Skip to content
NEXBRAND

Self-host

Your own nexbrand in a few minutes.

nexbrand runs as a single container. You need a machine with Docker, such as a small home server, a NAS or a server at your agency, and a short compose file. You do not need an account with us, and there is none.

Starting in three steps

The image exists for amd64 and arm64, so a Raspberry Pi or a NAS with an ARM processor works too.

  1. Create the compose file

    Make a folder, for example nexbrand, and put this file in it.

    docker-compose.yml
    services:
      nexbrand:
        image: ghcr.io/derkezorm/nexbrand:latest
        container_name: nexbrand
        restart: unless-stopped
        ports:
          - "8540:8000"
        volumes:
          - ./data:/data
        environment:
          PUID: 1000
          PGID: 1000
          TZ: Europe/Berlin
  1. Start it
    Shell
    docker compose up -d
  2. Create the first account

    Open http://your-server:8540 in the browser. nexbrand leads you to the setup and asks for the setup code. It writes the code to its log on every start until it is set up; you find it with docker logs nexbrand, or you set your own with NEXBRAND_SETUP_TOKEN. That way nobody takes over your fresh nexbrand just because they found it first. Whoever creates the first account becomes the operator. The password needs at least twelve characters.

Pavo saysRather build from source? Clone the repository, write build: . instead of the line with image: and start with docker compose up -d --build.

Behind a reverse proxy

As soon as clients open reviews or a printer reads a public page, nexbrand belongs behind a reverse proxy with TLS, for example Caddy, Traefik or nginx.

Name the address

With NEXBRAND_PUBLIC_URL you name the address at which others reach nexbrand. It builds invitation links, public pages, review links and the return from your sign-in service from it. The setting “Public address” in the interface wins when it is set.

Name the proxy

NEXBRAND_TRUSTED_PROXIES names the address or network of the proxy. Without it, every sign-in seems to come from the proxy, and the brake against guessed passwords cannot tell people apart. If nexbrand notices an unknown proxy, a hint appears under Settings, Server.

nexbrand on the internet

Reviews and public pages are meant for people outside, so nexbrand will often be reachable from the internet. Before you open it up, go through this list.

  1. Set up first, then open up

    Create the first account from your own network, with the code from the log. Only after that do you forward a port.

  2. TLS at the proxy, nexbrand only through it

    Publish the port as 127.0.0.1:8540:8000 if the proxy runs on the same machine, or keep both in a Docker network with no published port.

  3. Name the proxy and the address

    NEXBRAND_PUBLIC_URL, NEXBRAND_TRUSTED_PROXIES and NEXBRAND_COOKIE_SECURE: "on".

  4. A second factor

    Set up a second factor for your own account under My account, Security, or sign in through your OpenID Connect provider. If you like, nexbrand demands the second factor from everyone.

  5. Leave off what you do not need

    Public pages and reviews, API tokens, collecting from websites and the AI service are off by default. Switch on only what you need.

  6. Keep the operator settings at home

    With NEXBRAND_OPERATOR_NETWORKS: "192.168.0.0/16", nexbrand accepts changes to the operator settings only from that network, behind a proxy together with NEXBRAND_TRUSTED_PROXIES.

  7. Backups elsewhere

    A backup contains everything, every logo, every font and the key. Copy one off the machine now and then, as carefully as the data folder, and try out restoring with “Check”.

  8. Pin a version

    Use a fixed version such as 0.1.0 instead of latest, update on purpose and back up first.

Accounts and sign-in

Accounts come by invitation only. If you would rather sign in through a sign-in service, you get that with OpenID Connect.

authentik in one step

Under Settings, Server, Sign-in you enter your OpenID Connect provider: issuer, client ID and secret, plus the name for the button on the sign-in page. nexbrand shows you the redirect address for the provider, ready to copy.

If you use authentik, it is easier: enter the address of authentik and a one-time API token, press “Set up”, and nexbrand creates the signing key, provider and application there itself. The token is used only for that and is not stored. Alternatively you download a blueprint file and load it into authentik.

  • Switching off sign-in with a password: Then members get in only through the provider. As the operator you can always use your password.
  • New people: By default, only invited people or already linked accounts get in through the provider. If you like, every new person gets an account there.
  • Mail: With a mail server, nexbrand sends invitations and review links itself. Without one, the link to copy is enough.
Settings
Settings, Server, Sign-in with password sign-in, second factor, public address and authentik in one step
Sign-in under Settings, Server.

Where everything lives

Everything lives in /data: the database nexbrand.db with accounts, clients, versions and projects, the folder media/ with logos, fonts and examples, plus secret.key, backups/, logs/ and locales/ for your own languages. Only the owner may read the key, the database, the backups and the log.

Pavo saysMount the data folder from a local disk, never from an SMB or NFS share. SQLite does not lock reliably over network file systems, and in the worst case something breaks.

Backing up and restoring

Under Settings, Server, Backups, nexbrand by default creates an archive every night between three and six and keeps the last seven. Every week works instead of every night, and with “Back up now” you make one by hand. An archive is an ordinary ZIP file with the database, which nexbrand copies cleanly while running, with all files and with the key. Downloaded, and put back in on another server with “Upload a backup”, it is also the way to move.

“Check” opens an archive and tells you whether it is complete and what a restore would add and remove. When restoring, nexbrand first backs up the current state and then restarts. Downloading, uploading and restoring ask for your password once more.

Pavo saysWhoever has an archive has everything, including your clients' in-house fonts. Keep downloaded backups as carefully as the data folder itself, because they are not encrypted.

Settings
Settings, Server, Backups with the schedule, the number to keep, the buttons Upload a backup and Back up now, and backups in the list
The schedule, how many are kept, and every backup with “Check”.

Updating

Shell
docker compose pull
docker compose up -d

Whatever the database lacks, nexbrand adds itself on start, so there is nothing to do by hand. Before a big jump, a backup is still worth it. Once a day nexbrand asks GitHub for a newer version and shows it under “About nexbrand”; that is the only request to the outside it makes on its own, and the operator can switch it off. After an update nexbrand explains to every account, once, what is new.

All environment variables

VariableDefaultWhat it is for
NEXBRAND_DATA_DIR/dataDatabase, files, logs, backups, languages
NEXBRAND_MEDIA_DIR<data>/mediaLogos, fonts and examples
NEXBRAND_LOCALES_DIR<data>/localesFurther languages, one JSON file each
NEXBRAND_SECRET_KEYcreated on first startProtects secrets on the server, such as the mail server's password and the keys of AI services
NEXBRAND_PUBLIC_URLfrom the requestThe address at which others reach nexbrand; the setting in the interface wins when it is set
NEXBRAND_TRUSTED_PROXIESnoneAddresses or networks of proxies whose X-Forwarded-For is believed
NEXBRAND_SETUP_TOKENcreated on startThe code for the first account
NEXBRAND_OPERATOR_NETWORKSnoneNetworks from which the operator settings may be changed
NEXBRAND_UPLOAD_MAX_MB50The largest file; the operator can lower the value in the settings
NEXBRAND_SESSION_DAYS30After this many days a session in the browser ends
NEXBRAND_LOG_LEVELsettingquiet, normal, detailed or trace; overrides the setting
NEXBRAND_COOKIE_SECUREautoon, off or auto
NEXBRAND_COOKIE_SUFFIXnoneAn ending for the cookie names when two nexbrand instances run on the same machine
NEXBRAND_PORT8000The port inside the container, needed only in the host's network
NEXBRAND_API_DOCSfalseShows /api/docs and /api/openapi.json
PUID, PGID1000Who owns the files in the data folder; 0 is not allowed
TZEurope/BerlinThe time zone; it decides which day is “today” when a version applies from today