Skip to content
streamneo.
Setup Guides13 min read

How to Use Docker Compose to Run a 24/7 YouTube Stream on Hetzner

Build a Compose-based YouTube stream on Hetzner, protect credentials and check whether recovery restores a healthy feed.

sn.
StreamNeoPublished 4 October 2026
Worth sharing?

A Docker Compose deployment can keep an encoder process running on a Hetzner Cloud server and restart it after some failures. That does not prove YouTube is receiving usable video and audio: after any interruption, you still need to check the source, credentials, network path and YouTube preview.

The practical approach is to treat Compose as one part of a recovery plan. You define how the process starts, keep media and configuration where container replacement will not erase them, and verify the end-to-end feed in YouTube Live Control Room before relying on it overnight.

Map the path from media to YouTube

A typical setup has four pieces: a media file or playlist, an encoder or playback application, a Hetzner Cloud host running that application in a container, and YouTube Live ingest. The encoder reads the source, packages video and audio in a format YouTube accepts, and sends the feed to the server URL using the stream key associated with your YouTube stream.

Compose describes the container and its settings; it does not create the source media or validate the remote stream. The host needs to be available, the container must be able to read its files, the encoder must produce output, and the network connection must reach YouTube. YouTube must also accept the credentials and show a usable incoming feed. A problem at any link can leave you with a running container but no healthy broadcast.

Decide whether the job is to loop one file, rotate a playlist or generate a live scene. A devotional channel might loop a prepared bhajan video, while a local news channel may need scheduled items or a changing ticker. Those workflows can demand different software, file handling and checks. Confirm that the chosen encoder can perform the actual task before writing its Compose definition.

YouTube Live must be enabled for the channel. YouTube says first-time activation may take up to 24 hours, so check this well before a planned launch rather than debugging a server while waiting for channel access. See YouTube’s live-streaming activation guidance and the practical notes on how long YouTube Live activation takes.

For a recorded loop, also confirm that you have the rights and permissions needed for all included material. Technical delivery does not establish permission to broadcast music or images. Build a test using the same sort of motion and sound as the real programme: a static slide can conceal encoding or audio problems that only become obvious with music or moving footage.

Prepare the Hetzner Cloud host

Create a server in Hetzner Cloud and choose a supported operating system and region that suit your operational needs. Hetzner documents a Docker CE app based on Ubuntu 24.04 with Docker and the Compose plugin included; check Hetzner’s current Docker app documentation before following those details, as app images can change. If you use a standard image instead, install Docker Engine and the Compose plugin from their current official instructions.

There is no evidence-based universal server size for every 24/7 stream. A file-copy or lightweight playback workflow differs from software encoding with filters, overlays, high resolution or a high frame rate. Start with the actual source, settings and encoder you intend to run, then observe CPU, memory, disk activity and dropped or delayed output under that workload. Do not infer that one successful short test proves capacity for every future programme.

The trade-off is control versus operating work. A rented cloud host can keep the workload separate from your home computer and connection, but you remain responsible for host access, updates, files, configuration and monitoring. Running the encoder locally may suit you if you already have a reliable always-on machine and network, but a home power or broadband interruption can affect the stream. Neither location removes the need to verify the feed.

Review firewall rules before deployment. The encoder normally initiates an outbound connection to YouTube, so do not expose an inbound streaming port unless your chosen architecture specifically needs one. Keep administration access limited to trusted sources where practical, and use Hetzner’s official firewall documentation to understand what a rule allows. A firewall that is too restrictive can also block your own maintenance access, so keep a tested route for administration.

Plan where the source files and configuration will live. Container filesystems are replaceable; if you store the only copy of a video inside a container’s writable layer, recreating the container may lose it. Keep media and durable configuration on mounted host paths, and maintain a separate copy of valuable source material. A read-only media mount can reduce accidental changes by the encoder, provided the application does not need to modify that directory.

Package the playback process in a container

Choose an encoder image deliberately. Use an image and tag you can identify and maintain, and understand which executable, codecs and configuration format it contains. A tag that can change over time may make a future replacement behave differently. Pinning an image version improves repeatability, but you still need a process for applying security updates and testing them before they reach the live channel.

The container command must express the real workflow: select the source, set output dimensions and frame rate, configure video and audio codecs, and send the output to YouTube’s ingest endpoint. Those values depend on the encoder and the programme; do not paste a generic command into production without checking the image’s documentation. YouTube’s guidance identifies H.264 video and AAC audio for its documented incorrect-format error, and recommends RTMPS for secure ingestion. Check YouTube’s encoder settings guidance and the encoder’s own supported options.

Keep persistent inputs outside the image. A Compose bind mount can make a host media directory visible at a path such as /media inside the container. Configuration can be mounted separately, with permissions appropriate to the user running the encoder. Test those paths with the container’s actual user: a file visible to a host administrator may still be unreadable to a less-privileged process in the container.

Do not assume that a process staying alive means it is making progress. Some encoders exit when input disappears; others may remain open while failing to advance or while sending malformed output. Learn what the selected application logs on source errors, connection loss and reconnection. Where possible, use application-level checks for progress or output health in addition to Docker’s process status.

Compose is useful because the service definition can be reviewed and repeated. It is not a substitute for understanding the command. Keep a copy of the image name, mount paths, startup command and required configuration in a controlled project directory, then test the service with non-production credentials or a planned test stream before depending on it.

Define services and restart behaviour in Compose

A minimal illustrative structure looks like this:

services:
  streamer:
    image: your-encoder-image:your-pinned-tag
    command: ["your-encoder", "--config", "/config/stream.conf"]
    restart: unless-stopped
    volumes:
      - ./media:/media:ro
      - ./config:/config:ro

This is a framework, not a tested deployment. Replace the image, command, configuration path and secret handling with values supported by the selected encoder. The restart policy tells Docker when to try starting a stopped container again; it does not confirm that the source is readable, the output format is accepted, the stream key is valid or YouTube is showing video.

A restart policy is still useful for a process that exits unexpectedly. unless-stopped also means a deliberate stop by an operator should not be undone simply because Docker restarts. Choose a policy that matches how you administer the channel, and test what happens after the process exits and after the host reboots. Do not describe either test as proof of continuous end-to-end service.

Use a Compose production override or a separate production file if you need to distinguish development settings from the live deployment. Keep the definition understandable: explicit image, command, mounts and restart behaviour are easier to troubleshoot than hidden defaults. Docker’s Compose production guidance explains common deployment practices. Check the effect of changes before applying them: Docker notes that docker compose restart does not apply changed Compose configuration or environment values. Recreate or update the service as appropriate when settings change.

Useful operator commands include docker compose up -d to start or reconcile the stack, docker compose ps to inspect service status, and docker compose logs -f streamer to follow logs for the named service. A status of “running” is only a process-level observation. Pair it with encoder output and YouTube’s own ingest preview when investigating a break.

Provide media and YouTube credentials safely

Create or select the stream in YouTube Studio and copy the server URL and stream key into the encoder configuration. Treat the key like a password: do not put a real one in a public repository, screenshot, support post or diagnostic log. If it is exposed, reset it in YouTube Live Control Room and update the deployment with the replacement. YouTube’s stream setup instructions explain where stream details are managed.

Compose secrets can provide a file to a service, but the way secrets are provisioned depends on the platform and Compose environment. Do not assume that adding a secrets stanza alone has made a key safe on a single cloud host. Restrict access to the host file that contains the key, keep it out of version control, and ensure the encoder reads it without echoing its contents in logs. If the encoder only accepts an environment variable or configuration file, protect the source file and avoid showing its value in shell history or command output.

The stream URL is not the same thing as the stream key. If you are unsure which value belongs in each field, the difference between YouTube’s stream key and stream URL is worth checking before a test. A typo in either can prevent ingest even though the container starts normally.

Keep the media path and credential path separate. That makes it easier to replace a video without changing the secret, or rotate a secret without rebuilding an image that contains your programme files. Restrict write permissions to the people and services that need them. Back up the configuration securely, not by copying a live key into an unprotected notebook or shared folder.

Deploy and verify the YouTube feed

Before bringing up the service, confirm the channel is eligible and live streaming is enabled, the source file exists at the mounted path, the encoder configuration parses, and the stream key is current. Start the service, inspect docker compose ps, and read the encoder logs for input, encoding and connection errors. If the process exits, use the logs to identify whether the source, permissions, command or network caused the failure rather than repeatedly restarting without diagnosis.

Open YouTube Live Control Room and check that the incoming preview appears and that the health status is acceptable. Listen to the audio, watch for motion and artefacts, and confirm the programme from the public watch page when appropriate. YouTube’s stream-health guidance is more meaningful than a container status because it tests the receiving side of the path. A green-looking local process cannot tell you that the right event is receiving the signal.

Test with the conditions that matter for the channel. A music stream should be checked for continuous audio and any silent gaps; an ambience channel should be checked for its intended picture and sound; a news loop should be checked after a playlist transition. If you operate a lofi or recorded programme, content suitability is a separate concern from delivery; see the discussion of AI-generated music in a continuous lofi stream.

YouTube recommends upload headroom of 20 per cent above the total stream bitrate in its streaming tips. Include the primary and backup stream rates where applicable when considering the connection. That recommendation is not a promise that a particular Hetzner server or network route will perform well; observe the real connection and YouTube preview during a representative test. YouTube also recommends RTMPS, so use the secure ingest option offered for your stream when supported by the encoder.

If the preview does not appear, work from both ends. Check the encoder log for authentication or connection errors, verify the URL and key in the intended stream, and inspect host connectivity and firewall rules. Then check Live Control Room again. For a more detailed case where a local application claims to stream but YouTube reports otherwise, use this encoder-disconnected troubleshooting guide.

Monitor failures beyond container restarts

A robust operating routine separates process recovery from feed recovery. Docker can retry a process that has stopped, but it may not notice a frozen source, a stream that contains no sound, an invalid key, an ingest problem or an encoder that is alive but producing unusable output. After a restart, confirm that the media has resumed at the expected point, the encoder is sending, and YouTube’s preview and health status have recovered.

Define what you will check and how you will be alerted. At minimum, know how to inspect the Compose service, read its logs, reach the host and open Live Control Room. For an unattended channel, use monitoring that can tell you about both host/process failures and the actual YouTube feed; a process-only alert leaves important failures invisible. The unattended-stream monitoring checklist offers useful operational questions even if your channel is not aimed at children.

Plan a recovery sequence that a second person could follow: check the host, inspect logs, verify the file and permissions, confirm network access, validate the current key, restart only when appropriate, and inspect YouTube’s preview. Record what a normal log and normal preview look like. Repeatedly restarting a healthy process can interrupt a working feed, while repeatedly restarting a process with a bad key will not repair the credential.

If the channel cannot tolerate an interruption, an independent backup encoder or separately tested source path may be appropriate. A second process in the same container or on the same host is not necessarily independent: it may share power, network, source storage and credentials. YouTube advises testing encoder failover for event workflows. Verify how the backup takes over and confirm the receiving preview during a planned test; do not assume that a backup configuration is working merely because it exists.

Long broadcasts need a separate duration plan. YouTube says streams under 12 hours are automatically archived; that statement does not establish that one live event can run indefinitely or what happens after that duration. If your schedule depends on a very long continuous event, check YouTube’s current guidance and test a segmentation or restart plan rather than relying on an assumption about archive behaviour.

For a file-based channel, the recurring burden may be keeping a host, mounted media and encoder process healthy through the night. StreamNeo addresses that specific operational burden by turning an uploaded video into a YouTube live stream that runs with your computer switched off, so there is no host Compose stack for you to maintain.

Before committing, compare the operating options on the pricing page. When the file and channel are ready, start free — 24-hour trial, no card.

FAQ

Does restart: unless-stopped guarantee a 24/7 YouTube stream?

No. It is a Docker policy for restarting a stopped container under the policy’s conditions. It cannot establish that the source, credentials, network, encoder output or YouTube ingest is healthy, so check the incoming preview after recovery.

Do I need to open an inbound port on the Hetzner server?

For the usual arrangement, the encoder initiates an outbound connection to YouTube, so an inbound streaming listener is not normally needed. Keep only the access required for administration, and check the requirements of your chosen encoder architecture before applying firewall rules.

Can I use the same stream key after a restart?

A restart does not itself require a new key. If the key was changed or exposed, update the protected configuration and confirm that YouTube accepts the new value in Live Control Room.

Can one YouTube live event run forever?

Do not assume that it can. YouTube documents automatic archiving for streams under 12 hours, but the evidence here does not settle behaviour beyond that; check current official guidance and plan how to segment or restart a long programme.

YOU’VE REACHED THE END

Keep the ideas coming.

More guides, useful tools and a little help for your next broadcast.

Back to the journal ↗
YOUR NEXT READ

A little more to explore.

More Setup Guides guides ↗ · All topics ↗