Skip to content

Kaneo - use a single application service instead of two (replicate Kaneo configuration) - #343

Merged
crypt0rr merged 3 commits into
tailscale-dev:mainfrom
DimitriHautot:update-kaneo-to-single-container
Oct 7, 2026
Merged

crypt0rr merged 3 commits into
tailscale-dev:mainfrom
DimitriHautot:update-kaneo-to-single-container

Conversation

@DimitriHautot

@DimitriHautot DimitriHautot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Kaneo: fix services

Description

Recently, the Kaneo application code has been merged into a single service, so no distinct frontend + backend anymore, just one service.
Official documentation here.

Related Issues

  • None.

Verification

Edited the.env file:

  • added value for TS_AUTHKEY
  • set my own tailnet in the KANEO_CLIENT_URL
  • generated a random value for AUTH_SECRET

Then docker compose up
image
image

Checklist

  • I have performed a self-review of my code and followed the templates structure.
  • I have added verification that the stack works as expected.
  • I have updated necessary documentation (e.g. frontpage README.md ).
  • I have selected the correct label(s) for this PR.

Additional Context

  • None.

@jackspiering

Copy link
Copy Markdown
Collaborator

Thanks for updating Kaneo to the bundled image, @DimitriHautot! I tested this branch locally: Tailscale, PostgreSQL, and Kaneo all become healthy. The web UI and /api/health return 200 over HTTPS through Tailscale Serve, and creating an account works. So the approach is good.

A few things before we can merge (see CONTRIBUTING.md and the service template):

  1. Merge conflict. services/kaneo/compose.yaml now conflicts with main, which added health check comments and settings to the Kaneo services in the meantime. Please merge main again. When you resolve it, keep a single app service and add the comment # Healthcheck: defined by the image (wget against /api/health), so this file does not override it. The ghcr.io/usekaneo/kaneo image has its own HEALTHCHECK, so no healthcheck: block is needed.
  2. Service key. CONTRIBUTING asks to keep the Compose service keys tailscale and application. Please rename kaneo: to application:. The container name app-${SERVICE} is already correct.
  3. Image variable. Please use the template name IMAGE_URL instead of IMAGE_URL_SERVICE.
  4. README. Please update services/kaneo/README.md for the single container: the service names in "Configuration Overview", and a note that KANEO_CLIENT_URL must be your https://kaneo.<tailnet>.ts.net URL. The upstream docs derive the API URL from it. Mention that the container has to be recreated after you change the value.
  5. Optional cleanups:
    • Remove the unused top-level volumes: postgres_data:, because the database uses a bind mount.
    • Move the .env comments onto their own lines like in the current template.

Thanks again!

…ce into the only one, 'kaneo'.

Removed duplicate and now useless keys in .env file.
@DimitriHautot
DimitriHautot force-pushed the update-kaneo-to-single-container branch from 0043ddf to 442bfb8 Compare October 6, 2026 21:27
@DimitriHautot

Copy link
Copy Markdown
Contributor Author

Hi @jackspiering ,

Thanks for your code review. I rebased my branch and pushed a new commit with the requested changes.
I hope it will be okay; otherwise I'll fix it again...

@jackspiering

Copy link
Copy Markdown
Collaborator

Thanks for the quick update, @DimitriHautot! All five points are addressed.

I tested the branch again. All three containers become healthy, and the web UI, /api/health, and sign-up work over HTTPS through Tailscale Serve.

Two small things are left:

1. Typo in services/kaneo/.env

SERVICE=kaneok should be SERVICE=kaneo.

With the typo, the node is named kaneok.<tailnet>.ts.net. That no longer matches KANEO_CLIENT_URL, and sign-up then fails with 403 Invalid origin.

2. Markdown lint in services/kaneo/README.md

Please add a blank line below the ### .env file and ### Container image headings. You can check it with:

rumdl check --config .markdownlint.yml services/kaneo/README.md

Optional: "TailScale" → "Tailscale" in the README.

After that, this is good to merge. Thanks again!

@DimitriHautot

Copy link
Copy Markdown
Contributor Author

Hi @jackspiering ,

My bad, kaneok was my local test to not mess with my own instance of Kaneo. 😅

The linter has been applied to the README.md file, and the upper 'S' in TailScale has been lowered.

Thanks for your fast update !

@jackspiering
jackspiering requested review from crypt0rr and jackspiering and removed request for jackspiering October 6, 2026 22:02
@jackspiering

Copy link
Copy Markdown
Collaborator

@crypt0rr please have a second opinion, feel free to merge when approved.

@crypt0rr
crypt0rr merged commit b89d20f into tailscale-dev:main Oct 7, 2026
1 check passed
@DimitriHautot
DimitriHautot deleted the update-kaneo-to-single-container branch October 7, 2026 17:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants