diff --git a/services/kaneo/.env b/services/kaneo/.env index da2f2314..e5ed3255 100644 --- a/services/kaneo/.env +++ b/services/kaneo/.env @@ -3,15 +3,16 @@ #COMPOSE_PROJECT_NAME= # Optional: only use when running multiple deployments on the same infrastructure. # Service Configuration -SERVICE=kaneo # Service name (e.g., adguard). Used as hostname in Tailscale and for container naming (app-${SERVICE}). -IMAGE_URL_BACKEND=ghcr.io/usekaneo/api:latest # Docker image URL from container registry (e.g., adguard/adguard-home). -IMAGE_URL_FRONTEND=ghcr.io/usekaneo/web:latest # Docker image URL from container registry (e.g., adguard/adguard-home). -IMAGE_URL_DATABASE=postgres:16-alpine # Docker image URL from container registry (e.g., adguard/adguard-home). +# Service name (e.g., adguard). Used as hostname in Tailscale and for container naming (app-${SERVICE}). +SERVICE=kaneo +# Docker image URL from container registry (e.g., adguard/adguard-home). +IMAGE_URL=ghcr.io/usekaneo/kaneo:latest +# Docker image URL from container registry (e.g., adguard/adguard-home). +IMAGE_URL_DATABASE=postgres:16-alpine # Network Configuration -# SERVICEPORT= -SERVICEPORT_FRONTEND=5173 -SERVICEPORT_BACKEND=1337 +# Ports to expose to local network. Uncomment the "ports:" section in compose.yaml to enable. +SERVICEPORT=5173 SERVICEPORT_DATABASE=5432 DNS_SERVER=9.9.9.9 # Preferred DNS server for Tailscale. Uncomment the "dns:" section in compose.yaml to enable. @@ -28,7 +29,6 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim # Any Container environment variables are declared below. See https://docs.docker.com/compose/how-tos/environment-variables/ # Kaneo Configuration -KANEO_API_URL="https://kaneo..ts.net/api" KANEO_CLIENT_URL="https://kaneo..ts.net" # AUTH Configuration diff --git a/services/kaneo/README.md b/services/kaneo/README.md index 82ce868c..4b6b7213 100644 --- a/services/kaneo/README.md +++ b/services/kaneo/README.md @@ -16,4 +16,16 @@ This Docker Compose configuration sets up **[Kaneo](https://github.com/usekaneo/ ## Configuration Overview -In this setup, the `tailscale-kaneo` service runs Tailscale, which manages secure networking for the Kaneo service. The `kaneo` service uses the Tailscale network stack via Docker's `network_mode: service:tailscale` configuration. This ensures that Kaneo’s web interface is only accessible through the Tailscale network (or locally, if preferred), adding a strong layer of privacy and security to your self-hosted project management platform. +In this setup, the `tailscale-kaneo` service runs Tailscale, which manages secure networking for the Kaneo service. The `application` service uses the Tailscale network stack via Docker's `network_mode: service:tailscale` configuration. This ensures that Kaneo’s web interface is only accessible through the Tailscale network (or locally, if preferred), adding a strong layer of privacy and security to your self-hosted project management platform. + +### .env file + +In the `.env` file, you must configure the `KANEO_CLIENT_URL` variable to match your own tailnet, like this: `https://kaneo..ts.net`. The [upstream docs](https://kaneo.app/docs/core/installation/docker-compose) derive the API URL from it. The container has to be recreated after you change the value. + +You also have to provide two different secrets (`openssl rand -hex 32`), for the `AUTH_SECRET` and `DB_PASSWORD` variables. + +Finally, obtain an authentication key from Tailscale and set it as the `TS_AUTHKEY` variable. + +### Container image + +Since [release v2.7.0](https://github.com/usekaneo/kaneo/releases/tag/v2.7.0), the Kaneo service is composed of a single image, instead of two previously (web and backend). More information on the [Upgrade Kaneo](https://kaneo.app/docs/core/operations/upgrades) upstream documentation. diff --git a/services/kaneo/compose.yaml b/services/kaneo/compose.yaml index ce9f5496..5d4775ea 100644 --- a/services/kaneo/compose.yaml +++ b/services/kaneo/compose.yaml @@ -4,8 +4,7 @@ configs: {"TCP":{"443":{"HTTPS":true}}, "Web":{"$${TS_CERT_DOMAIN}:443": {"Handlers":{ - "/api/":{"Proxy":"http://localhost:${SERVICEPORT_BACKEND}/api/"}, - "/":{"Proxy":"http://localhost:${SERVICEPORT_FRONTEND}"} + "/":{"Proxy":"http://localhost:${SERVICEPORT}"} }}}, "AllowFunnel":{"$${TS_CERT_DOMAIN}:443":false}} @@ -70,11 +69,11 @@ services: start_period: 30s # Time to wait before starting health checks restart: always - # Backend (API) - backend: - image: ${IMAGE_URL_BACKEND} # Image to be used + # Application + application: + image: ${IMAGE_URL} # Image to be used network_mode: service:tailscale # Sidecar configuration to route the service through Tailscale - container_name: app-${SERVICE}-backend # Name for local container management + container_name: app-${SERVICE} # Name for local container management env_file: - .env environment: @@ -86,26 +85,3 @@ services: condition: service_healthy # Healthcheck: defined by the image (wget against /api/health), so this file does not override it. restart: always - - # Frontend (Web) - frontend: - image: ${IMAGE_URL_FRONTEND} # Image to be used - network_mode: service:tailscale # Sidecar configuration to route the service through Tailscale - container_name: app-${SERVICE}-frontend # Name for local container management - env_file: - - .env - depends_on: - tailscale: - condition: service_healthy - backend: - condition: service_started - healthcheck: - test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:5173/"] # Check if the service is responding - interval: 1m # How often to perform the check - timeout: 10s # Time to wait for the check to succeed - retries: 3 # Number of retries before marking as unhealthy - start_period: 30s # Time to wait before starting health checks - restart: always - -volumes: - postgres_data: