homelab-codex-ws/services/vikunja/README.md
Oskar Kapala f7e1391f30 feat(vikunja): bring PIHA Vikunja under GitOps (postgres + Forgejo OIDC)
Wraps the existing manually-run Vikunja instance on PIHA in the standard
service layout. No deploy — definition only, for review.

- services/vikunja/: docker-compose.yml (vikunja + postgres:16-alpine),
  service.yaml, README, healthcheck, config.yml (OIDC, secret-free),
  .env.example. Real .env stays gitignored.
- Pins EXISTING named volumes (vikunja_vikunja_db, vikunja_vikunja_files)
  so DB + uploaded files survive cutover.
- extra_hosts forgejo.okit.pl=192.168.31.5 (npm on PIHA) so OIDC discovery
  resolves over LAN instead of flaky public DNS.
- OIDC client secret injected via env (VIKUNJA_AUTH_OPENID_PROVIDERS_
  FORGEJO_CLIENTSECRET); config.yml keeps trailing-slash authurl/redirecturl.
- Registers vikunja in hosts/piha/services.yaml + inventory/topology.yaml,
  plus hosts/piha/runtime/vikunja override (advisory mem_limits).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-17 15:02:37 +02:00

1.8 KiB

Vikunja

Self-hosted task management. Runs on the PIHA node with a dedicated PostgreSQL backend, exposed publicly at https://vikunja.okit.pl via the npm reverse proxy on PIHA. Login is via Forgejo OIDC.

Stack

Container Image Purpose
vikunja vikunja/vikunja:latest App + API (port 3456)
vikunja-db postgres:16-alpine PostgreSQL (service alias db)

Data (do not move)

Persistent state lives in pre-existing Docker named volumes — these are pinned by name so the live data survives cutover:

  • vikunja_vikunja_db/var/lib/postgresql/data
  • vikunja_vikunja_files/app/vikunja/files

Configuration

  • config.yml — committed, secret-free. Holds OIDC provider metadata.
  • .envgitignored. Copy from .env.example and fill with the real live values (must be identical to the running instance):
    • POSTGRES_PASSWORD / VIKUNJA_DATABASE_PASSWORD (same value)
    • VIKUNJA_SERVICE_JWTSECRET
    • VIKUNJA_AUTH_OPENID_PROVIDERS_FORGEJO_CLIENTSECRET

Notes

  • forgejo.okit.pl is pinned via extra_hosts to 192.168.31.5 (npm on PIHA) so OIDC discovery resolves over the LAN, avoiding flaky public DNS.
  • Both redirecturl and the provider authurl MUST keep their trailing slash — the authurl must match the OIDC issuer exactly or discovery fails.

Cutover checklist

  1. git pull on PIHA.
  2. Create services/vikunja/.env from .env.example with the real values.
  3. Confirm the named volumes exist: docker volume ls | grep vikunja_vikunja.
  4. docker compose -f services/vikunja/docker-compose.yml up -d.
  5. Verify: ./healthcheck.sh and a test OIDC login.