Self-host
Your own board in a few minutes.
nexcanvas runs as a single container. You need a machine with Docker, such as a small home server or a NAS, and a short compose file. You do not need an account with us, and there is none.
Starting in three steps
The image is available for amd64 and arm64, so it also runs on a Raspberry Pi or a NAS with an ARM processor.
- Create the compose file
Make a folder, for example
nexcanvas, and put this file in it.docker-compose.ymlservices: nexcanvas: image: ghcr.io/derkezorm/nexcanvas:latest container_name: nexcanvas restart: unless-stopped ports: - "8500:8000" volumes: - ./data:/data environment: PUID: 1000 PGID: 1000 TZ: Europe/Berlin
- Start itShell
docker compose up -d - Create the first account
Open
http://your-server:8500in the browser. nexcanvas leads you to the setup and asks for the setup code. It writes the code to its log on every start until it is set up. You find it withdocker logs nexcanvasin the line “The setup code is …”, or you set your own withNEXCANVAS_SETUP_TOKEN. That way nobody takes over your fresh nexcanvas just because they found it first. Whoever creates the first account becomes the operator. The password needs at least twelve characters.
Cora saysWould you rather build from the source? Clone the repository, write build: . in place of the line with image: and start with docker compose up -d --build. The docker-compose.yml in the repository explains every setting.
Behind a reverse proxy
As soon as you use nexcanvas from anywhere other than your desk, it belongs behind a reverse proxy with TLS, for example Caddy, Traefik or nginx.
Let WebSockets through
Boards are edited live over a WebSocket connection, at /api/boards/<id>/live. The proxy has to let it through, otherwise the board shows “Offline” at the top, and the changes of others do not arrive. Caddy and Traefik do this by themselves, and nginx needs the usual lines for Upgrade and Connection.
Tell nexcanvas about the proxy
With NEXCANVAS_PUBLIC_URL you give the address at which others reach nexcanvas, for invitation links, public pages and the return from your sign-in service. NEXCANVAS_TRUSTED_PROXIES names the address or network of the proxy. Without it, every sign-in seems to come from the proxy, and the brake against password guessing cannot tell people apart.
nexcanvas on the internet
nexcanvas is built to be reachable from outside, for you on the road or for a small team. Before you open it up, go through this list.
- Set up first, then open up
Create the first account from your own network, with the code from the log. Only after that do you forward a port.
- TLS at the proxy, nexcanvas only through it
Publish the port as
127.0.0.1:8500:8000if the proxy runs on the same machine, or keep both in a Docker network with no published port. Let WebSockets through and send HSTS from the proxy. - Name the proxy and the address
NEXCANVAS_PUBLIC_URL,NEXCANVAS_TRUSTED_PROXIESandNEXCANVAS_COOKIE_SECURE: "on". - A second factor
Set up a second factor for your own account under My account, Security, or sign in through your OpenID Connect provider. If you like, nexcanvas demands the second factor from everyone.
- Leave off what you do not need
Public pages and API tokens are off by default. Switch them on only when you need them.
- Keep the operator settings at home
With
NEXCANVAS_OPERATOR_NETWORKS: "192.168.0.0/16", nexcanvas accepts changes to the operator settings only from that network, behind a proxy together withNEXCANVAS_TRUSTED_PROXIES. - Backups elsewhere
A backup contains everything, every photo too. Copy one off the machine now and then, as carefully as the data folder, and try out restoring with “Check”.
- Pin a version
Use a fixed version such as
0.1.0instead oflatest, update on purpose and back up first.
Accounts and sign-in
Accounts come by invitation only. If you would rather sign in through a sign-in service, you get that with OpenID Connect.
authentik in one step
Under Settings, Server, Sign-in you enter your OpenID Connect provider: issuer, client ID and secret, plus the name for the button on the sign-in page. nexcanvas shows you the redirect address for the provider, ready to copy.
If you use authentik, it is easier: enter the address of authentik and an API token, press “Set up”, and nexcanvas creates the provider and application there itself. The token is used only for that and is not stored. Alternatively you download a blueprint file and load it into authentik.
- Switching off sign-in with a password: Then members get in only through the provider. As the operator you can always use your password.
- New people: By default, only invited people or already linked accounts get in through the provider. If you like, every new person gets an account there.
- Mail for invitations: With a mail server, nexcanvas sends invitation links itself. Without one, the link to copy is enough.
Where everything lives
Everything lives in /data: the database nexcanvas.db with accounts, spaces, boards and their versions, the folder media/ with photos and files and their smaller previews, plus secret.key, backups/, logs/ and locales/ for your own languages.
Cora saysMount the data folder from a local disk, never from an SMB or NFS share. SQLite does not lock reliably over network file systems, and in the worst case something breaks.
Backing up and restoring
Under Settings, Server, Backups, nexcanvas by default creates an archive every night and keeps the last seven. Every week works instead of every night, and with “Back up now” you make one by hand. An archive is an ordinary ZIP file with the database, which nexcanvas copies cleanly while running, with all photos and files and with the key.
“Check” opens an archive and tells you whether it is complete and what a restore would add and remove. When restoring, nexcanvas first backs up the current state and then restarts. Downloading, restoring and deleting ask for your password once more.
Cora saysWhoever has an archive has everything. Keep downloaded backups as carefully as the data folder itself, because they are not encrypted.
Updating
docker compose pull
docker compose up -dWhatever the database lacks, nexcanvas adds itself on start, so there is nothing to do by hand. Before a big jump, a backup is still worth it. Once a day nexcanvas asks GitHub for a newer version and shows it under “About nexcanvas”. After an update it explains to every account, once, what is new and where to find it.
All environment variables
| Variable | Default | What it is for |
|---|---|---|
NEXCANVAS_DATA_DIR | /data | Database, photos and files, logs, backups, languages |
NEXCANVAS_MEDIA_DIR | <data>/media | Photos and files of the boards |
NEXCANVAS_LOCALES_DIR | <data>/locales | Further languages, one JSON file each |
NEXCANVAS_SECRET_KEY | created on first start | Protects secrets on the server; when set, it wins over secret.key |
NEXCANVAS_PUBLIC_URL | from the request | The address at which others reach nexcanvas; the setting in the interface wins when it is set |
NEXCANVAS_TRUSTED_PROXIES | none | Addresses or networks of proxies whose X-Forwarded-For is believed |
NEXCANVAS_SETUP_TOKEN | created on start | The code for the first account |
NEXCANVAS_OPERATOR_NETWORKS | none | Networks from which the operator settings may be changed |
NEXCANVAS_UPLOAD_MAX_MB | 50 | The largest file; the operator can lower the value in the settings |
NEXCANVAS_SESSION_DAYS | 30 | After this many days a session in the browser ends |
NEXCANVAS_LOG_LEVEL | setting | quiet, normal, detailed or trace; overrides the setting |
NEXCANVAS_COOKIE_SECURE | auto | on, off or auto |
NEXCANVAS_API_DOCS | false | Shows /api/docs and /api/openapi.json |
PUID, PGID | 1000 | Who owns the files in the data folder |