Docker did not invent Usenet automation, but it standardized how homelabs ship SABnzbd beside Sonarr without fighting dependency hell. A Docker Usenet stack is a set of containers with shared volumes, consistent user IDs, and published ports on a host that stays powered overnight. Provider choice sits outside those containers: you still paste SSL NNTP settings into SABnzbd whether it runs bare metal or in Compose.
Done well, Docker makes upgrades reversible and backups portable. Done poorly, permission errors masquerade as "Usenet completion is broken." This guide covers typical roles, networking, provider settings, and ops habits that keep queues moving.
Typical compose roles in a media stack
Most stacks include a downloader (SABnzbd for mainstream *arr homes, NZBGet when RAM is tight), Prowlarr to sync indexers, Sonarr and Radarr for TV and movies, and sometimes Lidarr or Readarr. Optional VPN sidecars route only selected containers through a tunnel when you want exit IP separation without moving NNTP off SSL.
Each service gets persistent appdata mounts so database state survives image updates. Download volumes are often split into incomplete and complete trees so par expand does not fill root filesystems. *arr apps map those complete paths identically so imports succeed.
Networking, ports, and reverse proxies
Publish SABnzbd's web UI on a host port or behind Traefik, Caddy, or nginx with TLS. Keep API keys secret; do not expose unauthenticated UIs to WAN. Internal DNS names let Sonarr reference http://sabnzbd:8080 inside the compose network while you browse https://sab.example.com externally.
VPN containers (Gluetun and similar) change default routes for attached services. Measure latency after enabling them: some setups add little overhead, others starve NNTP if misconfigured. SSL to the provider on port 563 remains required regardless of VPN container presence.
Paths, PUID/PGID, and the permission trap
LinuxServer and hotio images expect PUID and PGID environment variables matching ownership on bind mounts. If SABnzbd writes as root but Sonarr reads as abc, imports fail with "permission denied" and newcomers blame retention. Fix ownership once on the host, then recreate containers with matching IDs.
Use one shared downloads tree with clear subfolders rather than duplicating mounts differently in each container. Document paths in a README you future-you will read after six months.
Provider settings inside containers
NNTP configuration is identical to bare metal: primary server priority 0, optional fill on a different backbone at priority 1, SSL enabled, connection cap from the provider status page. Docker does not magically merge Highwinds twins into fill: Newshosting plus UsenetServer still hits the same pool twice.
Store provider passwords in SABnzbd's encrypted config on appdata volumes you back up. Rotate credentials if you restore appdata to a new host. Test with a manual NZB after every compose change before unleashing Sonarr season packs.
SABnzbd vs NZBGet in Docker
SABnzbd images dominate examples and Unraid templates. Choose NZBGet images when the host is a low-memory ARM SBC and you accept translating more Sonarr forum posts. Do not run both downloaders to the same complete folder without careful category separation; pick one.
Pin image tags or digests instead of floating latest in production homelabs. Upstream updates occasionally change Python dependencies or default paths. Read release notes before clicking update all in Portainer.
Ops: backups, disk, and upgrades
Back up appdata directories on a schedule separate from media files. Sonarr and Radarr databases encode path logic you cannot reconstruct from NZBs alone. Monitor incomplete disk: par repair temporarily doubles space needs.
Watch provider status pages during stack migrations. If completion drops after a Docker move, verify DNS inside containers (some VPN sidecars break provider hostname resolution). Compare notes with Usenet on Unraid if you migrate from bare Unraid templates to generic compose.
FAQ
- Do I need a VPN container for Usenet?
- Optional for exit IP policy. SSL to NNTP is still mandatory for transport privacy to the provider.
- Is Gluetun the only option?
- No, but it is common. Test throughput and DNS after enabling any sidecar.
- Can I run this stack on Windows Docker?
- Fine for labs. Always-on libraries usually belong on Linux NAS or mini PC hosts.
- Why did Sonarr imports break after Docker?
- Almost always path or permissions mismatch between downloader and *arr mounts.
- Does Docker improve completion?
- No. Backbone and retention dominate; containers only change how software runs.