There's nothing you have to do by hand. Before a big version jump it's still worth making a backup of your own, which you do under Settings, Backups with “Back up now”.
Self-host
One container and one folder, that's all you need.
nexlore runs as a single Docker container and keeps everything in SQLite. You don't need a database next to it, a search server or a service in the cloud, and your notes live as files on your own disk.
nexlore is running in five minutes
The image is built for amd64 and arm64. So it runs on a mini PC just as well as on a Raspberry Pi or your NAS.
services:
nexlore:
image: ghcr.io/derkezorm/nexlore:latest
container_name: nexlore
restart: unless-stopped
ports:
- "8470:8000"
volumes:
- ./data:/data
environment:
PUID: 1000
PGID: 1000
TZ: Europe/Berlin- Create the file
Put the file into an empty folder, for example
/opt/nexlore. WithPUIDandPGIDyou decide which user should own the files. - StartShell
docker compose up -d - Create the first account
Open
http://your-server:8470in your browser. Whoever creates the first account there becomes the operator. Everyone else joins by invitation, or through your sign-in provider if you allow that.
Lore saysOn the first start nexlore creates a space called “nexlore”. It holds a guide to try things out in, in English or German and with pictures. You're free to change or delete it, and the operator can create it again at any time.
Your notes in a folder of your choice
If you don't set anything else, the notes live in data/vault. If you want a folder that another program or Syncthing also works on, mount it into the container and tell nexlore about it.
Every folder at the top becomes a space
/srv/notes/Personal and /srv/notes/Family become the spaces “Personal” and “Family”. As long as a space has no members, it belongs to the operator, who can invite others to it under Settings.
The container sets up the data folder for PUID and PGID on every start. It doesn't do that for a mounted vault folder, so that one already has to be writable for this user.
volumes:
- ./data:/data
- /srv/notes:/vault
environment:
NEXLORE_VAULT_DIR: /vault
# a share without change notifications:
# NEXLORE_WATCH_POLLING: "true"Safe to reach with HTTPS
Before you use nexlore from anywhere other than your own desk, put a reverse proxy with TLS in front of it. You can only install nexlore on a phone over HTTPS anyway.
notes.example.com {
reverse_proxy 127.0.0.1:8470
}client_max_body_size 1024m;
location / {
proxy_pass http://127.0.0.1:8470;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}The public address
NEXLORE_PUBLIC_URL holds the address people use to reach nexlore. nexlore builds invitation links, public pages and the redirect address for OIDC from it.
Trusting your proxy
In NEXLORE_TRUSTED_PROXIES you list your proxies' addresses. Only then does nexlore slow down the real sender when someone guesses passwords, and not your proxy.
Secure cookies
By default nexlore works out on its own whether HTTPS is in use, behind the proxy too, through X-Forwarded-Proto. If that doesn't work, you set it with NEXLORE_COOKIE_SECURE.
Lore saysclient_max_body_size should match the largest file nexlore accepts. That's 1024 MB by default, and the operator can change it under Settings.
Where nexlore keeps what
Everything except the notes lives in /data. This folder belongs on a local disk and never on an SMB or NFS share, because SQLite's locking doesn't hold reliably over network filesystems.
| In the data folder | What it is |
|---|---|
nexlore.db | The database with the index, versions, trash and accounts. Everything in it except versions and trash can be rebuilt from the files. |
secret.key | The key for everything the server has to read on its own, meaning the OIDC secret, the mail password and the seeds of second factors. |
vault/ | Your notes, as long as no vault folder of your own is mounted. |
backups/ | The backups as ZIP files. |
trash/ | The trash, where deleted things wait for 30 days. |
logs/ | The log, which never contains note contents, passwords or keys. |
locales/ | Extra languages, one JSON file each. |
All environment variables
You don't need any of them. The operator sets most things in the interface anyway.
| Variable | Default | Meaning |
|---|---|---|
NEXLORE_DATA_DIR | /data | folder for the database, log, backups, trash and languages |
NEXLORE_VAULT_DIR | <data>/vault | folder with the notes as Markdown files |
NEXLORE_LOCALES_DIR | <data>/locales | folder for extra languages, one JSON file each |
NEXLORE_SECRET_KEY | made on first start | protects the secrets on the server and takes precedence over secret.key when you set it |
NEXLORE_PUBLIC_URL | from the request | the address for invitations, public pages and OIDC; the setting in the interface takes precedence |
NEXLORE_TRUSTED_PROXIES | none | addresses or networks of your reverse proxies whose X-Forwarded-For nexlore believes, comma separated |
NEXLORE_WATCH_POLLING | false | makes nexlore check regularly, for shares that don't report changes |
NEXLORE_SCAN_INTERVAL | 300 | seconds between two full passes over the vault; 0 turns them off |
NEXLORE_SESSION_DAYS | 30 | a sign-in in the browser ends after this many days |
NEXLORE_LOG_LEVEL | stored setting | quiet, normal, detailed or trace; helps when the app won't start |
NEXLORE_COOKIE_SECURE | auto | on, off or auto, in which case the request or X-Forwarded-Proto decides |
NEXLORE_API_DOCS | false | serves /api/docs and /api/openapi.json |
NEXLORE_PORT | 8000 | the port inside the container, relevant for host networking |
PUID, PGID | 1000 | who owns the files in the data folder |
Updating without any manual steps
You pull the new image and restart. nexlore adds whatever the database is missing when it starts, and it backs the database up first.
docker compose pull
docker compose up -dBack up and restore without breaking anything
The database keeps running while it's being backed up. That's why nexlore copies it itself, cleanly and in one piece, and never simply as a file while it's in use.
On a schedule
You can have backups made every night or every week, and by default this is off. You choose how many backups are kept, seven by default.
A dry run first
Before you restore, nexlore shows you what would be added, what would change and what would go.
A copy to take along
You can download every backup. nexlore asks for the operator's password once more before it hands it over.
Lore saysA backup is an ordinary ZIP with the database, all notes and files and secret.key. Whoever has it has everything. Please keep it as carefully as the data folder itself, and not only on the same server.