Help · Running sekrit
Run your own copy
sekrit runs anywhere Docker runs — a VPS, an old box under a desk, a Raspberry Pi. Images are built for amd64 and arm64.
Start it #
git clone https://github.com/IamMrCupp/sekrit.git
cd sekrit
cp .env.example .env
# set POSTGRES_PASSWORD and APP_DB_PASSWORD — generate each with: openssl rand -hex 24
docker compose up -d --build
Then browse to http://localhost:8080 and register the first promoter account.
Everything comes through one front door. Caddy routes /api/* to the API and the rest to the web app, so there's one origin and nothing else is exposed. The database sets itself up on start — there's no separate setup step.
Two database passwords. POSTGRES_PASSWORD belongs to the database owner, and only the short-lived migrate step uses it, to change the schema. The app connects with APP_DB_PASSWORD, as a role that can read and write rows but can't drop or alter a table. A bug in the app, or someone exploiting one, gets what the app can do, not everything the database can.
Put it on a domain #
In .env, set:
SITE_ADDRESS=tickets.example.comHTTP_PORT=80andHTTPS_PORT=443PUBLIC_URL=https://tickets.example.comENVIRONMENT=production
Point the domain's DNS at the box, and Caddy fetches a certificate on its own.
Production needs HTTPS. With ENVIRONMENT=production the login cookie only travels over HTTPS — over plain HTTP, login will look like it worked and then quietly fail.
.env.example lists every setting sekrit reads. If it isn't in there, it isn't configurable.
Back it up #
Everything that matters is in Postgres, plus the uploaded flyers. A nightly dump is enough for most people:
docker compose exec -T db pg_dump -U sekrit sekrit | gzip > sekrit-$(date +%F).sql.gz
Keep copies somewhere other than the box itself. Flyers live in the media volume — back that up alongside the database, because the database points at those files.
Test a restore before you need one. A backup you've never restored is a hope, not a backup. After restoring into a fresh database, run docker compose run --rm migrate so the app's role and its access are set up again.
Update #
git pull
docker compose up -d --build
The migrate step runs first, then the app starts. Take a backup first.
Updating from a version before September 2026? Add APP_DB_PASSWORD to your .env (openssl rand -hex 24). Compose refuses to start without it and tells you so.
These docs #
They ship with the app, so the help on your copy always matches the version it's running.