Self-host
Your own nexbrand in a few minutes.
nexbrand runs as a single container. You need a machine with Docker, such as a small home server, a NAS or a server at your agency, and a short compose file. You do not need an account with us, and there is none.
Starting in three steps
The image exists for amd64 and arm64, so a Raspberry Pi or a NAS with an ARM processor works too.
- Create the compose file
Make a folder, for example
nexbrand, and put this file in it.docker-compose.ymlservices: nexbrand: image: ghcr.io/derkezorm/nexbrand:latest container_name: nexbrand restart: unless-stopped ports: - "8540:8000" volumes: - ./data:/data environment: PUID: 1000 PGID: 1000 TZ: Europe/Berlin
- Start itShell
docker compose up -d - Create the first account
Open
http://your-server:8540in the browser. nexbrand leads you to the setup and asks for the setup code. It writes the code to its log on every start until it is set up; you find it withdocker logs nexbrand, or you set your own withNEXBRAND_SETUP_TOKEN. That way nobody takes over your fresh nexbrand just because they found it first. Whoever creates the first account becomes the operator. The password needs at least twelve characters.
Pavo saysRather build from source? Clone the repository, write build: . instead of the line with image: and start with docker compose up -d --build.
Behind a reverse proxy
As soon as clients open reviews or a printer reads a public page, nexbrand belongs behind a reverse proxy with TLS, for example Caddy, Traefik or nginx.
Name the address
With NEXBRAND_PUBLIC_URL you name the address at which others reach nexbrand. It builds invitation links, public pages, review links and the return from your sign-in service from it. The setting “Public address” in the interface wins when it is set.
Name the proxy
NEXBRAND_TRUSTED_PROXIES names the address or network of the proxy. Without it, every sign-in seems to come from the proxy, and the brake against guessed passwords cannot tell people apart. If nexbrand notices an unknown proxy, a hint appears under Settings, Server.
nexbrand on the internet
Reviews and public pages are meant for people outside, so nexbrand will often be reachable from the internet. Before you open it up, go through this list.
- Set up first, then open up
Create the first account from your own network, with the code from the log. Only after that do you forward a port.
- TLS at the proxy, nexbrand only through it
Publish the port as
127.0.0.1:8540:8000if the proxy runs on the same machine, or keep both in a Docker network with no published port. - Name the proxy and the address
NEXBRAND_PUBLIC_URL,NEXBRAND_TRUSTED_PROXIESandNEXBRAND_COOKIE_SECURE: "on". - A second factor
Set up a second factor for your own account under My account, Security, or sign in through your OpenID Connect provider. If you like, nexbrand demands the second factor from everyone.
- Leave off what you do not need
Public pages and reviews, API tokens, collecting from websites and the AI service are off by default. Switch on only what you need.
- Keep the operator settings at home
With
NEXBRAND_OPERATOR_NETWORKS: "192.168.0.0/16", nexbrand accepts changes to the operator settings only from that network, behind a proxy together withNEXBRAND_TRUSTED_PROXIES. - Backups elsewhere
A backup contains everything, every logo, every font and the key. Copy one off the machine now and then, as carefully as the data folder, and try out restoring with “Check”.
- Pin a version
Use a fixed version such as
0.1.0instead oflatest, update on purpose and back up first.
Accounts and sign-in
Accounts come by invitation only. If you would rather sign in through a sign-in service, you get that with OpenID Connect.
authentik in one step
Under Settings, Server, Sign-in you enter your OpenID Connect provider: issuer, client ID and secret, plus the name for the button on the sign-in page. nexbrand shows you the redirect address for the provider, ready to copy.
If you use authentik, it is easier: enter the address of authentik and a one-time API token, press “Set up”, and nexbrand creates the signing key, provider and application there itself. The token is used only for that and is not stored. Alternatively you download a blueprint file and load it into authentik.
- Switching off sign-in with a password: Then members get in only through the provider. As the operator you can always use your password.
- New people: By default, only invited people or already linked accounts get in through the provider. If you like, every new person gets an account there.
- Mail: With a mail server, nexbrand sends invitations and review links itself. Without one, the link to copy is enough.
Where everything lives
Everything lives in /data: the database nexbrand.db with accounts, clients, versions and projects, the folder media/ with logos, fonts and examples, plus secret.key, backups/, logs/ and locales/ for your own languages. Only the owner may read the key, the database, the backups and the log.
Pavo saysMount the data folder from a local disk, never from an SMB or NFS share. SQLite does not lock reliably over network file systems, and in the worst case something breaks.
Backing up and restoring
Under Settings, Server, Backups, nexbrand by default creates an archive every night between three and six and keeps the last seven. Every week works instead of every night, and with “Back up now” you make one by hand. An archive is an ordinary ZIP file with the database, which nexbrand copies cleanly while running, with all files and with the key. Downloaded, and put back in on another server with “Upload a backup”, it is also the way to move.
“Check” opens an archive and tells you whether it is complete and what a restore would add and remove. When restoring, nexbrand first backs up the current state and then restarts. Downloading, uploading and restoring ask for your password once more.
Pavo saysWhoever has an archive has everything, including your clients' in-house fonts. Keep downloaded backups as carefully as the data folder itself, because they are not encrypted.
Updating
docker compose pull
docker compose up -dWhatever the database lacks, nexbrand adds itself on start, so there is nothing to do by hand. Before a big jump, a backup is still worth it. Once a day nexbrand asks GitHub for a newer version and shows it under “About nexbrand”; that is the only request to the outside it makes on its own, and the operator can switch it off. After an update nexbrand explains to every account, once, what is new.
All environment variables
| Variable | Default | What it is for |
|---|---|---|
NEXBRAND_DATA_DIR | /data | Database, files, logs, backups, languages |
NEXBRAND_MEDIA_DIR | <data>/media | Logos, fonts and examples |
NEXBRAND_LOCALES_DIR | <data>/locales | Further languages, one JSON file each |
NEXBRAND_SECRET_KEY | created on first start | Protects secrets on the server, such as the mail server's password and the keys of AI services |
NEXBRAND_PUBLIC_URL | from the request | The address at which others reach nexbrand; the setting in the interface wins when it is set |
NEXBRAND_TRUSTED_PROXIES | none | Addresses or networks of proxies whose X-Forwarded-For is believed |
NEXBRAND_SETUP_TOKEN | created on start | The code for the first account |
NEXBRAND_OPERATOR_NETWORKS | none | Networks from which the operator settings may be changed |
NEXBRAND_UPLOAD_MAX_MB | 50 | The largest file; the operator can lower the value in the settings |
NEXBRAND_SESSION_DAYS | 30 | After this many days a session in the browser ends |
NEXBRAND_LOG_LEVEL | setting | quiet, normal, detailed or trace; overrides the setting |
NEXBRAND_COOKIE_SECURE | auto | on, off or auto |
NEXBRAND_COOKIE_SUFFIX | none | An ending for the cookie names when two nexbrand instances run on the same machine |
NEXBRAND_PORT | 8000 | The port inside the container, needed only in the host's network |
NEXBRAND_API_DOCS | false | Shows /api/docs and /api/openapi.json |
PUID, PGID | 1000 | Who owns the files in the data folder; 0 is not allowed |
TZ | Europe/Berlin | The time zone; it decides which day is “today” when a version applies from today |