Typr-Companion ghcr.io/max-prime-math/typr-server:latest https://github.com/max-prime-math/typr-server/pkgs/container/typr-server bridge sh false https://github.com/max-prime-math/typr-server/issues https://github.com/max-prime-math/typr-server https://github.com/max-prime-math/typr-server/blob/main/docs/companion-unraid.md https://typr.ca Optional native LaTeX, TeXpresso, and scoped workspace service for Typr. Stateless by default; one dedicated workspace can be mapped explicitly. Trusted LAN/VPN use only; never expose it publicly. Typr Companion is installed separately from the browser-local Typr PWA. It runs native latexmk/pdfLaTeX and experimental TeXpresso. On stock Unraid kernels without Landlock, the template permits an explicit stateless fallback only while no host workspace is mounted; use mutually trusted documents only. Browser projects remain authoritative. A mapped workspace still requires a working Landlock launcher and otherwise fails closed. No broad share or appdata root belongs here. The service is unauthenticated and must never be exposed to the public Internet. Tools:Utilities http://[IP]:[PORT:8484]/api/v1/status https://raw.githubusercontent.com/max-prime-math/typr/main/templates/typr-companion.xml https://raw.githubusercontent.com/max-prime-math/typr/main/public/icons/icon-512.png --restart=unless-stopped --user=1000:1000 --read-only --tmpfs=/tmp:rw,nosuid,nodev,noexec,size=536870912 --cap-drop=ALL --security-opt=no-new-privileges:true --pids-limit=256 --memory=2g --memory-swap=2g --cpus=2 2026-08-10 2026-08-10: Document host-level Tailscale Serve and prohibit the incompatible per-container Tailscale hook. Preserve the volume-free stateless fallback for stock Unraid kernels. False Use only on a trusted LAN or private VPN with mutually trusted documents. Never expose this unauthenticated service to the public Internet. Remote browser use requires a client-trusted HTTPS reverse proxy with WebSocket support and firewall/VPN restriction. For Tailscale, keep the container's Use Tailscale switch off and use host-level Tailscale Serve; never use Funnel. Stock Unraid may use the explicit volume-free stateless fallback; any mapped workspace requires working Landlock support and otherwise fails closed. 8484 https://typr.ca,https://beta.typr.ca,https://dev.typr.ca 1 unraid-workspace