Typr ghcr.io/max-prime-math/typr:latest https://github.com/max-prime-math/typr/pkgs/container/typr bridge sh false https://github.com/max-prime-math/typr/issues https://github.com/max-prime-math/typr https://github.com/max-prime-math/typr/blob/main/docs/self-hosting.md https://typr.ca Local-first Typst, LaTeX, and Markdown workspace. The stable full image keeps projects in browser storage and needs no appdata volume. Trusted LAN/VPN use only; never expose it publicly. Typr serves a browser-local writing workspace from the self-contained full image. Projects, settings, browser Git data, and sync bindings remain in each browser origin instead of the container. The optional lite image can use fixed R2 assets or an exact read-only compiler pack. This is an unauthenticated trusted-environment application: never expose it to the public Internet; any client-side sign-in screen is not a network security boundary. Plain LAN HTTP has reduced secure-context/PWA and local-folder features. Tools:Utilities http://[IP]:[PORT:8080]/ https://raw.githubusercontent.com/max-prime-math/typr/main/templates/typr.xml https://raw.githubusercontent.com/max-prime-math/typr/main/public/icons/icon-512.png --restart=unless-stopped --user=101:101 --read-only --tmpfs=/tmp:rw,nosuid,nodev,noexec,size=33554432 --cap-drop=ALL --security-opt=no-new-privileges:true --pids-limit=64 --memory=256m --memory-swap=256m --cpus=1 2026-08-10 2026-08-10: Document private host-level Tailscale Serve and prohibit the incompatible per-container Tailscale hook. False Use only on a trusted machine, LAN, or private VPN. Never expose this unauthenticated self-hosted application to the public Internet. For Tailscale, keep the container's Use Tailscale switch off and use host-level Tailscale Serve; never use Funnel. Plain HTTP on a LAN address is not a secure context and loses service-worker/PWA and local-folder capabilities; use trusted HTTPS for cross-device access. Browser data is isolated by exact scheme, host, and port, so export a backup before changing the URL. 8080 local