From 018a2b6d2a5bf5b4fafca9a476df9f4b88e750ce Mon Sep 17 00:00:00 2001 From: Dimitri Hautot <3765206+DimitriHautot@users.noreply.github.com> Date: Thu, 24 Sep 2026 22:02:00 +0200 Subject: [PATCH 1/3] Removed the frontend service definition, and turned the backend service into the only one, 'kaneo'. Removed duplicate and now useless keys in .env file. --- services/kaneo/.env | 8 ++------ services/kaneo/compose.yaml | 22 +++------------------- 2 files changed, 5 insertions(+), 25 deletions(-) diff --git a/services/kaneo/.env b/services/kaneo/.env index da2f2314..71476013 100644 --- a/services/kaneo/.env +++ b/services/kaneo/.env @@ -4,14 +4,11 @@ # Service Configuration SERVICE=kaneo # Service name (e.g., adguard). Used as hostname in Tailscale and for container naming (app-${SERVICE}). -IMAGE_URL_BACKEND=ghcr.io/usekaneo/api:latest # Docker image URL from container registry (e.g., adguard/adguard-home). -IMAGE_URL_FRONTEND=ghcr.io/usekaneo/web:latest # Docker image URL from container registry (e.g., adguard/adguard-home). +IMAGE_URL_SERVICE=ghcr.io/usekaneo/kaneo:latest # Docker image URL from container registry (e.g., adguard/adguard-home). IMAGE_URL_DATABASE=postgres:16-alpine # Docker image URL from container registry (e.g., adguard/adguard-home). # Network Configuration -# SERVICEPORT= -SERVICEPORT_FRONTEND=5173 -SERVICEPORT_BACKEND=1337 +SERVICEPORT=5173 SERVICEPORT_DATABASE=5432 DNS_SERVER=9.9.9.9 # Preferred DNS server for Tailscale. Uncomment the "dns:" section in compose.yaml to enable. @@ -28,7 +25,6 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim # Any Container environment variables are declared below. See https://docs.docker.com/compose/how-tos/environment-variables/ # Kaneo Configuration -KANEO_API_URL="https://kaneo..ts.net/api" KANEO_CLIENT_URL="https://kaneo..ts.net" # AUTH Configuration diff --git a/services/kaneo/compose.yaml b/services/kaneo/compose.yaml index ce9f5496..926e8626 100644 --- a/services/kaneo/compose.yaml +++ b/services/kaneo/compose.yaml @@ -4,8 +4,7 @@ configs: {"TCP":{"443":{"HTTPS":true}}, "Web":{"$${TS_CERT_DOMAIN}:443": {"Handlers":{ - "/api/":{"Proxy":"http://localhost:${SERVICEPORT_BACKEND}/api/"}, - "/":{"Proxy":"http://localhost:${SERVICEPORT_FRONTEND}"} + "/":{"Proxy":"http://localhost:${SERVICEPORT}"} }}}, "AllowFunnel":{"$${TS_CERT_DOMAIN}:443":false}} @@ -70,8 +69,8 @@ services: start_period: 30s # Time to wait before starting health checks restart: always - # Backend (API) - backend: + # Application + application: image: ${IMAGE_URL_BACKEND} # Image to be used network_mode: service:tailscale # Sidecar configuration to route the service through Tailscale container_name: app-${SERVICE}-backend # Name for local container management @@ -84,21 +83,6 @@ services: condition: service_healthy postgres: condition: service_healthy - # Healthcheck: defined by the image (wget against /api/health), so this file does not override it. - restart: always - - # Frontend (Web) - frontend: - image: ${IMAGE_URL_FRONTEND} # Image to be used - network_mode: service:tailscale # Sidecar configuration to route the service through Tailscale - container_name: app-${SERVICE}-frontend # Name for local container management - env_file: - - .env - depends_on: - tailscale: - condition: service_healthy - backend: - condition: service_started healthcheck: test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:5173/"] # Check if the service is responding interval: 1m # How often to perform the check From 442bfb83b44969b67b1f95c3a9c669eb649b7e07 Mon Sep 17 00:00:00 2001 From: Dimitri Hautot <3765206+DimitriHautot@users.noreply.github.com> Date: Tue, 6 Oct 2026 23:26:59 +0200 Subject: [PATCH 2/3] Adapted .env, compose.yaml and README.md files according to code review comments --- services/kaneo/.env | 10 +++++++--- services/kaneo/README.md | 12 +++++++++++- services/kaneo/compose.yaml | 14 +++----------- 3 files changed, 21 insertions(+), 15 deletions(-) diff --git a/services/kaneo/.env b/services/kaneo/.env index 71476013..538ca4ee 100644 --- a/services/kaneo/.env +++ b/services/kaneo/.env @@ -3,11 +3,15 @@ #COMPOSE_PROJECT_NAME= # Optional: only use when running multiple deployments on the same infrastructure. # Service Configuration -SERVICE=kaneo # Service name (e.g., adguard). Used as hostname in Tailscale and for container naming (app-${SERVICE}). -IMAGE_URL_SERVICE=ghcr.io/usekaneo/kaneo:latest # Docker image URL from container registry (e.g., adguard/adguard-home). -IMAGE_URL_DATABASE=postgres:16-alpine # Docker image URL from container registry (e.g., adguard/adguard-home). +# Service name (e.g., adguard). Used as hostname in Tailscale and for container naming (app-${SERVICE}). +SERVICE=kaneok +# Docker image URL from container registry (e.g., adguard/adguard-home). +IMAGE_URL=ghcr.io/usekaneo/kaneo:latest +# Docker image URL from container registry (e.g., adguard/adguard-home). +IMAGE_URL_DATABASE=postgres:16-alpine # Network Configuration +# Ports to expose to local network. Uncomment the "ports:" section in compose.yaml to enable. SERVICEPORT=5173 SERVICEPORT_DATABASE=5432 DNS_SERVER=9.9.9.9 # Preferred DNS server for Tailscale. Uncomment the "dns:" section in compose.yaml to enable. diff --git a/services/kaneo/README.md b/services/kaneo/README.md index 82ce868c..1d7b5cc7 100644 --- a/services/kaneo/README.md +++ b/services/kaneo/README.md @@ -16,4 +16,14 @@ This Docker Compose configuration sets up **[Kaneo](https://github.com/usekaneo/ ## Configuration Overview -In this setup, the `tailscale-kaneo` service runs Tailscale, which manages secure networking for the Kaneo service. The `kaneo` service uses the Tailscale network stack via Docker's `network_mode: service:tailscale` configuration. This ensures that Kaneo’s web interface is only accessible through the Tailscale network (or locally, if preferred), adding a strong layer of privacy and security to your self-hosted project management platform. +In this setup, the `tailscale-kaneo` service runs Tailscale, which manages secure networking for the Kaneo service. The `application` service uses the Tailscale network stack via Docker's `network_mode: service:tailscale` configuration. This ensures that Kaneo’s web interface is only accessible through the Tailscale network (or locally, if preferred), adding a strong layer of privacy and security to your self-hosted project management platform. + +### .env file +In the `.env` file, you must configure the `KANEO_CLIENT_URL` variable to match your own tailnet, like this: `https://kaneo..ts.net`. The [upstream docs](https://kaneo.app/docs/core/installation/docker-compose) derive the API URL from it. The container has to be recreated after you change the value. + +You also have to provide two different secrets (`openssl rand -hex 32`), for the `AUTH_SECRET` and `DB_PASSWORD` variables. + +Finally, obtain an authentication key from TailScale and set it as the `TS_AUTHKEY` variable. + +### Container image +Since [release v2.7.0](https://github.com/usekaneo/kaneo/releases/tag/v2.7.0), the Kaneo service is composed of a single image, instead of two previously (web and backend). More information on the [Upgrade Kaneo](https://kaneo.app/docs/core/operations/upgrades) upstream documentation. diff --git a/services/kaneo/compose.yaml b/services/kaneo/compose.yaml index 926e8626..5d4775ea 100644 --- a/services/kaneo/compose.yaml +++ b/services/kaneo/compose.yaml @@ -71,9 +71,9 @@ services: # Application application: - image: ${IMAGE_URL_BACKEND} # Image to be used + image: ${IMAGE_URL} # Image to be used network_mode: service:tailscale # Sidecar configuration to route the service through Tailscale - container_name: app-${SERVICE}-backend # Name for local container management + container_name: app-${SERVICE} # Name for local container management env_file: - .env environment: @@ -83,13 +83,5 @@ services: condition: service_healthy postgres: condition: service_healthy - healthcheck: - test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:5173/"] # Check if the service is responding - interval: 1m # How often to perform the check - timeout: 10s # Time to wait for the check to succeed - retries: 3 # Number of retries before marking as unhealthy - start_period: 30s # Time to wait before starting health checks + # Healthcheck: defined by the image (wget against /api/health), so this file does not override it. restart: always - -volumes: - postgres_data: From 6de0e04e79fd9dee3f4eb26403be0ed85d4a1048 Mon Sep 17 00:00:00 2001 From: Dimitri Hautot <3765206+DimitriHautot@users.noreply.github.com> Date: Tue, 6 Oct 2026 23:57:54 +0200 Subject: [PATCH 3/3] Adapted .env and README.md files according to 2nd code review comments --- services/kaneo/.env | 2 +- services/kaneo/README.md | 4 +++- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/services/kaneo/.env b/services/kaneo/.env index 538ca4ee..e5ed3255 100644 --- a/services/kaneo/.env +++ b/services/kaneo/.env @@ -4,7 +4,7 @@ # Service Configuration # Service name (e.g., adguard). Used as hostname in Tailscale and for container naming (app-${SERVICE}). -SERVICE=kaneok +SERVICE=kaneo # Docker image URL from container registry (e.g., adguard/adguard-home). IMAGE_URL=ghcr.io/usekaneo/kaneo:latest # Docker image URL from container registry (e.g., adguard/adguard-home). diff --git a/services/kaneo/README.md b/services/kaneo/README.md index 1d7b5cc7..4b6b7213 100644 --- a/services/kaneo/README.md +++ b/services/kaneo/README.md @@ -19,11 +19,13 @@ This Docker Compose configuration sets up **[Kaneo](https://github.com/usekaneo/ In this setup, the `tailscale-kaneo` service runs Tailscale, which manages secure networking for the Kaneo service. The `application` service uses the Tailscale network stack via Docker's `network_mode: service:tailscale` configuration. This ensures that Kaneo’s web interface is only accessible through the Tailscale network (or locally, if preferred), adding a strong layer of privacy and security to your self-hosted project management platform. ### .env file + In the `.env` file, you must configure the `KANEO_CLIENT_URL` variable to match your own tailnet, like this: `https://kaneo..ts.net`. The [upstream docs](https://kaneo.app/docs/core/installation/docker-compose) derive the API URL from it. The container has to be recreated after you change the value. You also have to provide two different secrets (`openssl rand -hex 32`), for the `AUTH_SECRET` and `DB_PASSWORD` variables. -Finally, obtain an authentication key from TailScale and set it as the `TS_AUTHKEY` variable. +Finally, obtain an authentication key from Tailscale and set it as the `TS_AUTHKEY` variable. ### Container image + Since [release v2.7.0](https://github.com/usekaneo/kaneo/releases/tag/v2.7.0), the Kaneo service is composed of a single image, instead of two previously (web and backend). More information on the [Upgrade Kaneo](https://kaneo.app/docs/core/operations/upgrades) upstream documentation.