Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/linting.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,9 +29,9 @@ jobs:
- name: Clone this repo
uses: actions/checkout@v6

- name: Lint services
- name: Lint Markdown
uses: rvben/rumdl@v0.2.41
with:
path: "services/"
path: "."
config: ".markdownlint.yml"
report-type: annotations
13 changes: 10 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,11 +51,11 @@ ScaleTail provides ready-to-run [Docker Compose](https://docs.docker.com/compose
- [🎥 Media and Entertainment](#-media-and-entertainment)
- [💼 Productivity and Collaboration](#-productivity-and-collaboration)
- [📊 Dashboards and Visualization](#-dashboards-and-visualization)
- [🛠️ Development Tools](#️-development-tools)
- [🛠️ Development Tools](#development-tools)
- [📈 Monitoring and Analytics](#-monitoring-and-analytics)
- [🏠 Smart Home](#-smart-home)
- [📱 Utilities](#-utilities)
- [🍽️ Food \& Wellness](#️-food--wellness)
- [🍽️ Food \& Wellness](#food-wellness)
- [Tailscale Information](#tailscale-information)
- [Tailscale Funnel vs. Tailscale Serve](#tailscale-funnel-vs-tailscale-serve)
- [Tailscale Funnel](#tailscale-funnel)
Expand Down Expand Up @@ -99,6 +99,7 @@ ScaleTail provides ready-to-run [Docker Compose](https://docs.docker.com/compose
| 📰 **FreshRSS** | A customizable feed reader with themes, extensions, and no separate database. | [Details](services/freshrss) |
| 🎥 **Frigate** | A self-hosted NVR with real-time AI object detection for IP cameras and local video monitoring. | [Details](services/frigate) |
| 🎮 **Hytale** | A self-hosted Hytale game server. | [Details](services/hytale) |
| ⛏️ **Minecraft** | A self-hosted Minecraft Java Edition server for private Tailnet multiplayer. | [Details](services/minecraft) |
| 🖼️ **Immich** | A self-hosted Google Photos alternative with face recognition and mobile sync. | [Details](services/immich) |
| 📺 **Jellyfin** | An open-source media system that puts you in control of managing and streaming your media. | [Details](services/jellyfin) |
| 📖 **Kavita** | An open-source, self-hosted digital library for comics, manga, and ebooks. | [Details](services/kavita) |
Expand All @@ -125,6 +126,7 @@ ScaleTail provides ready-to-run [Docker Compose](https://docs.docker.com/compose
| 💼 Service | 📝 Description | 🔗 Link |
| ------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------- |
| 💰 **Actual Budget** | A self-hosted personal finance and budgeting app focused on privacy and full data ownership. | [Details](services/actual-budget) |
| 🧠 **AFFiNE** | A self-hosted workspace for documents, whiteboards, and databases. | [Details](services/affine) |
| ⚓ **Anchor** | An offline-first, self-hosted note-taking app with sync, attachments, sharing, and optional OIDC authentication. | [Details](services/anchor) |
| 📄 **BentoPDF** | A lightweight, self-hosted web app for viewing and managing PDF documents. | [Details](services/bentopdf) |
| ✂️ **ClipCascade** | A self-hosted clipboard manager for syncing and organizing clipboard history. | [Details](services/clipcascade) |
Expand All @@ -150,6 +152,7 @@ ScaleTail provides ready-to-run [Docker Compose](https://docs.docker.com/compose
| 📥 **Mattermost** | A self-hosted collaborative workflow and communication tool. | [Details](services/mattermost) |
| 📝 **Memos** | A lightweight, self-hosted note-taking and knowledge management platform for capturing ideas, daily notes, and personal knowledge. | [Details](services/memos) |
| 📝 **Nanote** | A lightweight, self-hosted note-taking app with Markdown support. | [Details](services/nanote) |
| 📂 **NextExplorer** | A self-hosted file explorer for managing mounted directories. | [Details](services/next-explorer) |
| 🤖 **Open WebUI** | A self-hosted AI platform with a ChatGPT-style interface for local and cloud-based models. | [Details](services/open-webui) |
| 🔗 **Pingvin Share** | **PROJECT ARCHIVED** A self-hosted file sharing platform. | [Details](services/pingvin-share) |
| 📅 **Radicale** | A lightweight CalDAV and CardDAV server for self-hosted calendar, to-do, and contact sync. | [Details](services/radicale) |
Expand All @@ -171,6 +174,7 @@ ScaleTail provides ready-to-run [Docker Compose](https://docs.docker.com/compose
| 🏠 **Homepage** | A modern, highly customizable homepage for organizing links and monitoring services. | [Details](services/homepage) |
| 🖼️ **NewWallpaperWhoDis** | A lightweight, self-hosted wallpaper management server and dynamic rotation engine built on flat-file architecture. | [Details](services/newwallpaperwhodis) |

<a id="development-tools"></a>

### 🛠️ Development Tools

Expand All @@ -183,6 +187,7 @@ ScaleTail provides ready-to-run [Docker Compose](https://docs.docker.com/compose
| 🐳 **Dockhand** | A modern, lightweight Docker management UI for containers and Compose stacks. | [Details](services/dockhand) |
| 🐳 **Dockge** | A lightweight, self-hosted Docker Compose stack manager with a web UI. | [Details](services/dockge) |
| 🖥️ **Dozzle** | A real-time log viewer for Docker containers. | [Details](services/dozzle) |
| 📁 **Filebrowser** | A lightweight web file manager for a host directory. | [Details](services/filebrowser) |
| 🔁 **FossFLOW** | A self-hosted tool to make beautiful isometric infrastructure diagrams. | [Details](services/fossflow) |
| 🖥️ **GitSave** | A self-hosted service to back up your GitHub repositories via a simple REST API and scheduled runs. | [Details](services/gitsave) |
| 🖥️ **Gokapi** | A lightweight self-hosted file sharing platform. | [Details](services/gokapi) |
Expand Down Expand Up @@ -224,6 +229,8 @@ ScaleTail provides ready-to-run [Docker Compose](https://docs.docker.com/compose
| 🚗 **Tracktor** | Self-hosted vehicle maintenance tracker. | [Details](services/tracktor) |
| 🔁 **Transmute** | A self-hosted file conversion and transformation service for handling documents, media, and other format changes. | [Details](services/transmute) |

<a id="food-wellness"></a>

### 🍽️ Food & Wellness

| 🥘 Service | 📝 Description | 🔗 Link |
Expand Down Expand Up @@ -272,7 +279,7 @@ Made with [contrib.rocks](https://contrib.rocks).

## Contributing

See [CONTRIBUTING.md](/CONTRIBUTING.md) for guidance on adding services with the [template](/templates/service-template/) to keep Tailscale-sidecar setups consistent.
See [CONTRIBUTING.md](CONTRIBUTING.md) for guidance on adding services with the [template](templates/service-template/) to keep Tailscale-sidecar setups consistent.

## Star History

Expand Down
3 changes: 2 additions & 1 deletion services/actual-budget/.env
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,8 @@ SERVICEPORT=5006 # Port to expose to local network. Uncomment the "ports:" secti
DNS_SERVER=9.9.9.9 # Preferred DNS server for Tailscale. Uncomment the "dns:" section in compose.yaml to enable.

# Tailscale Configuration
TS_AUTHKEY= # Auth key from https://tailscale.com/admin/authkeys. See: https://tailscale.com/kb/1085/auth-keys#generate-an-auth-key for instructions.
TS_AUTHKEY=
# Auth key from https://tailscale.com/admin/authkeys. See: https://tailscale.com/kb/1085/auth-keys#generate-an-auth-key for instructions.

# Time Zone setting for containers
TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones
Expand Down
2 changes: 1 addition & 1 deletion services/actual-budget/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ When paired with Tailscale, Actual Budget becomes accessible across your devices

## Configuration Overview

In this setup, the `tailscale-actual` service runs Tailscale, which manages secure networking for Actual Budget. The `actual` service uses the Tailscale network stack via Docker's `network_mode: service:` configuration. This ensures the application is only reachable over your Tailnet unless you explicitly expose ports.
In this setup, the `tailscale-actual` service runs Tailscale, which manages secure networking for Actual Budget. The `actual` service uses the Tailscale network stack via Docker's `network_mode: service:tailscale` configuration. This ensures the application is only reachable over your Tailnet unless you explicitly expose ports.

## Key Features

Expand Down
2 changes: 1 addition & 1 deletion services/adguardhome-sync/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,4 +16,4 @@ This Docker Compose configuration sets up **[AdGuardHome Sync](https://github.co

## Configuration Overview

In this setup, the `tailscale-adguardhome-sync` service runs Tailscale, which manages secure networking for the AdGuardHome Sync service. The `adguardhome-sync` container uses the Tailscale network stack via Docker’s `network_mode: service:` configuration. This ensures that all sync communication is confined to your private Tailscale network, preventing exposure to the public internet.
In this setup, the `tailscale-adguardhome-sync` service runs Tailscale, which manages secure networking for the AdGuardHome Sync service. The `adguardhome-sync` container uses the Tailscale network stack via Docker’s `network_mode: service:tailscale` configuration. This ensures that all sync communication is confined to your private Tailscale network, preventing exposure to the public internet.
2 changes: 1 addition & 1 deletion services/adguardhome/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ This Docker Compose configuration sets up [AdGuard Home](https://github.com/Adgu

## Configuration Overview

In this setup, the `tailscale-adguardhome` service runs Tailscale, which manages secure networking for the AdGuard Home service. The `adguardhome` service uses the Tailscale network stack via Docker's `network_mode: service:` configuration. This setup ensures that AdGuard Home's DNS service is only accessible through the Tailscale network (or local as well, if preferred).
In this setup, the `tailscale-adguardhome` service runs Tailscale, which manages secure networking for the AdGuard Home service. The `adguardhome` service uses the Tailscale network stack via Docker's `network_mode: service:tailscale` configuration. This setup ensures that AdGuard Home's DNS service is only accessible through the Tailscale network (or local as well, if preferred).

## Binding to your local host machine? Port 53 - DNSStubListener

Expand Down
5 changes: 3 additions & 2 deletions services/affine/.env
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,8 @@ SERVICEPORT=3010 # Port to expose to local network. Uncomment the "ports:" secti
DNS_SERVER=9.9.9.9 # Preferred DNS server for Tailscale. Uncomment the "dns:" section in compose.yaml to enable.

# Tailscale Configuration
TS_AUTHKEY= # Auth key from https://tailscale.com/admin/authkeys. See: https://tailscale.com/kb/1085/auth-keys#generate-an-auth-key for instructions.
TS_AUTHKEY=
# Auth key from https://tailscale.com/admin/authkeys. See: https://tailscale.com/kb/1085/auth-keys#generate-an-auth-key for instructions.

# Time Zone setting for containers
TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones
Expand All @@ -30,4 +31,4 @@ AFFINE_SERVER_EXTERNAL_URL=https://affine.<YOUR_TS_DOMAIN>.ts.net
# database credentials
DB_USERNAME=affine
DB_PASSWORD=affine
DB_DATABASE=affine
DB_DATABASE=affine
2 changes: 1 addition & 1 deletion services/affine/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ AFFiNE is designed around modern knowledge work, blending structured content and

## Configuration Overview

In this setup, the `tailscale-affine` service runs Tailscale and handles secure networking for the stack. The `affine` service shares the Tailscale container's network namespace using Docker's `network_mode: service:` configuration. This means AFFiNE is reachable through your Tailnet without exposing it directly to the public internet.
In this setup, the `tailscale-affine` service runs Tailscale and handles secure networking for the stack. The `affine` service shares the Tailscale container's network namespace using Docker's `network_mode: service:tailscale` configuration. This means AFFiNE is reachable through your Tailnet without exposing it directly to the public internet.

This approach provides a secure and simple way to self-host AFFiNE privately, whether for personal note-taking, team collaboration, or internal documentation.

Expand Down
6 changes: 3 additions & 3 deletions services/affine/compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ services:
env_file:
- .env
environment:
# Varibles are delared in .env file.
# Variables are declared in .env file.
- REDIS_SERVER_HOST=redis
- DATABASE_URL=postgresql://${DB_USERNAME}:${DB_PASSWORD}@postgres:5432/${postgres:-affine}
- AFFINE_INDEXER_ENABLED=false
Expand All @@ -84,7 +84,7 @@ services:
env_file:
- .env
environment:
# Varibles are delared in .env file.
# Variables are declared in .env file.
- REDIS_SERVER_HOST=redis
- DATABASE_URL=postgresql://${DB_USERNAME}:${DB_PASSWORD}@postgres:5432/${postgres:-affine}
- AFFINE_INDEXER_ENABLED=false
Expand All @@ -111,7 +111,7 @@ services:
volumes:
- ./postgres:/var/lib/postgresql/data
environment:
# Varibles are delared in .env file.
# Variables are declared in .env file.
POSTGRES_USER: ${DB_USERNAME}
POSTGRES_PASSWORD: ${DB_PASSWORD}
POSTGRES_DB: ${postgres:-affine}
Expand Down
3 changes: 2 additions & 1 deletion services/anchor/.env
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,8 @@ SERVICEPORT=3000 # Port to expose to local network. Uncomment the "ports:" secti
DNS_SERVER=9.9.9.9 # Preferred DNS server for Tailscale. Uncomment the "dns:" section in compose.yaml to enable.

# Tailscale Configuration
TS_AUTHKEY= # Auth key from https://tailscale.com/admin/authkeys. See: https://tailscale.com/kb/1085/auth-keys#generate-an-auth-key for instructions.
TS_AUTHKEY=
# Auth key from https://tailscale.com/admin/authkeys. See: https://tailscale.com/kb/1085/auth-keys#generate-an-auth-key for instructions.

# Time Zone setting for containers
TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones
Expand Down
2 changes: 1 addition & 1 deletion services/anchor/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ This Docker Compose configuration sets up [Anchor](https://github.com/ZhFahim/an

## Configuration Overview

In this setup, the `tailscale-anchor` service runs Tailscale and manages secure networking for Anchor. The `anchor` service shares that network stack via Docker's `network_mode: service:` configuration, which keeps the app private to your Tailnet unless you intentionally add host port mappings or funnel it through another public entrypoint.
In this setup, the `tailscale-anchor` service runs Tailscale and manages secure networking for Anchor. The `anchor` service shares that network stack via Docker's `network_mode: service:tailscale` configuration, which keeps the app private to your Tailnet unless you intentionally add host port mappings or funnel it through another public entrypoint.

## Upstream documentation

Expand Down
6 changes: 4 additions & 2 deletions services/arcane/.env
Original file line number Diff line number Diff line change
Expand Up @@ -11,12 +11,14 @@ SERVICEPORT=3552 # Port to expose to local network. Uncomment the "ports:" secti
DNS_SERVER=9.9.9.9 # Preferred DNS server for Tailscale. Uncomment the "dns:" section in compose.yaml to enable.

# Tailscale Configuration
TS_AUTHKEY= # Auth key from https://tailscale.com/admin/authkeys. See: https://tailscale.com/kb/1085/auth-keys#generate-an-auth-key for instructions.
TS_AUTHKEY=
# Auth key from https://tailscale.com/admin/authkeys. See: https://tailscale.com/kb/1085/auth-keys#generate-an-auth-key for instructions.

# Time Zone setting for containers
TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones

# Optional Service variables
TAILNET_NAME= # for example: tail-scale
TAILNET_NAME=
# for example: tail-scale

#EXAMPLE_VAR="Environment varibale"
2 changes: 1 addition & 1 deletion services/arcane/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ This Docker Compose configuration sets up **Arcane** with a Tailscale sidecar co
In this deployment, a **Tailscale sidecar container** (for example `tailscale-arcane`) runs the Tailscale client and joins your private Tailscale network. The main `arcane` service uses:

```plain
network_mode: service:tailscale-arcane
network_mode: service:tailscale
```

This configuration routes all traffic through the Tailscale interface, ensuring that the Arcane web UI and API are accessible **only via your Tailscale network**. This provides a simple and secure way to access your Docker management console from all trusted devices while preventing public access to container controls.
Expand Down
5 changes: 3 additions & 2 deletions services/artisttrackarr/.env
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,8 @@ SERVICEPORT=8080 # Port to expose to local network. Uncomment the "ports:" secti
DNS_SERVER=9.9.9.9 # Preferred DNS server for Tailscale. Uncomment the "dns:" section in compose.yaml to enable.

# Tailscale Configuration
TS_AUTHKEY= # Auth key from https://tailscale.com/admin/authkeys. See: https://tailscale.com/kb/1085/auth-keys#generate-an-auth-key for instructions.
TS_AUTHKEY=
# Auth key from https://tailscale.com/admin/authkeys. See: https://tailscale.com/kb/1085/auth-keys#generate-an-auth-key for instructions.

# Optional Service variables
# PUID=1000
Expand All @@ -30,4 +31,4 @@ POLL_INTERVAL=6h
TRUST_PROXY=false
# SPOTIFY_CLIENT_ID=
# SPOTIFY_CLIENT_SECRET=
# SPOTIFY_MARKET=US
# SPOTIFY_MARKET=US
2 changes: 1 addition & 1 deletion services/artisttrackarr/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ Pairing ArtistTrackarr with Tailscale provides private access to its web interfa

## Configuration Overview

In this setup, the `tailscale-artist-trackarr` service runs Tailscale and manages secure networking for ArtistTrackarr. The `artist-trackarr` service uses the Tailscale container's network stack through Docker's `network_mode: service:tailscale-artist-trackarr` configuration.
In this setup, the `tailscale-artist-trackarr` service runs Tailscale and manages secure networking for ArtistTrackarr. The `artist-trackarr` service uses the Tailscale container's network stack through Docker's `network_mode: service:tailscale` configuration.

ArtistTrackarr listens on port `8080`. Because both containers share the same network namespace, Tailscale Serve can forward traffic directly to `http://127.0.0.1:8080`.

Expand Down
Loading