Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion services/gitsave/compose.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ services:
- PGID=1000
- TZ=${TZ}
- JWT_SECRET=${JWT_SECRET:?Set JWT_SECRET in .env}
- DISABLE_AUTH=${DISABLE_AUTH:?error}
- DISABLE_AUTH=${DISABLE_AUTH:-false}
- ENCRYPTION_SECRET=${ENCRYPTION_SECRET:?Set ENCRYPTION_SECRET in .env}
volumes:
- ./${SERVICE}-data/gitsave:/app/data
Expand Down
Empty file modified services/kitchenowl/.env
100755 → 100644
Empty file.
Empty file modified services/kitchenowl/compose.yaml
100755 → 100644
Empty file.
1 change: 1 addition & 0 deletions services/mailpit/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@ This stack runs Mailpit with a Tailscale sidecar, as described in [the standard

## Deviations from the standard setup

- **Service name.** The application service is called `mailpit`, not `application`.
- **Published SMTP port.** The `ports` block is active. It publishes TCP port `25` of the Docker host and forwards it to port `1025` of Mailpit, so that mail servers on the internet can deliver messages. The web interface stays on your Tailnet.
- **Recipient filter.** `MP_SMTP_ALLOWED_RECIPIENTS` only accepts mail for the recipients that match `MAIL_DOMAIN_REGEX`.
- **Retention.** `compose.yaml` passes the limits from `.env` to Mailpit, which deletes messages beyond them.
Expand Down
8 changes: 3 additions & 5 deletions services/mattermost/.env
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ SERVICE=mattermost
IMAGE_URL=mattermost/mattermost-team-edition:latest

# Network Configuration
SERVICEPORT=443 ## The webport will be exposed to the tailnet. Change if needed.
SERVICEPORT=8065 ## Host port of the optional ports block in compose.yaml. Mattermost listens on 8065 inside the container.
DNS_SERVER=9.9.9.9 # Preferred DNS server for Tailscale. Uncomment the "dns:" section in compose.yaml to enable.

# Tailscale Configuration
Expand All @@ -25,10 +25,8 @@ DOMAIN=mattermost.example.com
MM_SERVICESETTINGS_SITEURL=https://${DOMAIN}
## also relevant if you want to use Funnel

## Default APP_PORT=8065 for Mattermost also see serve.json
## Exposed ports to the host. Inside the container 80, 443 and 8443 will be used
HTTPS_PORT=${SERVICEPORT}
HTTP_PORT=80
## Mattermost listens on 8065 inside the container (see serve.json).
## Mattermost Calls media uses UDP and TCP port 8443 by default. CALLS_PORT is published by the optional ports block in compose.yaml. Keep it equal to the port that Calls uses.
CALLS_PORT=8443

# Mattermost settings
Expand Down
7 changes: 3 additions & 4 deletions services/mattermost/compose.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -35,10 +35,9 @@ services:
cap_add:
- net_admin # Tailscale requirement
#ports:
# - ${HTTP_PORT}:${HTTP_PORT} # Binding the service port to the local network - may be removed if only exposure to your Tailnet is required
# - ${HTTPS_PORT}:${HTTPS_PORT} # Binding the service port to the local network - may be removed if only exposure to your Tailnet is required
# - ${CALLS_PORT}:${CALLS_PORT}/udp
# - ${CALLS_PORT}:${CALLS_PORT}/tcp
# - 0.0.0.0:${SERVICEPORT}:8065 # Binding the service port to the local network - may be removed if only exposure to your Tailnet is required
# - ${CALLS_PORT}:${CALLS_PORT}/udp # Mattermost Calls media - only needed when you use Calls
# - ${CALLS_PORT}:${CALLS_PORT}/tcp # Mattermost Calls media - only needed when you use Calls
# If any DNS issues arise, use your preferred DNS provider by uncommenting the config below
#dns:
# - ${DNS_SERVER}
Expand Down
1 change: 0 additions & 1 deletion services/metube/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,6 @@ Nothing beyond the [Quick Start](../../README.md#quick-start).

## Deviations from the standard setup

- **MagicDNS is enabled.** The stack sets `TS_ACCEPT_DNS=true`, so the containers resolve names through MagicDNS and not through Docker's DNS.
- **Download folder.** The downloads are in `./downloads`, not in a `./metube-data` folder.

## First run
Expand Down
2 changes: 1 addition & 1 deletion services/metube/compose.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ services:
- TS_USERSPACE=false
- TS_ENABLE_HEALTH_CHECK=true # Enable healthcheck endpoint: "/healthz"
- TS_LOCAL_ADDR_PORT=127.0.0.1:41234 # The <addr>:<port> for the healthz endpoint
- TS_ACCEPT_DNS=true # MagicDNS is enabled for this service. Remove this line to use Docker DNS only.
#- TS_ACCEPT_DNS=true # Uncomment only if the service must resolve MagicDNS names - this replaces Docker DNS, so Compose service names no longer resolve
- TS_AUTH_ONCE=true
configs:
- source: ts-serve
Expand Down
2 changes: 1 addition & 1 deletion services/netbox/.env
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ REDIS_CACHE_INSECURE_SKIP_TLS_VERIFY=false
REDIS_CACHE_PASSWORD=${SUPER_SECRET:?Set SUPER_SECRET in .env}REDIS
REDIS_CACHE_SSL=false
REDIS_DATABASE=0
REDIS_HOST=${SERVICE}-rediscache
REDIS_HOST=${SERVICE}-redis
REDIS_INSECURE_SKIP_TLS_VERIFY=false
REDIS_PASSWORD=${SUPER_SECRET:?Set SUPER_SECRET in .env}REDIS
REDIS_SSL=false
Expand Down
2 changes: 2 additions & 0 deletions services/netbox/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,8 @@ Open the web interface and log in with that account.

If you are upgrading, set `SUPER_SECRET` to the value from your previous `.env`, including the old default if you never changed it. Otherwise NetBox cannot log in to the existing database.

Earlier versions of this stack sent background jobs to the `redis-cache` container. They now use the `redis` container. Jobs that were still queued in `redis-cache` are not moved to `redis`.

## Links

- [NetBox documentation](https://netboxlabs.com/docs/netbox/)
Expand Down
1 change: 1 addition & 0 deletions services/netbox/config/configuration.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# Copied from netbox-docker (https://github.com/netbox-community/netbox-docker, Apache-2.0).
####
## We recommend to not edit this file.
## Create separate files to overwrite the settings.
Expand Down
1 change: 1 addition & 0 deletions services/netbox/config/extra.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# Copied from netbox-docker (https://github.com/netbox-community/netbox-docker, Apache-2.0).
####
## This file contains extra configuration options that can't be configured
## directly through environment variables.
Expand Down
1 change: 1 addition & 0 deletions services/netbox/config/ldap/extra.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# Copied from netbox-docker (https://github.com/netbox-community/netbox-docker, Apache-2.0).
####
## This file contains extra configuration options that can't be configured
## directly through environment variables.
Expand Down
1 change: 1 addition & 0 deletions services/netbox/config/ldap/ldap_config.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# Copied from netbox-docker (https://github.com/netbox-community/netbox-docker, Apache-2.0).
from importlib import import_module
from os import environ

Expand Down
1 change: 1 addition & 0 deletions services/netbox/config/logging.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# Copied from netbox-docker (https://github.com/netbox-community/netbox-docker, Apache-2.0).
# # Remove first comment(#) on each line to implement this working logging example.
# # Add LOGLEVEL environment variable to netbox if you use this example & want a different log level.
# from os import environ
Expand Down
1 change: 1 addition & 0 deletions services/netbox/config/plugins.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# Copied from netbox-docker (https://github.com/netbox-community/netbox-docker, Apache-2.0).
# Add your plugins and plugin settings here.
# Of course uncomment this file out.

Expand Down
4 changes: 2 additions & 2 deletions services/open-webui/.env
Original file line number Diff line number Diff line change
Expand Up @@ -17,9 +17,9 @@ TS_AUTHKEY=
# Open WebUI Configuration
# Point to your Ollama instance - can be local or remote.
# Examples:
# Ollama on same Docker host: http://host.docker.internal:11434
# Ollama on same Docker host: http://host.docker.internal:11434 (Ollama must listen beyond loopback, see README)
# Ollama on LAN: http://192.168.1.x:11434
# Ollama over Tailnet: http://100.x.x.x:11434
# Ollama over Tailnet: http://100.x.x.x:11434 (also the Tailscale IP of the Ollama stack in this repository)
# Leave blank to configure a different provider (e.g. OpenAI) via the UI.
OLLAMA_BASE_URL=http://host.docker.internal:11434
# Random secret key for session security. Generate with: openssl rand -hex 32
Expand Down
5 changes: 3 additions & 2 deletions services/open-webui/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,14 +19,15 @@ Set these values in `.env`:

- **`WEBUI_SECRET_KEY`.** A long random value that Open WebUI uses to sign the login tokens.
- **`OLLAMA_BASE_URL`.** The address of your Ollama instance:
- On the Docker host: `http://host.docker.internal:11434`
- On the Docker host: `http://host.docker.internal:11434`. A native Ollama listens only on `127.0.0.1` by default, which containers cannot reach. Set `OLLAMA_HOST=0.0.0.0:11434` for it. This makes Ollama reachable on every network of the host, so limit access with a firewall.
- In the [Ollama stack](../ollama/) of this repository: `http://<Tailscale IP address of ollama>:11434`. That stack runs on its own Tailnet device and does not publish port `11434` on the Docker host.
- On a machine in your local network: `http://<local-ip>:11434`
- On another Tailnet device: `http://<Tailscale IP address>:11434`
- Leave it empty to add another provider, such as OpenAI, in the web interface later.

## Deviations from the standard setup

None.
- **Host gateway.** The `tailscale` container has an `extra_hosts` entry that maps `host.docker.internal` to the gateway of the Docker host, so that Open WebUI can reach an Ollama instance on the host. The `application` container shares the network of `tailscale`, so the entry is set there.

## First run

Expand Down
2 changes: 2 additions & 0 deletions services/open-webui/compose.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,8 @@ services:
- /dev/net/tun:/dev/net/tun # Network configuration for Tailscale to work
cap_add:
- net_admin # Tailscale requirement
extra_hosts:
- host.docker.internal:host-gateway # Lets Open WebUI reach an Ollama instance on the Docker host - the application shares this network
#ports:
# - 0.0.0.0:${SERVICEPORT}:${SERVICEPORT} # Binding the service port to the local network - may be removed if only exposure to your Tailnet is required
# If any DNS issues arise, use your preferred DNS provider by uncommenting the config below
Expand Down
2 changes: 1 addition & 1 deletion services/rustdesk-server/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ Nothing beyond the [Quick Start](../../README.md#quick-start).
## Deviations from the standard setup

- **Two application containers.** The `application` container runs the ID server `hbbs`, and the `hbbr` container runs the relay server. Both use the network of the `tailscale` container.
- **No web interface.** The clients connect directly to the ports of the device on your Tailnet. The Tailscale Serve configuration from the template has no use here.
- **No Tailscale Serve.** RustDesk has no web interface. The clients connect directly to the ports of the device on your Tailnet, so the stack has no Serve configuration.
- **Relay setting.** `ALWAYS_USE_RELAY` in `.env` is `N`. Set it to `Y` to send all connections through the relay server.

## First run
Expand Down
13 changes: 0 additions & 13 deletions services/rustdesk-server/compose.yaml
Original file line number Diff line number Diff line change
@@ -1,12 +1,3 @@
configs:
ts-serve:
content: |
{"TCP":{"443":{"HTTPS":true}},
"Web":{"$${TS_CERT_DOMAIN}:443":
{"Handlers":{"/":
{"Proxy":"http://127.0.0.1:80"}}}},
"AllowFunnel":{"$${TS_CERT_DOMAIN}:443":false}}

services:
# Make sure you have updated/checked the .env file with the correct variables.
# Every variable used in this file must be defined there.
Expand All @@ -18,15 +9,11 @@ services:
environment:
- TS_AUTHKEY=${TS_AUTHKEY}
- TS_STATE_DIR=/var/lib/tailscale
- TS_SERVE_CONFIG=/config/serve.json # Tailscale Serve configuration to expose the web interface on your local Tailnet - remove this line if not required
- TS_USERSPACE=false
- TS_ENABLE_HEALTH_CHECK=true # Enable healthcheck endpoint: "/healthz"
- TS_LOCAL_ADDR_PORT=127.0.0.1:41234 # The <addr>:<port> for the healthz endpoint
#- TS_ACCEPT_DNS=true # Uncomment only if the service must resolve MagicDNS names - this replaces Docker DNS, so Compose service names no longer resolve
- TS_AUTH_ONCE=true
configs:
- source: ts-serve
target: /config/serve.json
volumes:
- ./config:/config # Config folder used to store Tailscale files - you may need to change the path
- ./ts/state:/var/lib/tailscale # Tailscale requirement - you may need to change the path
Expand Down
2 changes: 1 addition & 1 deletion services/seafile/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ MariaDB and Seafile apply the database passwords only at the first start.

## Deviations from the standard setup

- **Service names.** The application service is called `seafile`, not `application`, and its container has no fixed name.
- **Service names.** The application service is called `seafile`, not `application`, and its container is named `app-seafile`.
- **Extra containers.** The stack runs `db` (MariaDB) and `memcached`. They use the default Compose network, and Seafile reaches them by their service name through Docker's DNS. Keep `TS_ACCEPT_DNS` disabled, because MagicDNS cannot resolve these names.
- **Images are set in `.env`.** The stack does not use `IMAGE_URL`. `SEAFILE_IMAGE`, `SEAFILE_DB_IMAGE`, and `SEAFILE_MEMCACHED_IMAGE` select the images. Keep the Memcached image on a Debian-based tag, because its health check needs `perl`, which Alpine tags lack.
- **Small deployment.** The stack is meant for a handful of users. It leaves out the SeaDoc, Collabora, and notification servers, and it uses Memcached instead of Redis.
Expand Down
29 changes: 28 additions & 1 deletion services/searxng/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,8 @@ Set these values in `.env`. Compose stops with an error if one of them is empty.

## Deviations from the standard setup

- **Settings file.** This directory contains `searxng/settings.yml`, a copy of the [default settings of SearXNG](https://github.com/searxng/searxng/blob/master/searx/settings.yml). The stack mounts the folder at `/etc/searxng`. Edit that file to change the engines and other settings.
- **Settings file.** This directory contains `searxng/settings.yml`, which only sets `use_default_settings: true` and the secret key. Every other setting comes from the [default settings of SearXNG](https://github.com/searxng/searxng/blob/master/searx/settings.yml). The stack mounts the folder at `/etc/searxng`. Add your own settings to that file; see the [settings documentation](https://docs.searxng.org/admin/settings/settings.html). After you edit the file, run `docker compose restart application`.
- **Folder ownership.** `FORCE_OWNERSHIP=false` in `compose.yaml` stops SearXNG from making its own user the owner of the `searxng` folder. The folder stays yours, so you can edit `settings.yml` without `sudo`, and `git pull` can update it. At each start, SearXNG logs a warning that the folder `is not owned by "searxng:searxng"`. This is expected. Do not change the owner to match, because `git pull` then fails.
- **Extra container.** The stack runs a `valkey` container on the default Compose network. `SEARXNG_VALKEY_URL` in `.env` points SearXNG at it, because the default settings do not use Valkey. Keep `TS_ACCEPT_DNS` disabled, because MagicDNS cannot resolve the name `valkey`.
- **Reduced privileges.** Both containers drop all capabilities and add back only the few that they need.
- **Log size.** Both containers limit their log to one file of 1 MB.
Expand All @@ -33,6 +34,32 @@ Set these values in `.env`. Compose stops with an error if one of them is empty.

Nothing to set up. Open the web interface and search. SearXNG has no login.

## Upgrading

Earlier versions of this stack had a full copy of the SearXNG settings file. Its list of engines contained modules that upstream has since removed, so SearXNG logged `Cannot load engine` errors. The file now only overrides the secret key.

Earlier versions also let SearXNG make its own user (ID `977`) the owner of the `searxng` folder. If you started the stack before, Git cannot replace `settings.yml`. `git pull` then stops with `unable to unlink old 'services/searxng/searxng/settings.yml': Permission denied` and leaves your clone half updated. To prevent this, take the folder back before you update your clone. Run this from the service directory:

```bash
sudo chown -R "$(id -u):$(id -g)" searxng
```

You need this only once, because the stack now sets `FORCE_OWNERSHIP=false`. If you changed `settings.yml`, also copy it to another folder and run `git restore searxng/settings.yml`, and move your own settings into the new file after the update.

If `git pull` already stopped with that error, run the `chown` command, and then finish the update with these commands. They keep your own changes, such as the values in `.env`:

```bash
git stash
git reset --hard origin/main
git stash pop
```

If you ran `git stash` before the pull, run `git stash pop` once more.

In both cases, run `docker compose up -d` after the update. Compose recreates the `application` container. It then reads the new file and no longer takes the folder.

SearXNG now uses its default request method, `GET`, so a search query shows in the address bar and in the browser history. The old file set `POST`. To keep `POST`, add the line `method: "POST"` under the existing `server:` key in `settings.yml`.

## Links

- [SearXNG documentation](https://docs.searxng.org/)
Expand Down
1 change: 1 addition & 0 deletions services/searxng/compose.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,7 @@ services:
- SEARXNG_BASE_URL=https://${SERVICE}.${TAILNET_NAME:?Set TAILNET_NAME in .env}.ts.net/
- SEARXNG_SECRET=${SEARXNG_SECRET:?Set SEARXNG_SECRET in .env}
- SEARXNG_VALKEY_URL=${SEARXNG_VALKEY_URL}
- FORCE_OWNERSHIP=false # Leaves ./searxng owned by your user, so Git and your editor can change settings.yml - SearXNG logs an ownership warning at each start
- TZ=${TZ}
volumes:
- ./searxng:/etc/searxng:rw
Expand Down
Loading
Loading