Install

One compose file. Postgres and you.

Answer a few questions and copy the .env. Secrets are generated in your browser and never leave it. Everything else has a sensible default you can change later.

Where it runs
Attachments
Credentials
Sign-in
Generated with crypto.getRandomValues, here, in this tab.
.env
 
Commands
 

Then

  1. 1

    Clone and configure

    Clone the repo, fill in the generated .env below. Three values matter: POSTGRES_PASSWORD, the matching DATABASE_URL, and AUTH_SECRET.

  2. 2

    docker compose up -d

    One app container and Postgres. Migrations run on start. Add --profile vault for the Bitwarden sidecar when you are ready for it.

  3. 3

    Create the first administrator

    The first visit to APP_URL opens a one-time setup screen. No default password, nothing to rotate.

  4. 4

    Put it behind a tunnel

    Set APP_BIND=127.0.0.1 and publish the hostname through cloudflared, Caddy, or nginx. APP_URL must be the address people actually type.