This site is still a work in progress. For the current docs, head to dictionarry.dev.

Installation

Profilarr is a self-hosted web app that runs continuously, like Radarr and Sonarr. It keeps everything in one folder: its SQLite database, logs, backups, and the databases you link. Testing custom formats and quality profiles requires the Profilarr parser, a small companion service that runs as its own container.

Requirements

  • A Docker host running Linux kernel 3.17 or newer, on linux/amd64 or linux/arm64.
  • Sonarr v4.0.9.2386 or newer.
  • Radarr v5.10.4 or newer.
Info

Profilarr crashes at startup with getentropy failed on kernels older than 3.17. Deno, the runtime Profilarr is built on, relies on the getrandom system call, which Linux added in 3.17. This mostly affects older NAS devices, such as Synology DSM installs that still run kernel 3.10. See issue #650 for more details.

Installation Methods

Profilarr is currently distributed as a Docker image. Standalone binaries for Windows, macOS, and Linux are a work in progress.

Any Docker host, amd64 or arm64
Available
Unraid, from Community Applications
Available
Windows binary
Windows
Planned
macOS binary
macOS
Planned
Linux binary
Linux
Planned

The Parser

The parser is a small companion service that reads release titles the way Radarr and Sonarr do. It’s written in C#, like Radarr and Sonarr, so it uses the same parsing logic and the same .NET regex engine they do. That means test results match what your Arrs will actually decide.

Profilarr uses it for:

  • Custom format testing
  • Quality profile testing, including Quick Parse
  • Checking that a regular expression is valid
  • Running Regex101 unit tests

The parser was built mostly for the development side of Profilarr: building and testing configurations. If you’re only linking a database and syncing it to your Arrs, without changing its configs, you can skip the parser entirely and lose nothing you’d use (and save about 50 MB of RAM). Without it, Profilarr hides custom format and quality profile testing, and regex checks and Regex101 tests show no results.

Release Channels

Profilarr is published under a few tags, so you can choose how it updates. New features land on develop first for beta testers, and a batch becomes a stable release once it’s verified. How you keep Profilarr up to date depends on how you installed it. For Docker, see Updating.

latest
The newest stable release, including future major versions.
2
The newest stable release within v2. It never moves to a new major version.
2.1.0
One specific release. It never updates.
develop
Pre-release builds still being tested. Not guaranteed to be stable.

Use latest unless you specifically want to test upcoming changes. The parser publishes the same tags. Keep both containers on the same one.

Environment Variables

Profilarr is configured with environment variables. Most are read by Profilarr itself and work the same way with any installation method. The ones marked Docker only are handled by the container’s startup script, so they won’t apply to the standalone binaries.

General

PUID Docker only
Default: 1000
User ID that Profilarr runs as. Its config folder is owned by this user.
PGID Docker only
Default: 1000
Group ID that Profilarr runs as. Its config folder is owned by this group.
UMASK Docker only
Default: 022
File creation mask for files Profilarr writes.
TZ
Default: UTC
Timezone used for schedules, such as Australia/Adelaide.
PORT
Default: 6868
Port the web UI listens on.
HOST
Default: 0.0.0.0
Address the web UI binds to.

Authentication

AUTH
Default: on
Turns login on or off. See Authentication.
OIDC_DISCOVERY_URL
Default: not set
Discovery URL of your OIDC provider.
OIDC_CLIENT_ID
Default: not set
Client ID registered with your OIDC provider.
OIDC_CLIENT_SECRET
Default: not set
Client secret registered with your OIDC provider.
ORIGIN
Default: not set
The URL you reach Profilarr at behind a reverse proxy, such as https://profilarr.example.com. See Reverse Proxy.
PROFILARR_API_KEY
Default: not set
An API key with full access, for scripts and automated deployments. See Authentication.

Set all three OIDC_ variables to turn on SSO.

Parser

See The Parser for what it does and whether you need it.

PARSER_HOST
Default: localhost
Host name of the parser service, such as its service name in your compose file.
PARSER_PORT
Default: 5000
Port of the parser service.

Outbound Proxy

Profilarr has no proxy setting of its own. It follows these standard variables for everything it fetches: database updates from GitHub, notifications, TMDB, and announcements.

HTTPS_PROXY
Default: not set
Proxy for outbound https:// requests.
HTTP_PROXY
Default: not set
Proxy for outbound http:// requests.
ALL_PROXY
Default: not set
Proxy for both http:// and https:// requests.
NO_PROXY
Default: not set
Comma-separated hosts, IPs, or ranges that skip the proxy.
  • Proxy URLs take the form scheme://user:pass@host:port, where the scheme is http, socks5, or socks5h. Use socks5h to send DNS lookups through the proxy too.
  • Special characters in the username or password need to be URL-encoded, such as @ as %40 and : as %3A.
Warning

Add your Radarr and Sonarr instances and the parser to NO_PROXY. Any host that isn’t listed is sent to the proxy, and the proxy usually can’t reach services on your local network. This matters most when HTTP_PROXY or ALL_PROXY is set, since those also cover plain http:// addresses.

For example, this routes Profilarr through a proxy container named gluetun, while your Arrs and the parser stay direct:

compose.yml
environment:
  - HTTPS_PROXY=http://user:pass@gluetun:8888
  - NO_PROXY=localhost,127.0.0.1,parser,radarr,sonarr

Announcements

PROFILARR_BULLETIN_URL
Where announcements and release information are fetched from. Only change it to point at a mirror.

Secrets from Files

Docker only. Any variable can be read from a file instead by adding _FILE to its name and setting it to the file’s path. This works with Docker secrets, so values like the OIDC client secret don’t have to sit in your compose file:

compose.yml
environment:
  - OIDC_CLIENT_SECRET_FILE=/run/secrets/oidc_client_secret

The startup script reads the file, strips any newlines, and sets the variable without _FILE from it. If the file doesn’t exist, it logs a warning and leaves the variable unset.