Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 8 additions & 8 deletions services/kaneo/.env
Original file line number Diff line number Diff line change
Expand Up @@ -3,15 +3,16 @@
#COMPOSE_PROJECT_NAME= # Optional: only use when running multiple deployments on the same infrastructure.

# Service Configuration
SERVICE=kaneo # Service name (e.g., adguard). Used as hostname in Tailscale and for container naming (app-${SERVICE}).
IMAGE_URL_BACKEND=ghcr.io/usekaneo/api:latest # Docker image URL from container registry (e.g., adguard/adguard-home).
IMAGE_URL_FRONTEND=ghcr.io/usekaneo/web:latest # Docker image URL from container registry (e.g., adguard/adguard-home).
IMAGE_URL_DATABASE=postgres:16-alpine # Docker image URL from container registry (e.g., adguard/adguard-home).
# Service name (e.g., adguard). Used as hostname in Tailscale and for container naming (app-${SERVICE}).
SERVICE=kaneo
# Docker image URL from container registry (e.g., adguard/adguard-home).
IMAGE_URL=ghcr.io/usekaneo/kaneo:latest
# Docker image URL from container registry (e.g., adguard/adguard-home).
IMAGE_URL_DATABASE=postgres:16-alpine

# Network Configuration
# SERVICEPORT=
SERVICEPORT_FRONTEND=5173
SERVICEPORT_BACKEND=1337
# Ports to expose to local network. Uncomment the "ports:" section in compose.yaml to enable.
SERVICEPORT=5173
SERVICEPORT_DATABASE=5432
DNS_SERVER=9.9.9.9 # Preferred DNS server for Tailscale. Uncomment the "dns:" section in compose.yaml to enable.

Expand All @@ -28,7 +29,6 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim
# Any Container environment variables are declared below. See https://docs.docker.com/compose/how-tos/environment-variables/

# Kaneo Configuration
KANEO_API_URL="https://kaneo.<your-tailnet>.ts.net/api"
KANEO_CLIENT_URL="https://kaneo.<your-tailnet>.ts.net"

# AUTH Configuration
Expand Down
14 changes: 13 additions & 1 deletion services/kaneo/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,4 +16,16 @@ This Docker Compose configuration sets up **[Kaneo](https://github.com/usekaneo/

## Configuration Overview

In this setup, the `tailscale-kaneo` service runs Tailscale, which manages secure networking for the Kaneo service. The `kaneo` service uses the Tailscale network stack via Docker's `network_mode: service:tailscale` configuration. This ensures that Kaneo’s web interface is only accessible through the Tailscale network (or locally, if preferred), adding a strong layer of privacy and security to your self-hosted project management platform.
In this setup, the `tailscale-kaneo` service runs Tailscale, which manages secure networking for the Kaneo service. The `application` service uses the Tailscale network stack via Docker's `network_mode: service:tailscale` configuration. This ensures that Kaneo’s web interface is only accessible through the Tailscale network (or locally, if preferred), adding a strong layer of privacy and security to your self-hosted project management platform.

### .env file

In the `.env` file, you must configure the `KANEO_CLIENT_URL` variable to match your own tailnet, like this: `https://kaneo.<your-tailnet>.ts.net`. The [upstream docs](https://kaneo.app/docs/core/installation/docker-compose) derive the API URL from it. The container has to be recreated after you change the value.

You also have to provide two different secrets (`openssl rand -hex 32`), for the `AUTH_SECRET` and `DB_PASSWORD` variables.

Finally, obtain an authentication key from Tailscale and set it as the `TS_AUTHKEY` variable.

### Container image

Since [release v2.7.0](https://github.com/usekaneo/kaneo/releases/tag/v2.7.0), the Kaneo service is composed of a single image, instead of two previously (web and backend). More information on the [Upgrade Kaneo](https://kaneo.app/docs/core/operations/upgrades) upstream documentation.
34 changes: 5 additions & 29 deletions services/kaneo/compose.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,7 @@ configs:
{"TCP":{"443":{"HTTPS":true}},
"Web":{"$${TS_CERT_DOMAIN}:443":
{"Handlers":{
"/api/":{"Proxy":"http://localhost:${SERVICEPORT_BACKEND}/api/"},
"/":{"Proxy":"http://localhost:${SERVICEPORT_FRONTEND}"}
"/":{"Proxy":"http://localhost:${SERVICEPORT}"}
}}},
"AllowFunnel":{"$${TS_CERT_DOMAIN}:443":false}}

Expand Down Expand Up @@ -70,11 +69,11 @@ services:
start_period: 30s # Time to wait before starting health checks
restart: always

# Backend (API)
backend:
image: ${IMAGE_URL_BACKEND} # Image to be used
# Application
application:
image: ${IMAGE_URL} # Image to be used
network_mode: service:tailscale # Sidecar configuration to route the service through Tailscale
container_name: app-${SERVICE}-backend # Name for local container management
container_name: app-${SERVICE} # Name for local container management
env_file:
- .env
environment:
Expand All @@ -86,26 +85,3 @@ services:
condition: service_healthy
# Healthcheck: defined by the image (wget against /api/health), so this file does not override it.
restart: always

# Frontend (Web)
frontend:
image: ${IMAGE_URL_FRONTEND} # Image to be used
network_mode: service:tailscale # Sidecar configuration to route the service through Tailscale
container_name: app-${SERVICE}-frontend # Name for local container management
env_file:
- .env
depends_on:
tailscale:
condition: service_healthy
backend:
condition: service_started
healthcheck:
test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:5173/"] # Check if the service is responding
interval: 1m # How often to perform the check
timeout: 10s # Time to wait for the check to succeed
retries: 3 # Number of retries before marking as unhealthy
start_period: 30s # Time to wait before starting health checks
restart: always

volumes:
postgres_data:
Loading