Skip to main content

Self-host setup builder

Editing an existing .env? Drop it anywhere, or

This is self-host setup: it writes the .env for running Cobblr on your own machine. Hosted Cobblr needs none of it. If you wanted that, start at cobblr.xyz, where the sandbox needs no account and the hosted start is the button in the corner.

Fills in the blanks of the self-host .env. Everything runs in your browser; nothing you type leaves this page. Secrets are pre-generated for you, and each lives on exactly one line: the stack derives the database connection strings, so changing the password later is a one-line edit.

1 · How you'll reach it
Tailscale, two ways:
This has to match the machine's full name in the Tailscale admin console exactly, tailnet included. The first part becomes the node's name, and your tailnet name (the middle part) is on the admin console's DNS page. It is often not tail1234, so read it rather than guessing from the shape of this placeholder. Just the name, no https:// (pasting one strips it).Joining your tailnet:

Easiest. No key to mint: on first start, the box asks Tailscale to authorize it and the caddy logs print a one-time link (docker compose logs caddy). Open it, sign in, approve.

Either way, the bundled proxy joins your tailnet as its own node and serves the address above; the box needs no Tailscale install. MagicDNS + HTTPS certificates must be enabled on the tailnet. See Install.

2 · Operator & secretsRegister with this address and your account unlocks the /admin console: instance settings, and the invites that let people in once signup is closed.
Postgres password and JWT secret are generated too (see the preview); those are replaceable. The encryption key is not: lose it and stored integration credentials are gone.
3 · Email (optional)

Password login works; invites become copy-the-link. Magic-link sign-in needs a sender.

4 · Barcode network (recommended)

Open databases cover groceries, books, and music. The barcode network covers the rest: electronics, tools, hardware, craft supplies. You get everyone else's corrections, and yours go back in.

No key yet? Leave it blank. The lines go into your .env commented out, so you can join later without regenerating anything.

5 · Privacy
6 · Advanced
What landed the day before. Recommended while Cobblr is in active development: fixes and features arrive daily, and the updater below keeps you on them.
A small updater container checks for newer images every four hours and restarts only the ones that changed. About one build is published a day, so that is about one restart a day, and no fixed hour has to be the right one where you live. Your .env carries a commented line if you would rather pick the moment. It needs the Docker socket, which is why it is a choice and not the default.One line moves every mount (database, files, modules, TLS certs) onto a data disk, NAS, or an appdata root you already use. Copying that one folder is still a full backup.
.env (you fill this in)
Still need the address, your email. Confirm the key backup in section 2. Copy and Download unlock once these are done.
# Cobblr self-host, generated by the setup builder.

# ── 1. REQUIRED ─────────────────────────────
COBBLR_SITE_ADDRESS=
SUPERADMIN_EMAILS=
POSTGRES_PASSWORD=kqd3WXcRaTv6gcGfMDzZ89z8
JWT_SECRET=be96ac90fb6e5b39570a94c846f87ef07861c0abfa1bc19cc314924b733f88b6
# back the next line up somewhere safe. Unrecoverable:
TENANT_CREDS_ENCRYPTION_KEY=51330c1ef6cd9834ae628350111d1de9
# set false after your account exists, especially if exposing your instance to the public:
PUBLIC_SIGNUP_ENABLED=true

# ── 2. HTTPS ────────────────────────────────
# the proxy joins your tailnet as its own node; no tailscale on the box
COMPOSE_PROFILES=caddy,autoupdate
COBBLR_TLS_MODE=tsnet
# TS_AUTHKEY left empty: on first start, open the approval link
#   printed in the caddy logs (docker compose logs caddy) and sign in.

# ── 3. EMAIL ────────────────────────────────
# none configured. Password login works;
# invites are copy-the-link.

# ── 4. BARCODE NETWORK ──────────────────────
# Coverage beyond groceries, books, and music, and your corrections
# help everyone else. Get a per-install key at account.cobblr.xyz,
# paste it below, and uncomment both lines. Both, or neither: a URL
# with no key is refused on every scan. Nothing else changes.
# COBBLR_BIDB_URL=https://barcodes.cobblr.xyz
# COBBLR_BIDB_KEY=

# ── 5. PRIVACY ──────────────────────────────
# COBBLR_AI_ENABLED=false
# COBBLR_SCAN_EXTERNAL_LOOKUPS=false

# ── 6. ADVANCED ─────────────────────────────
# The development channel: what landed the day before.
COBBLR_VERSION=nightly
# Auto-update: the autoupdate profile above checks for newer images every
# four hours and restarts only the Cobblr containers that changed. About one
# build is published a day, so that is about one restart a day. Uncomment
# these two to pick a fixed hour in your own zone instead:
# WATCHTOWER_SCHEDULE=0 0 8 * * *   # six fields, seconds first
# WATCHTOWER_TZ=UTC
# COBBLR_DATA_ROOT=./data  # move all data (db, files, modules, certs) onto a NAS or data disk
# DB connection strings derive from POSTGRES_PASSWORD in the stack;
# set DATABASE_URL / SUPERUSER_DATABASE_URL only for an external Postgres.
docker-compose.yml (same for everyone)Download
# loading docker-compose.yml…
Drop both files in a folder together, thendocker compose up -d. See Install for the full walkthrough.