redeploy your existing configuration. If the server is running and only the provider connection fails, existing subtitles and playback remain available.

To disconnect, remove only these three server secret mounts and redeploy. Preserve TMDB and data. If rolling back a server version, restore the previous matching image and data together. The ZIP includes complete bilingual steps in OPENSUBTITLES_SETUP.md.

Automatically tested prerelease feature. Authentication, downloads and invited-member use on a real NAS still need verification.

SYNOLOGY · REMOTE ACCESS

Your library.
Beyond your Wi-Fi.

Finish your first playback at home before continuing. This guide uses DDNS and an HTTPS reverse proxy on DSM 7.2 or later. Menu names may vary with DSM versions.

QuickConnect addresses and join codes do not provide internet connectivity for Roux. Roux needs a separate, reachable HTTPS address. Never share your NAS administrator password.

Connection path
iPhone → HTTPS 443 → NAS reverse proxy → Roux 8080

  1. Check playback at home and your router

    Complete owner setup and play a video on the same Wi-Fi. Reserve a stable LAN IP for the NAS in your router. Check whether the router’s internet (WAN) address is public IPv4. A private address or 100.64.0.0–100.127.255.255 may indicate double NAT or CGNAT. Ask your ISP about a public IP or configure a VPN separately in that case. Opening one port alone will not solve it.

  2. Create a Synology DDNS address

    In DSM, open Control Panel → External Access → DDNS → Add. Select Synology and register an available hostname. Check Test Connection and the status. Replace every example roux-example.synology.me below with your own hostname. DDNS maps a name to an address; it does not open ports.

  3. Get a certificate for that hostname

    Use the Let’s Encrypt option during DDNS setup, or Control Panel → Security → Certificate → Add. After creating the proxy below, assign this certificate to its service in certificate Settings/Configure. Changing the default certificate can affect other services.

    Check automatic renewal too. HTTP validation for custom domains may need TCP 80 connectivity; follow Synology’s certificate instructions. Playback uses HTTPS 443. Do not bypass certificate warnings.

  4. Create the reverse proxy to Roux

    Open Control Panel → Login Portal → Advanced → Reverse Proxy → Create. Name the rule Roux.

    Source
    Protocol HTTPS
    Hostname roux-example.synology.me
    Port 443
    Destination
    Protocol HTTP
    Hostname 127.0.0.1
    Port 8080

    8080 is the Roux port mapped on the NAS; use your existing YAML’s host port if different. Set the custom request header X-Forwarded-Proto to https and retain existing forwarding headers. Roux uses these to recognize proxy connections as remote requests. Do not point the rule at DSM management or owner enrollment port 8081.

  5. Forward HTTPS through your router

    In your router’s port forwarding settings, map external TCP 443 → NAS LAN IP, TCP 443. If DSM Firewall is enabled, allow the required clients to reach port 443. If 443 is already in use, check hostname-based proxy rules without overwriting existing services.

    How to set up port forwarding

    This routes incoming HTTPS connections from your router to your NAS. First prepare the certificate and reverse proxy in the steps above.

    1. Open your router’s admin page. On an iPhone connected to home Wi-Fi, open Settings → Wi-Fi → ⓘ beside the connected network. Enter its Router address in Safari and sign in with your router admin account.
    2. Find port forwarding. Depending on your router, look under “NAT”, “Port Forwarding” or “Virtual Server”. Add a rule with these values.
    Rule name
    Roux HTTPS
    Protocol
    TCP
    External port
    443 (enter 443 for both start and end, if shown)
    Internal IP
    Your NAS’s LAN IP
    Example: 192.168.1.100 — replace this with your own.
    Internal port
    443 — the DSM reverse proxy’s source port

    Find the NAS IP in DSM under Control Panel → Network → Network Interface. Reserve that address in your router’s DHCP settings so it stays the same.

    Save/apply, then turn Wi-Fi off to test. On cellular, open https://roux-example.synology.me/health and check for status: ok, then play a video in the app. Use your own DDNS hostname.

    Is another device already using 443? Keep its existing rule. To use a separate port, set the external port, internal port and DSM proxy source port all to 9443, and allow it through the firewall. Add :9443 to the app and test URLs, for example https://roux-example.synology.me:9443. The proxy destination remains Roux port 8080.

    For timeouts, check the NAS IP, ports and firewall first. See “If the connection fails” below for double NAT or CGNAT. To stop remote access, disable only the Roux rule you added.

    Do not expose Roux 8080/8081 or DSM management 5000/5001 directly, and do not enable DMZ. This guide explains the settings; it does not open ports automatically.

  6. Set the app address and permissions

    Enter https://roux-example.synology.me in Roux’s server address field and connect. Do not append /health, /webman or the internal port. Guests request access using this HTTPS address and a join code from the owner. The owner must grant both the appropriate libraries and remote access permission.

  7. Turn Wi-Fi off and test on cellular

    In Safari, open https://roux-example.synology.me/health without certificate warnings. Then play and seek a video in Roux. Testing on home Wi-Fi alone does not prove remote connectivity. Turn Wi-Fi back on afterward.

If the connection fails
  • Timeout: Check the DDNS IP, WAN address, port 443 forwarding and firewalls. Double NAT or CGNAT may require help from your ISP.
  • Certificate error: Match the app hostname, proxy hostname and certificate name. Check expiry and service assignment.
  • 502 or a DSM screen: Check the destination HTTP port, running container and source hostname.
  • Connected but denied: Check membership approval, library permissions and remote access. Initial owner enrollment must happen at home.
  • Only playback is slow: Check your home upload speed and cellular connection, then compare another video.

Synology DDNS · Certificate · Reverse proxy · QuickConnect

A LITTLE HELP

Help when you need it.

Can I collect Watch Cards without ads or slabs?

Yes. The current launch version has no ads. Earn Watch Cards by meeting the viewing requirements, and add ratings and short reviews in the film or season detail screen. Review labels appear only on slabs you already own. New slabs are not offered in this version; existing cards, slabs and viewing records are preserved.

Does Roux provide movies?

No. Roux organizes and plays media you own on your NAS. Bring your own videos or ask a server owner for library access.

Is it an address error, an offline server, or a permission issue?

For an invalid address, check http or https, the host, and port before entering it again. If the server does not respond, check Wi-Fi, server health, firewall, and Local Network permission. If it connects but denies access, ask the owner to check device approval and library permissions, then retry. You do not need to delete data or reinstall.

Posters are missing or metadata has errors.

Check the owner’s personal TMDB key settings and NAS connectivity. Detecting settings does not confirm successful lookups. Recreate the container after replacing a key. File browsing and playback remain available; do not delete data. See the connection and recovery guide.

My server is not discovered.

Check that the NAS and iPhone are on the same Wi-Fi, Roux Server is running, and Local Network access is allowed on iPhone. Guest Wi-Fi may block communication between devices. If discovery fails, enter the server address manually in the app.

I entered the join code but cannot connect.

First check that the address is reachable. A home address may not work outside your network. Join codes expire after 48 hours or when the owner changes them. Get a current code and request again. If approval is pending, check with the owner.

The owner approved me, but some works are missing.

Only permitted libraries appear. Library access and remote access are separate permissions. Ask the owner to check both.

Where are my videos and account information stored?

Original videos stay on the NAS, which also manages viewing history and reviews. Social sign-in and account linking use Roux’s central account service. Metadata, images, and external subtitles involve separate providers. Not all data is stored only on your NAS.

Will an update erase my history?

Updates are designed to preserve your existing data folder. Back up server data and settings first, and follow the instructions for that version. When rolling back, restore a compatible data backup together with the previous version.