First steps · Chapter 1
Setting up
nexbrand runs as one Docker container on your own server. This chapter is the short version, up to the first account. Reverse proxy, environment variables and updates are covered in full under Self-host.
What you need
- A machine with Docker and Docker Compose.
- A folder on a local disk for the data. An SMB or NFS share will not do: SQLite's locking does not work reliably over a network drive.
- A free port. The template takes
8540and passes it to port8000inside the container.
Starting it and creating the first account
- Create the compose file
Take the file from the Self-host page. It mounts the folder
./dataas/dataand setsPUID,PGIDand the time zoneTZ. - Start the container
In the folder of the file:
Shelldocker compose up -d - Fetch the setup code
The code is in the container's log. A new one is made at every start until nexbrand is set up. To choose it yourself, set
NEXBRAND_SETUP_TOKEN.Shelldocker logs nexbrand - Create the first account
Open
http://<your-server>:8540. On the page Set up nexbrand, enter Name, Password (at least twelve characters) and the Setup code, then click Create account.
The first account is the operator
The first account runs this server: it may invite others and change every setting. The code makes sure that nobody who happens to reach a fresh instance first can take it over. Every further account comes by invitation only, as described in the chapter Access and teams.
Whatever leads outside is off out of the box: public pages and reviews, API tokens, collecting from websites and repositories, and AI. You switch them on under Settings, Server when you need them. The chapter The operator goes through the switches.
Where the data lives
Everything is in /data: the database nexbrand.db, the folder media/ with logos, fonts and examples, the key secret.key, plus backups/, logs/ and locales/. A backup every night is on out of the box; more under Backups and moving.
Pavo saysSet nexbrand up from your own network before you open a port to the outside, and put it behind a reverse proxy with TLS afterwards.