Wraps the existing manually-run Vikunja instance on PIHA in the standard service layout. No deploy — definition only, for review. - services/vikunja/: docker-compose.yml (vikunja + postgres:16-alpine), service.yaml, README, healthcheck, config.yml (OIDC, secret-free), .env.example. Real .env stays gitignored. - Pins EXISTING named volumes (vikunja_vikunja_db, vikunja_vikunja_files) so DB + uploaded files survive cutover. - extra_hosts forgejo.okit.pl=192.168.31.5 (npm on PIHA) so OIDC discovery resolves over LAN instead of flaky public DNS. - OIDC client secret injected via env (VIKUNJA_AUTH_OPENID_PROVIDERS_ FORGEJO_CLIENTSECRET); config.yml keeps trailing-slash authurl/redirecturl. - Registers vikunja in hosts/piha/services.yaml + inventory/topology.yaml, plus hosts/piha/runtime/vikunja override (advisory mem_limits). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1.8 KiB
1.8 KiB
Vikunja
Self-hosted task management. Runs on the PIHA node with a dedicated
PostgreSQL backend, exposed publicly at https://vikunja.okit.pl via the npm
reverse proxy on PIHA. Login is via Forgejo OIDC.
Stack
| Container | Image | Purpose |
|---|---|---|
vikunja |
vikunja/vikunja:latest |
App + API (port 3456) |
vikunja-db |
postgres:16-alpine |
PostgreSQL (service alias db) |
Data (do not move)
Persistent state lives in pre-existing Docker named volumes — these are pinned by name so the live data survives cutover:
vikunja_vikunja_db→/var/lib/postgresql/datavikunja_vikunja_files→/app/vikunja/files
Configuration
config.yml— committed, secret-free. Holds OIDC provider metadata..env— gitignored. Copy from.env.exampleand fill with the real live values (must be identical to the running instance):POSTGRES_PASSWORD/VIKUNJA_DATABASE_PASSWORD(same value)VIKUNJA_SERVICE_JWTSECRETVIKUNJA_AUTH_OPENID_PROVIDERS_FORGEJO_CLIENTSECRET
Notes
forgejo.okit.plis pinned viaextra_hoststo192.168.31.5(npm on PIHA) so OIDC discovery resolves over the LAN, avoiding flaky public DNS.- Both
redirecturland the providerauthurlMUST keep their trailing slash — theauthurlmust match the OIDC issuer exactly or discovery fails.
Cutover checklist
git pullon PIHA.- Create
services/vikunja/.envfrom.env.examplewith the real values. - Confirm the named volumes exist:
docker volume ls | grep vikunja_vikunja. docker compose -f services/vikunja/docker-compose.yml up -d.- Verify:
./healthcheck.shand a test OIDC login.