Skip to content

Services

Auth tiers: PUBLIC = no auth · AUTHELIA = forward-auth via auth.tskn.org · BUILTIN = app's own login · NONE = open


Infrastructure

Caddy

  • Role: Reverse proxy (host binary, not containerized)
  • Config: /home/tforkan/docker/Caddyfile → symlinked from /etc/caddy/Caddyfile
  • Admin API: 127.0.0.1:2019 (local only — used by Glance Caddy status widget)
  • TLS: Cloudflare DNS challenge (acme_dns cloudflare)
  • Backup: ✅ R2 (/data/caddy)

Authelia

  • URL: auth.tskn.org · Port: 9091 · Auth: NONE (it is the auth)
  • Compose: authelia/
  • Secrets: stored in authelia/secrets/ (separate from .env) — backed up to R2
  • Backup: ✅ R2 (/data/authelia_config, /data/authelia_secrets)

Pi-hole

  • URL: pihole.tskn.org · Port: 8070→80 · Auth: BUILTIN
  • Compose: pihole/
  • DNS: Binds to host port 53 — handles local DNS for *.tskn.org on LAN
  • Backup: ✅ R2
  • ⚠️ Quirk: Pi-hole v6 uses FTLCONF_webserver_api_password env var. The old v5 WEBPASSWORD does NOT work. PIHOLE_PASSWORD in glance/.env must match FTLCONF_WEBSERVER_API_PASSWORD in pihole/.env.

Autoheal

  • Role: Restarts unhealthy containers automatically
  • Compose: autoheal/ · No web UI · No port
  • Watches containers with label autoheal: 'true' (currently: Authelia)

Media

Jellyfin

  • URL: jellyfin.tskn.org · Port: 8096 (public, not bound to 127.0.0.1) · Auth: BUILTIN
  • Compose: jellyfin/
  • HW Accel: Intel QuickSync via /dev/dri/renderD128 + /dev/dri/card1 · Groups: render (GID 991), video (GID 44)
  • Backup: ✅ R2 (config only — media excluded)
  • ⚠️ Quirk: Port 8096 is exposed to all interfaces (not 127.0.0.1), unlike most services. Jellyfin handles its own auth — no Authelia gate.
  • ⚠️ Quirk: latest-media widget in Glance queries /Users and picks the first user alphabetically. Must explicitly set libraries: [Movies, Shows] in the Glance widget host config or it returns stale data from the wrong user.

Seerr

  • URL: seerr.tskn.org · Port: 5055 · Auth: BUILTIN
  • Compose: seerr/
  • Backup: ✅ R2 (config)

Dispatcharr

  • URL: dispatcharr.tskn.org · Port: 9191 · Auth: BUILTIN
  • Compose: dispatcharr/
  • Role: IPTV stream manager

Photos & Social

Immich

  • URL: immich.tskn.org · Port: 2283 · Auth: BUILTIN
  • Compose: immich/
  • HW Accel: QuickSync (transcoding) + OpenVINO (ML) via hwaccel.*.yml files
  • Backup: ✅ R2 (DB dump + library/library/ — transcoded previews excluded)
  • WUD: ❌ ALL Immich containers (immich-server, immich-machine-learning, immich-postgres, immich-redis, immich-db-dumper) have wud.watch=false
  • ⚠️ Quirk: Postgres image is a custom Immich build (ghcr.io/immich-app/postgres) with pgvector + vectorchord extensions. Cannot be swapped for standard Postgres.
  • ⚠️ Quirk: IMMICH_VERSION in immich/.env is pinned (currently v3). All Immich containers must be updated together. Never update one container independently. Follow Immich migration guide on each release.
  • CORS: Caddy adds CORS headers for webapps.tskn.org and snapcap.tskn.org origins on the Immich block.

Socials-Immich-Bot

  • No web UI · Port: 5433 (internal API) · Auth: Token
  • Compose: socials-immich-bot/
  • WUD: ❌ (wud.watch=false) — locally built image, no registry
  • Backup: ✅ R2 (entire dir including cookies)
  • ⚠️ Quirk: Custom docker build from local Dockerfile. WUD cannot track it. Must be manually rebuilt after code changes.
  • ⚠️ Quirk: Requires per-platform cookie files mounted as volumes (cookies_instagram.txt, etc.). Expired cookies cause silent failures per platform.

Snapcap

  • URL: snapcap.tskn.org · Port: 5151 · Auth: AUTHELIA
  • Compose: snapcap/
  • HW Accel: /dev/dri mounted · Groups: render (GID 991), video (GID 44)

Home Automation

Home Assistant

  • URL: homeassistant.tskn.org · Port: host:8123 · Auth: BUILTIN
  • Compose: homeassistant/
  • Network: host — required for mDNS, Bluetooth, Zigbee discovery on LAN
  • Zigbee: USB coordinator at /dev/serial/by-id/usb-1a86_USB_Serial-if00-port0 → /dev/ttyUSB0. If USB ID changes after replug, HA loses Zigbee.
  • Backup: ✅ R2 (full /config dir)
  • Glance iframe: Embedded at /dashboard-glance/0?kiosk. Background set to transparent in lovelace.dashboard_glance storage file — do not change to hex color.
  • ⚠️ Quirk: lovelace_resources file at homeassistant/config/.storage/lovelace_resources is root-owned. Edit via docker exec homeassistant python3 rather than directly.
  • ⚠️ Quirk: HA runs privileged: true with NET_ADMIN + NET_RAW caps. This is required for device discovery.

Productivity & Tracking

Paperless-ngx

  • URL: paperless.tskn.org · Port: 8000 · Auth: BUILTIN
  • Compose: paperless-ngx/
  • DB: Postgres 18 + Redis (broker) + postgres-backup-local (daily dump)
  • Backup: ✅ R2 (DB dump + media + index)

Vikunja

  • URL: vikunja.tskn.org · Port: 3456 · Auth: BUILTIN
  • Compose: vikunja/
  • Image: vikunja/vikunja:2.3.0 — hardcoded, not latest
  • ⚠️ Quirk: Pinned at 2.3.0 due to breaking changes in newer releases. Do not update without reviewing Vikunja changelog for migration steps.

Dawarich (GPS Tracking)

  • URL: dawarich.tskn.org · Port: 3000 · Auth: BUILTIN
  • Compose: dawarich/ · DB: PostGIS/Postgres + Redis

AdventureLog

  • URL: adventurelog.tskn.org · Port: 8015 · Auth: BUILTIN
  • Compose: adventurelog/ · DB: PostGIS/Postgres
  • Backup: ✅ R2 (DB dump + media)

Homebox

  • URL: homebox.tskn.org · Port: 3100→7745 · Auth: BUILTIN
  • Compose: homebox/
  • Backup: ✅ R2

Yamtrack

  • URL: yamtrack.tskn.org · Port: 8111→8000 · Auth: BUILTIN
  • Compose: yamtrack/ · DB: SQLite + Redis sidecar
  • Backup: ✅ R2

SparkFitness

  • URL: sparkyfitness.tskn.org · Port: 3004→80 · Auth: BUILTIN
  • Compose: sparkyfitness/ · DB: Postgres

Sure (Finance)

  • URL: sure.tskn.org · Port: 3334 · Auth: BUILTIN
  • Compose: sure/ · DB: Postgres + Redis

Dashboard & Monitoring

Glance / Dynacat

  • URL: tskn.org (root) · Port: host:8080 · Auth: NONE (startpage) / AUTHELIA (dashboard + editor)
  • Image: ghcr.io/panonim/dynacat:latest — NOT glanceapp/glance
  • Network: host — no port mapping in compose. Caddy proxies localhost:8080 directly.
  • Config: glance/config/ (YAMLs tracked in git)
  • Backup: ✅ R2
  • ⚠️ Quirk: <script> tags inside type: html widgets are silently dropped — Dynacat loads content via AJAX/morphing. Do not attempt JavaScript listeners this way.
  • ⚠️ Quirk: Jellyfin latest-media widget must have libraries: [Movies, Shows] explicitly set or it returns wrong-user data. See glance/config/dashboard.yml and startpage.yml.

Beszel

  • URL: beszel.tskn.org · Port: 8090 · Auth: BUILTIN
  • Compose: beszel/ · Agent runs network_mode: host
  • Backup: ✅ R2
  • ⚠️ Quirk: Beszel records containers by Docker container ID. On container recreation, old records persist as duplicates. Delete orphaned records via Beszel PocketBase API if duplicates appear in the Resources tab.

Dozzle (Container Logs)

  • URL: dozzle.tskn.org · Port: 3030→8080 · Auth: AUTHELIA (forward-auth)
  • Compose: dozzle/

WUD (What's Up Docker)

  • URL: wud.tskn.org · Port: 3005→3000 · Auth: NONE
  • Compose: wud/
  • Notifies: via ntfy topic wud (major updates only)
  • Excluded containers: see WUD Watch column — any container with wud.watch=false label

Uptime Kuma

  • Port: 3001 (internal only, not exposed via Caddy) · Auth: BUILTIN
  • Compose: uptime-kuma/
  • Backup: ✅ R2

Utilities

Kopia (Backup UI)

  • URL: kopia.tskn.org · Port: 51515 · Auth: AUTHELIA
  • Compose: kopia/
  • Target: Cloudflare R2 bucket cortex-backups

Syncthing

  • URL: syncthing.tskn.org · Port: 8384 · Auth: BUILTIN
  • Compose: syncthing/

ntfy

  • URL: ntfy.tskn.org · Port: 8085→80 · Auth: BUILTIN
  • Compose: ntfy/
  • Backup: ✅ R2

Megadown

  • URL: megadown.tskn.org · Port: 8091 · Auth: AUTHELIA
  • Compose: megadown/

IT-Tools

  • URL: it-tools.tskn.org · Port: 8082→8080 · Auth: NONE
  • Compose: it-tools/

Shuffle-JIT

  • URL: webapps.tskn.org (API path /shuffle/api/) · Port: 3088 · Auth: AUTHELIA
  • Compose: shuffle-jit/

Homepage

  • Port: 1111→3000 · Status: UNUSED — replaced by Glance/Dynacat
  • Compose: homepage/

GPU Group ID Reference

If iGPU render group ID changes after kernel update, update GID 991 in all affected compose files.

GID Group Used By
991 render Immich, Jellyfin, Snapcap
44 video Immich, Jellyfin, Snapcap