Domain & HTTPS
Installing the app on a phone and push notifications only work over HTTPS.
The docker-compose.prod.yml override puts Caddy
in front of Loomkeep: it serves the app and the API on one domain, and gets
and renews a Let’s Encrypt certificate on its own.
-
Point your domain at the server: an
Arecord (andAAAAwith IPv6) to its public IP. Open ports 80 and 443, in the server’s firewall and, on a VPS, in the provider’s network firewall too. Port 80 is needed for the certificate, then redirects to 443. -
Set the domain in
.env. The API and web addresses follow from it:Terminal window DOMAIN=loomkeep.example.com -
Add the override to
COMPOSE_FILE, then restart:Terminal window COMPOSE_FILE=docker/docker-compose.yml:docker/docker-compose.prod.ymlTerminal window docker compose pulldocker compose up -d -
Open
https://<DOMAIN>. The first request can take a few seconds while Caddy gets the certificate. If it doesn’t come up,docker compose logs caddysays why: most often DNS not propagated yet, or a port still blocked.
The override stops publishing ports 3000 and 8080: only Caddy is reachable. It also tells the API to trust the one proxy in front of it, so rate limits and logs see visitors’ real addresses.
Behind Cloudflare
Section titled “Behind Cloudflare”Proxying through Cloudflare, a challenge on the sign-up form, a login in front of the admin tools: see Behind Cloudflare.
Using another reverse proxy
Section titled “Using another reverse proxy”Already running Traefik, nginx or another proxy? Skip the override: keep the
base setup’s two ports, route your domain’s /api to port 3000 and the rest
to port 8080, then set in .env:
PUBLIC_API_URL=https://loomkeep.example.com/apiWEB_ORIGIN=https://loomkeep.example.comSo that rate limits and logs see visitors’ real addresses rather than your
proxy’s, tell the API to trust it, in a small override of your own, for
instance docker/docker-compose.proxy.yml, added to COMPOSE_FILE:
services: api: environment: TRUST_PROXY_HOPS: "1"