Skip to content
NEXCANVAS

Self-host

Your own board in a few minutes.

nexcanvas runs as a single container. You need a machine with Docker, such as a small home server or a NAS, and a short compose file. You do not need an account with us, and there is none.

Starting in three steps

The image is available for amd64 and arm64, so it also runs on a Raspberry Pi or a NAS with an ARM processor.

  1. Create the compose file

    Make a folder, for example nexcanvas, and put this file in it.

    docker-compose.yml
    services:
      nexcanvas:
        image: ghcr.io/derkezorm/nexcanvas:latest
        container_name: nexcanvas
        restart: unless-stopped
        ports:
          - "8500:8000"
        volumes:
          - ./data:/data
        environment:
          PUID: 1000
          PGID: 1000
          TZ: Europe/Berlin
  1. Start it
    Shell
    docker compose up -d
  2. Create the first account

    Open http://your-server:8500 in the browser. nexcanvas leads you to the setup and asks for the setup code. It writes the code to its log on every start until it is set up. You find it with docker logs nexcanvas in the line “The setup code is …”, or you set your own with NEXCANVAS_SETUP_TOKEN. That way nobody takes over your fresh nexcanvas just because they found it first. Whoever creates the first account becomes the operator. The password needs at least twelve characters.

Cora saysWould you rather build from the source? Clone the repository, write build: . in place of the line with image: and start with docker compose up -d --build. The docker-compose.yml in the repository explains every setting.

Behind a reverse proxy

As soon as you use nexcanvas from anywhere other than your desk, it belongs behind a reverse proxy with TLS, for example Caddy, Traefik or nginx.

Let WebSockets through

Boards are edited live over a WebSocket connection, at /api/boards/<id>/live. The proxy has to let it through, otherwise the board shows “Offline” at the top, and the changes of others do not arrive. Caddy and Traefik do this by themselves, and nginx needs the usual lines for Upgrade and Connection.

Tell nexcanvas about the proxy

With NEXCANVAS_PUBLIC_URL you give the address at which others reach nexcanvas, for invitation links, public pages and the return from your sign-in service. NEXCANVAS_TRUSTED_PROXIES names the address or network of the proxy. Without it, every sign-in seems to come from the proxy, and the brake against password guessing cannot tell people apart.

nexcanvas on the internet

nexcanvas is built to be reachable from outside, for you on the road or for a small team. Before you open it up, go through this list.

  1. Set up first, then open up

    Create the first account from your own network, with the code from the log. Only after that do you forward a port.

  2. TLS at the proxy, nexcanvas only through it

    Publish the port as 127.0.0.1:8500:8000 if the proxy runs on the same machine, or keep both in a Docker network with no published port. Let WebSockets through and send HSTS from the proxy.

  3. Name the proxy and the address

    NEXCANVAS_PUBLIC_URL, NEXCANVAS_TRUSTED_PROXIES and NEXCANVAS_COOKIE_SECURE: "on".

  4. A second factor

    Set up a second factor for your own account under My account, Security, or sign in through your OpenID Connect provider. If you like, nexcanvas demands the second factor from everyone.

  5. Leave off what you do not need

    Public pages and API tokens are off by default. Switch them on only when you need them.

  6. Keep the operator settings at home

    With NEXCANVAS_OPERATOR_NETWORKS: "192.168.0.0/16", nexcanvas accepts changes to the operator settings only from that network, behind a proxy together with NEXCANVAS_TRUSTED_PROXIES.

  7. Backups elsewhere

    A backup contains everything, every photo too. Copy one off the machine now and then, as carefully as the data folder, and try out restoring with “Check”.

  8. Pin a version

    Use a fixed version such as 0.1.0 instead of latest, update on purpose and back up first.

Accounts and sign-in

Accounts come by invitation only. If you would rather sign in through a sign-in service, you get that with OpenID Connect.

authentik in one step

Under Settings, Server, Sign-in you enter your OpenID Connect provider: issuer, client ID and secret, plus the name for the button on the sign-in page. nexcanvas shows you the redirect address for the provider, ready to copy.

If you use authentik, it is easier: enter the address of authentik and an API token, press “Set up”, and nexcanvas creates the provider and application there itself. The token is used only for that and is not stored. Alternatively you download a blueprint file and load it into authentik.

  • Switching off sign-in with a password: Then members get in only through the provider. As the operator you can always use your password.
  • New people: By default, only invited people or already linked accounts get in through the provider. If you like, every new person gets an account there.
  • Mail for invitations: With a mail server, nexcanvas sends invitation links itself. Without one, the link to copy is enough.
Settings
Settings, Server, Sign-in with password sign-in, second factor, public address and OpenID Connect
Sign-in under Settings, Server.

Where everything lives

Everything lives in /data: the database nexcanvas.db with accounts, spaces, boards and their versions, the folder media/ with photos and files and their smaller previews, plus secret.key, backups/, logs/ and locales/ for your own languages.

Cora saysMount the data folder from a local disk, never from an SMB or NFS share. SQLite does not lock reliably over network file systems, and in the worst case something breaks.

Backing up and restoring

Under Settings, Server, Backups, nexcanvas by default creates an archive every night and keeps the last seven. Every week works instead of every night, and with “Back up now” you make one by hand. An archive is an ordinary ZIP file with the database, which nexcanvas copies cleanly while running, with all photos and files and with the key.

“Check” opens an archive and tells you whether it is complete and what a restore would add and remove. When restoring, nexcanvas first backs up the current state and then restarts. Downloading, restoring and deleting ask for your password once more.

Cora saysWhoever has an archive has everything. Keep downloaded backups as carefully as the data folder itself, because they are not encrypted.

Settings
Settings, Server, Backups with the schedule, the number to keep and one backup in the list
The schedule, how many are kept, and every backup with “Check”.

Updating

Shell
docker compose pull
docker compose up -d

Whatever the database lacks, nexcanvas adds itself on start, so there is nothing to do by hand. Before a big jump, a backup is still worth it. Once a day nexcanvas asks GitHub for a newer version and shows it under “About nexcanvas”. After an update it explains to every account, once, what is new and where to find it.

All environment variables

VariableDefaultWhat it is for
NEXCANVAS_DATA_DIR/dataDatabase, photos and files, logs, backups, languages
NEXCANVAS_MEDIA_DIR<data>/mediaPhotos and files of the boards
NEXCANVAS_LOCALES_DIR<data>/localesFurther languages, one JSON file each
NEXCANVAS_SECRET_KEYcreated on first startProtects secrets on the server; when set, it wins over secret.key
NEXCANVAS_PUBLIC_URLfrom the requestThe address at which others reach nexcanvas; the setting in the interface wins when it is set
NEXCANVAS_TRUSTED_PROXIESnoneAddresses or networks of proxies whose X-Forwarded-For is believed
NEXCANVAS_SETUP_TOKENcreated on startThe code for the first account
NEXCANVAS_OPERATOR_NETWORKSnoneNetworks from which the operator settings may be changed
NEXCANVAS_UPLOAD_MAX_MB50The largest file; the operator can lower the value in the settings
NEXCANVAS_SESSION_DAYS30After this many days a session in the browser ends
NEXCANVAS_LOG_LEVELsettingquiet, normal, detailed or trace; overrides the setting
NEXCANVAS_COOKIE_SECUREautoon, off or auto
NEXCANVAS_API_DOCSfalseShows /api/docs and /api/openapi.json
PUID, PGID1000Who owns the files in the data folder