// the find
pierre-emmanuelJ/iptv-proxy
IPTV reverse proxy for M3U/M3U8 playlists and Xtream Codes accounts, with HLS. One binary or Docker container.
A reverse proxy that sits between IPTV players and either an M3U playlist or an Xtream Codes account, so players connect to your own address with your own login and never see the provider's host or credentials. It suits a household sharing one provider subscription, or anyone who wants to put a provider behind their own domain or VPN. It ships as a single Go binary or a Docker image, with no database.
Live streams are shared. When several players watch the same channel, the proxy holds one provider connection and fans it out, which matters on providers that allow only one or two connections. A stream that drops or goes silent for 20 seconds is reopened while someone is still watching, so the player does not have to reconnect. The last-good cache is handled deliberately: it serves the previous full answer when the provider errors, but passes refusals such as a bad account or expired subscription straight through, so a player still learns something real when its login stops working. HLS rewriting is stateless. Each variant, segment, key and audio address is replaced by the provider URL encrypted into a token, so nothing is stored and tokens survive restarts. Filters apply the same way to the playlist, the Xtream API and the XMLTV guide, and the guide is trimmed to the channels you kept. On a provider with thousands of channels, that decides whether a player can load the guide at all.
The proxy's user and password are part of every playlist and stream address. The README is right that HTTPS is needed once the proxy is reachable from outside, but TLS does not protect the URL in a reverse proxy's access log, a player's history or a screenshot, and a reverse proxy in front will log the full path unless it is configured not to. The HDHomeRun tuner has no login at all. The README warns about this and its example binds to a LAN address, but a plain -p 5004:5004 in a compose file publishes the port on every interface, and anyone who reaches it can watch. Per-user filters do not reach movies or series. The README's kids example restricts live channels by group, but that account still gets the full VOD catalogue, which is a real gap for anyone using this for parental control. The configuration surface is large: about thirty options, each settable by flag, environment variable or YAML with its own precedence, and several modes (passthrough, sources, users, M3U versus Xtream) that exclude each other. The README says the proxy reports these conflicts at startup, so the first working setup mostly means reading the docs.