Prepare the checkout
Configure the installation
Edit.env with your own values:
AUTH_KEY: a high-entropy primary Bearer key with at least 32 random bytes.POSTGRES_PASSWORD: the database password used by Compose.ROOT_EMAILandROOT_PASSWORD: the root credentials for dashboard sign-in, key generation and OAuth consent. Use at least 15 non-padding password characters. The password must differ fromAUTH_KEY.DEFAULT_TIMEZONE: the IANA timezone used for dates and daily summaries.
PUBLIC_BASE_URL=http://127.0.0.1:3000, API_BASE_URL=http://127.0.0.1:3000 and UI_BASE_URL=http://127.0.0.1:3001. Never commit .env.
http://127.0.0.1:3001/login. The API listens on loopback port 3000 and the UI on loopback port 3001. Compose keeps PostgreSQL on its private network and stores its data in a named volume.
Add public HTTPS origins
Use separate UI and API origins behind your TLS ingress:API_INTERNAL_BASE_URL=http://api:3000 for private server reads. Use Configuration to configure trusted proxies and allowed browser-client origins for your ingress.
For a Towbar deployment, use the checked-in PostgreSQL, API and web manifests.
Develop locally
The repository requires Node.js 24.16 and npm 11.13. Start PostgreSQL and provideDATABASE_URL in .env, then run:
npm run dev:web. The API and web app read the root .env. Apply forward migrations with npm run db:migrate; do not use schema push for production upgrades.