Skip to content
nexlore

Self-host

One container and one folder, that's all you need.

nexlore runs as a single Docker container and keeps everything in SQLite. You don't need a database next to it, a search server or a service in the cloud, and your notes live as files on your own disk.

nexlore is running in five minutes

The image is built for amd64 and arm64. So it runs on a mini PC just as well as on a Raspberry Pi or your NAS.

docker-compose.yml
services:
  nexlore:
    image: ghcr.io/derkezorm/nexlore:latest
    container_name: nexlore
    restart: unless-stopped
    ports:
      - "8470:8000"
    volumes:
      - ./data:/data
    environment:
      PUID: 1000
      PGID: 1000
      TZ: Europe/Berlin
  1. Create the file

    Put the file into an empty folder, for example /opt/nexlore. With PUID and PGID you decide which user should own the files.

  2. Start
    Shell
    docker compose up -d
  3. Create the first account

    Open http://your-server:8470 in your browser. Whoever creates the first account there becomes the operator. Everyone else joins by invitation, or through your sign-in provider if you allow that.

Lore saysOn the first start nexlore creates a space called “nexlore”. It holds a guide to try things out in, in English or German and with pictures. You're free to change or delete it, and the operator can create it again at any time.

Your notes in a folder of your choice

If you don't set anything else, the notes live in data/vault. If you want a folder that another program or Syncthing also works on, mount it into the container and tell nexlore about it.

Every folder at the top becomes a space

/srv/notes/Personal and /srv/notes/Family become the spaces “Personal” and “Family”. As long as a space has no members, it belongs to the operator, who can invite others to it under Settings.

The container sets up the data folder for PUID and PGID on every start. It doesn't do that for a mounted vault folder, so that one already has to be writable for this user.

docker-compose.yml, excerpt
    volumes:
      - ./data:/data
      - /srv/notes:/vault
    environment:
      NEXLORE_VAULT_DIR: /vault
      # a share without change notifications:
      # NEXLORE_WATCH_POLLING: "true"

Safe to reach with HTTPS

Before you use nexlore from anywhere other than your own desk, put a reverse proxy with TLS in front of it. You can only install nexlore on a phone over HTTPS anyway.

Caddyfile
notes.example.com {
	reverse_proxy 127.0.0.1:8470
}
nginx, in the server block
client_max_body_size 1024m;
location / {
  proxy_pass http://127.0.0.1:8470;
  proxy_set_header Host $host;
  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  proxy_set_header X-Forwarded-Proto $scheme;
}

The public address

NEXLORE_PUBLIC_URL holds the address people use to reach nexlore. nexlore builds invitation links, public pages and the redirect address for OIDC from it.

Trusting your proxy

In NEXLORE_TRUSTED_PROXIES you list your proxies' addresses. Only then does nexlore slow down the real sender when someone guesses passwords, and not your proxy.

Secure cookies

By default nexlore works out on its own whether HTTPS is in use, behind the proxy too, through X-Forwarded-Proto. If that doesn't work, you set it with NEXLORE_COOKIE_SECURE.

Lore saysclient_max_body_size should match the largest file nexlore accepts. That's 1024 MB by default, and the operator can change it under Settings.

Where nexlore keeps what

Everything except the notes lives in /data. This folder belongs on a local disk and never on an SMB or NFS share, because SQLite's locking doesn't hold reliably over network filesystems.

In the data folderWhat it is
nexlore.dbThe database with the index, versions, trash and accounts. Everything in it except versions and trash can be rebuilt from the files.
secret.keyThe key for everything the server has to read on its own, meaning the OIDC secret, the mail password and the seeds of second factors.
vault/Your notes, as long as no vault folder of your own is mounted.
backups/The backups as ZIP files.
trash/The trash, where deleted things wait for 30 days.
logs/The log, which never contains note contents, passwords or keys.
locales/Extra languages, one JSON file each.

All environment variables

You don't need any of them. The operator sets most things in the interface anyway.

VariableDefaultMeaning
NEXLORE_DATA_DIR/datafolder for the database, log, backups, trash and languages
NEXLORE_VAULT_DIR<data>/vaultfolder with the notes as Markdown files
NEXLORE_LOCALES_DIR<data>/localesfolder for extra languages, one JSON file each
NEXLORE_SECRET_KEYmade on first startprotects the secrets on the server and takes precedence over secret.key when you set it
NEXLORE_PUBLIC_URLfrom the requestthe address for invitations, public pages and OIDC; the setting in the interface takes precedence
NEXLORE_TRUSTED_PROXIESnoneaddresses or networks of your reverse proxies whose X-Forwarded-For nexlore believes, comma separated
NEXLORE_WATCH_POLLINGfalsemakes nexlore check regularly, for shares that don't report changes
NEXLORE_SCAN_INTERVAL300seconds between two full passes over the vault; 0 turns them off
NEXLORE_SESSION_DAYS30a sign-in in the browser ends after this many days
NEXLORE_LOG_LEVELstored settingquiet, normal, detailed or trace; helps when the app won't start
NEXLORE_COOKIE_SECUREautoon, off or auto, in which case the request or X-Forwarded-Proto decides
NEXLORE_API_DOCSfalseserves /api/docs and /api/openapi.json
NEXLORE_PORT8000the port inside the container, relevant for host networking
PUID, PGID1000who owns the files in the data folder

Updating without any manual steps

You pull the new image and restart. nexlore adds whatever the database is missing when it starts, and it backs the database up first.

Shell
docker compose pull
docker compose up -d

There's nothing you have to do by hand. Before a big version jump it's still worth making a backup of your own, which you do under Settings, Backups with “Back up now”.

Back up and restore without breaking anything

The database keeps running while it's being backed up. That's why nexlore copies it itself, cleanly and in one piece, and never simply as a file while it's in use.

On a schedule

You can have backups made every night or every week, and by default this is off. You choose how many backups are kept, seven by default.

A dry run first

Before you restore, nexlore shows you what would be added, what would change and what would go.

A copy to take along

You can download every backup. nexlore asks for the operator's password once more before it hands it over.

Lore saysA backup is an ordinary ZIP with the database, all notes and files and secret.key. Whoever has it has everything. Please keep it as carefully as the data folder itself, and not only on the same server.