Services
Auth tiers:
PUBLIC= no auth ·AUTHELIA= forward-auth viaauth.tskn.org·BUILTIN= app's own login ·NONE= open
Infrastructure
Caddy
- Role: Reverse proxy (host binary, not containerized)
- Config:
/home/tforkan/docker/Caddyfile→ symlinked from/etc/caddy/Caddyfile - Admin API:
127.0.0.1:2019(local only — used by Glance Caddy status widget) - TLS: Cloudflare DNS challenge (
acme_dns cloudflare) - Backup: ✅ R2 (
/data/caddy)
Authelia
- URL:
auth.tskn.org· Port:9091· Auth: NONE (it is the auth) - Compose:
authelia/ - Secrets: stored in
authelia/secrets/(separate from.env) — backed up to R2 - Backup: ✅ R2 (
/data/authelia_config,/data/authelia_secrets)
Pi-hole
- URL:
pihole.tskn.org· Port:8070→80· Auth: BUILTIN - Compose:
pihole/ - DNS: Binds to host port 53 — handles local DNS for
*.tskn.orgon LAN - Backup: ✅ R2
- ⚠️ Quirk: Pi-hole v6 uses
FTLCONF_webserver_api_passwordenv var. The old v5WEBPASSWORDdoes NOT work.PIHOLE_PASSWORDinglance/.envmust matchFTLCONF_WEBSERVER_API_PASSWORDinpihole/.env.
Autoheal
- Role: Restarts unhealthy containers automatically
- Compose:
autoheal/· No web UI · No port - Watches containers with label
autoheal: 'true'(currently: Authelia)
Media
Jellyfin
- URL:
jellyfin.tskn.org· Port:8096(public, not bound to 127.0.0.1) · Auth: BUILTIN - Compose:
jellyfin/ - HW Accel: Intel QuickSync via
/dev/dri/renderD128+/dev/dri/card1· Groups:render(GID 991),video(GID 44) - Backup: ✅ R2 (config only — media excluded)
- ⚠️ Quirk: Port
8096is exposed to all interfaces (not127.0.0.1), unlike most services. Jellyfin handles its own auth — no Authelia gate. - ⚠️ Quirk:
latest-mediawidget in Glance queries/Usersand picks the first user alphabetically. Must explicitly setlibraries: [Movies, Shows]in the Glance widget host config or it returns stale data from the wrong user.
Seerr
- URL:
seerr.tskn.org· Port:5055· Auth: BUILTIN - Compose:
seerr/ - Backup: ✅ R2 (config)
Dispatcharr
- URL:
dispatcharr.tskn.org· Port:9191· Auth: BUILTIN - Compose:
dispatcharr/ - Role: IPTV stream manager
Photos & Social
Immich
- URL:
immich.tskn.org· Port:2283· Auth: BUILTIN - Compose:
immich/ - HW Accel: QuickSync (transcoding) + OpenVINO (ML) via
hwaccel.*.ymlfiles - Backup: ✅ R2 (DB dump +
library/library/— transcoded previews excluded) - WUD: ❌ ALL Immich containers (
immich-server,immich-machine-learning,immich-postgres,immich-redis,immich-db-dumper) havewud.watch=false - ⚠️ Quirk: Postgres image is a custom Immich build (
ghcr.io/immich-app/postgres) withpgvector+vectorchordextensions. Cannot be swapped for standard Postgres. - ⚠️ Quirk:
IMMICH_VERSIONinimmich/.envis pinned (currentlyv3). All Immich containers must be updated together. Never update one container independently. Follow Immich migration guide on each release. - CORS: Caddy adds CORS headers for
webapps.tskn.organdsnapcap.tskn.orgorigins on the Immich block.
Socials-Immich-Bot
- No web UI · Port:
5433(internal API) · Auth: Token - Compose:
socials-immich-bot/ - WUD: ❌ (
wud.watch=false) — locally built image, no registry - Backup: ✅ R2 (entire dir including cookies)
- ⚠️ Quirk: Custom
docker buildfrom localDockerfile. WUD cannot track it. Must be manually rebuilt after code changes. - ⚠️ Quirk: Requires per-platform cookie files mounted as volumes (
cookies_instagram.txt, etc.). Expired cookies cause silent failures per platform.
Snapcap
- URL:
snapcap.tskn.org· Port:5151· Auth: AUTHELIA - Compose:
snapcap/ - HW Accel:
/dev/drimounted · Groups:render(GID 991),video(GID 44)
Home Automation
Home Assistant
- URL:
homeassistant.tskn.org· Port: host:8123 · Auth: BUILTIN - Compose:
homeassistant/ - Network:
host— required for mDNS, Bluetooth, Zigbee discovery on LAN - Zigbee: USB coordinator at
/dev/serial/by-id/usb-1a86_USB_Serial-if00-port0→/dev/ttyUSB0. If USB ID changes after replug, HA loses Zigbee. - Backup: ✅ R2 (full
/configdir) - Glance iframe: Embedded at
/dashboard-glance/0?kiosk. Background set totransparentinlovelace.dashboard_glancestorage file — do not change to hex color. - ⚠️ Quirk:
lovelace_resourcesfile athomeassistant/config/.storage/lovelace_resourcesis root-owned. Edit viadocker exec homeassistant python3rather than directly. - ⚠️ Quirk: HA runs
privileged: truewithNET_ADMIN+NET_RAWcaps. This is required for device discovery.
Productivity & Tracking
Paperless-ngx
- URL:
paperless.tskn.org· Port:8000· Auth: BUILTIN - Compose:
paperless-ngx/ - DB: Postgres 18 + Redis (broker) +
postgres-backup-local(daily dump) - Backup: ✅ R2 (DB dump + media + index)
Vikunja
- URL:
vikunja.tskn.org· Port:3456· Auth: BUILTIN - Compose:
vikunja/ - Image:
vikunja/vikunja:2.3.0— hardcoded, notlatest - ⚠️ Quirk: Pinned at
2.3.0due to breaking changes in newer releases. Do not update without reviewing Vikunja changelog for migration steps.
Dawarich (GPS Tracking)
- URL:
dawarich.tskn.org· Port:3000· Auth: BUILTIN - Compose:
dawarich/· DB: PostGIS/Postgres + Redis
AdventureLog
- URL:
adventurelog.tskn.org· Port:8015· Auth: BUILTIN - Compose:
adventurelog/· DB: PostGIS/Postgres - Backup: ✅ R2 (DB dump + media)
Homebox
- URL:
homebox.tskn.org· Port:3100→7745· Auth: BUILTIN - Compose:
homebox/ - Backup: ✅ R2
Yamtrack
- URL:
yamtrack.tskn.org· Port:8111→8000· Auth: BUILTIN - Compose:
yamtrack/· DB: SQLite + Redis sidecar - Backup: ✅ R2
SparkFitness
- URL:
sparkyfitness.tskn.org· Port:3004→80· Auth: BUILTIN - Compose:
sparkyfitness/· DB: Postgres
Sure (Finance)
- URL:
sure.tskn.org· Port:3334· Auth: BUILTIN - Compose:
sure/· DB: Postgres + Redis
Dashboard & Monitoring
Glance / Dynacat
- URL:
tskn.org(root) · Port: host:8080 · Auth: NONE (startpage) / AUTHELIA (dashboard + editor) - Image:
ghcr.io/panonim/dynacat:latest— NOTglanceapp/glance - Network:
host— no port mapping in compose. Caddy proxieslocalhost:8080directly. - Config:
glance/config/(YAMLs tracked in git) - Backup: ✅ R2
- ⚠️ Quirk:
<script>tags insidetype: htmlwidgets are silently dropped — Dynacat loads content via AJAX/morphing. Do not attempt JavaScript listeners this way. - ⚠️ Quirk: Jellyfin
latest-mediawidget must havelibraries: [Movies, Shows]explicitly set or it returns wrong-user data. Seeglance/config/dashboard.ymlandstartpage.yml.
Beszel
- URL:
beszel.tskn.org· Port:8090· Auth: BUILTIN - Compose:
beszel/· Agent runsnetwork_mode: host - Backup: ✅ R2
- ⚠️ Quirk: Beszel records containers by Docker container ID. On container recreation, old records persist as duplicates. Delete orphaned records via Beszel PocketBase API if duplicates appear in the Resources tab.
Dozzle (Container Logs)
- URL:
dozzle.tskn.org· Port:3030→8080· Auth: AUTHELIA (forward-auth) - Compose:
dozzle/
WUD (What's Up Docker)
- URL:
wud.tskn.org· Port:3005→3000· Auth: NONE - Compose:
wud/ - Notifies: via ntfy topic
wud(major updates only) - Excluded containers: see WUD Watch column — any container with
wud.watch=falselabel
Uptime Kuma
- Port:
3001(internal only, not exposed via Caddy) · Auth: BUILTIN - Compose:
uptime-kuma/ - Backup: ✅ R2
Utilities
Kopia (Backup UI)
- URL:
kopia.tskn.org· Port:51515· Auth: AUTHELIA - Compose:
kopia/ - Target: Cloudflare R2 bucket
cortex-backups
Syncthing
- URL:
syncthing.tskn.org· Port:8384· Auth: BUILTIN - Compose:
syncthing/
ntfy
- URL:
ntfy.tskn.org· Port:8085→80· Auth: BUILTIN - Compose:
ntfy/ - Backup: ✅ R2
Megadown
- URL:
megadown.tskn.org· Port:8091· Auth: AUTHELIA - Compose:
megadown/
IT-Tools
- URL:
it-tools.tskn.org· Port:8082→8080· Auth: NONE - Compose:
it-tools/
Shuffle-JIT
- URL:
webapps.tskn.org(API path/shuffle/api/) · Port:3088· Auth: AUTHELIA - Compose:
shuffle-jit/
Homepage
- Port:
1111→3000· Status: UNUSED — replaced by Glance/Dynacat - Compose:
homepage/
GPU Group ID Reference
If iGPU render group ID changes after kernel update, update GID
991in all affected compose files.
| GID | Group | Used By |
|---|---|---|
991 |
render |
Immich, Jellyfin, Snapcap |
44 |
video |
Immich, Jellyfin, Snapcap |