Skip to content
NEXDIARY

Getting started · Chapter 1

Setting up nexdiary

nexdiary runs as a single Docker container on your own server, a NAS for instance or a small computer at home. This chapter takes you as far as the first account. Putting nexdiary behind a reverse proxy, the environment variables and how updates work are covered in full under Self-hosting.

What you need

  • A machine with Docker and Docker Compose. The image is built for Intel and AMD processors (amd64) and for ARM (arm64).
  • A folder on a local disk for the data. An SMB or NFS share will not do, because the SQLite database cannot rely on its locks over a network drive.
  • An authenticator app on your phone, for the second factor. Any app that shows six-digit codes is fine.

Starting the server

  1. Create the compose file

    Take the file from the Self-hosting page. It pulls the image ghcr.io/derkezorm/nexdiary, keeps the data in the folder ./data and sets PUID, PGID and the time zone TZ.

  2. Start the container

    In the folder of the file:

    Shell
    docker compose up -d
  3. Fetch the setup code

    When it starts, nexdiary writes a setup code to its log. A new one is made at every start until the first account exists. If you would rather choose the code yourself, set NEXDIARY_SETUP_TOKEN.

    Shell
    docker logs nexdiary
  4. Open nexdiary

    The template opens port 8550 on the machine itself only. There you reach nexdiary at http://127.0.0.1:8550. To reach it from your home network, write 8550:8000 in the compose file instead of 127.0.0.1:8550:8000. Without https, though, passwords and codes then cross the network unencrypted. For everyday use a reverse proxy with https belongs in front of it.

Creating the first account

The first page is called “Set up nexdiary”. The account you create here runs the server. It invites the family and may change every setting, but it never sees the others' diaries. The setup code makes sure that nobody who happens to reach a fresh instance first can take it over.

  1. Enter the code, a name and a password

    The code from the log goes into “Setup code”. The “Name” is what you sign in with, 2 to 64 characters made of letters without accents, digits, dot, hyphen or underscore. The “Password” has at least 12 characters. Then tap “Create account”.

  2. Set up the second factor

    Straight afterwards nexdiary asks for the second factor. From the start it is required for every account that signs in with a password. Scan the QR code with your authenticator app or type in the key below it, enter the six digits the app shows under “Code from the app” and press “Turn on”.

  3. Keep the recovery codes

    Now nexdiary shows eight recovery codes, and only this once. Each one signs you in once when your phone is not at hand. Take them with “Copy” or “Save as file”. Keep them apart from the phone, then tap “I have them, go on”.

Set up nexdiary
The page “Set up nexdiary” with setup code, name and password
The first page of a fresh instance.

After that you land on “Today” and can start writing. Rather do without the app? A passkey, signing in with your fingerprint, face or the device's PIN, can be added later under “My account” on the “Security” tab. Passkeys need an address with https, or localhost.

Worth doing straight away

  • Save the master key. nexdiary encrypts what each person writes with a key of their own. Those keys depend on a master key that nexdiary makes at the first start. Under “Settings”, “Backup” tab, “Encryption” card, “Save master key” downloads it. Without it no backup can be read, not even by you.
  • Know your backups. From the start nexdiary backs up every night and keeps seven backups, in the data folder on the same server. A copy somewhere else is yours to make. More in the chapter Backups.
  • Check before going online. The card “Ready for the internet?” under “Settings”, “Sign-in” tab, checks eight points by itself, from https to a saved master key. More under Security.
  • Invite your family. How that works is the next chapter, Inviting your family.

Good to knowThe first account has no mail address, and as the operator you have nobody above you to send you a reset link. If you forget your password, make the link yourself inside the container with docker exec -it -u nexdiary nexdiary python -m app.reset_link <your-name>. It works once and for 24 hours, and your second factor stays.