# nexdiary, start with: docker compose up -d --build # # Then open http://:8550. The first account you create there is the operator; it needs the setup code # from the log (docker logs nexdiary) or the one you set below. services: nexdiary: build: . container_name: nexdiary restart: unless-stopped ports: # Host port on the left, container port on the right. Only this machine reaches it (127.0.0.1): put a reverse # proxy with https in front and let it forward to http://127.0.0.1:8550 (a proxy in another container: put both # in one Docker network and forward to http://nexdiary:8000). Set NEXDIARY_TRUSTED_PROXIES below to the proxy. # To reach nexdiary directly from your home network instead, write "8550:8000", but only for a network you trust: # without https, passwords and codes cross it in the clear. - "127.0.0.1:8550:8000" # The container needs nothing it is not given: it may not gain rights later, and starts with only what the # entrypoint needs to set the ownership of /data (CHOWN, DAC_READ_SEARCH) and to drop from root to the user # nexdiary (SETUID, SETGID). nexdiary itself runs as that user, with none. security_opt: - no-new-privileges:true cap_drop: - ALL cap_add: - CHOWN - DAC_READ_SEARCH - SETUID - SETGID volumes: # Database, logs, backups and the operator's own languages. # A local disk, never an SMB or NFS share: SQLite's locking does not work reliably over network filesystems. - ./data:/data environment: # Who should own the files in the data directory. The container fixes the permissions itself on startup. PUID: 1000 PGID: 1000 TZ: Europe/Berlin # The address people use to reach nexdiary, for invitation links and the OIDC redirect. Can also be set in the # interface. # NEXDIARY_PUBLIC_URL: https://diary.example.com # Behind a reverse proxy: its address, so that the brake against password guessing sees the real sender. # NEXDIARY_TRUSTED_PROXIES: 172.16.0.0/12 # The code the first account needs. Without it nexdiary makes one at every start until it is set up and # writes it to the log: docker logs nexdiary # NEXDIARY_SETUP_TOKEN: choose-a-long-one