This is the sekrit demo. Nothing here is real and nobody pays anyone. Each visitor gets their own sandbox, deleted after 24 hours.

shhh…sekrit

Help · Running sekrit

Run your own copy

sekrit runs anywhere Docker runs — a VPS, an old box under a desk, a Raspberry Pi. Images are built for amd64 and arm64.

Start it #

git clone https://github.com/IamMrCupp/sekrit.git
cd sekrit
cp .env.example .env
# set POSTGRES_PASSWORD and APP_DB_PASSWORD — generate each with: openssl rand -hex 24
docker compose up -d --build

Then browse to http://localhost:8080 and register the first promoter account.

Everything comes through one front door. Caddy routes /api/* to the API and the rest to the web app, so there's one origin and nothing else is exposed. The database sets itself up on start — there's no separate setup step.

Two database passwords. POSTGRES_PASSWORD belongs to the database owner, and only the short-lived migrate step uses it, to change the schema. The app connects with APP_DB_PASSWORD, as a role that can read and write rows but can't drop or alter a table. A bug in the app, or someone exploiting one, gets what the app can do, not everything the database can.

Put it on a domain #

In .env, set:

Point the domain's DNS at the box, and Caddy fetches a certificate on its own.

Production needs HTTPS. With ENVIRONMENT=production the login cookie only travels over HTTPS — over plain HTTP, login will look like it worked and then quietly fail.

.env.example lists every setting sekrit reads. If it isn't in there, it isn't configurable.

Back it up #

Everything that matters is in Postgres, plus the uploaded flyers. A nightly dump is enough for most people:

docker compose exec -T db pg_dump -U sekrit sekrit | gzip > sekrit-$(date +%F).sql.gz

Keep copies somewhere other than the box itself. Flyers live in the media volume — back that up alongside the database, because the database points at those files.

Test a restore before you need one. A backup you've never restored is a hope, not a backup. After restoring into a fresh database, run docker compose run --rm migrate so the app's role and its access are set up again.

Update #

git pull
docker compose up -d --build

The migrate step runs first, then the app starts. Take a backup first.

Updating from a version before September 2026? Add APP_DB_PASSWORD to your .env (openssl rand -hex 24). Compose refuses to start without it and tells you so.

These docs #

They ship with the app, so the help on your copy always matches the version it's running.