Skip to content

Docker Deployment

gysosin edited this page Oct 8, 2026 · 1 revision

Docker deployment

Run Apply Desk always on, restarting with your machine, at https://applydesk.localhost.

What runs

Service Role
applydesk the app (Python 3, bubblewrap, poppler), listening only on the internal Docker network
router nginx: TLS on host port 443 (80 redirects), the only published service, bound to 127.0.0.1

The repo, TinyTeX (~/.TinyTeX), bun (~/.bun), your Claude login (~/.claude) and the config (~/.config/applydesk) are mounted from the host, so the image stays small and your data stays in one place.

Steps

# 1. A local HTTPS certificate for applydesk.localhost
sh app/deploy/make-cert.sh

# 2. Trust its CA once
sudo trust anchor ~/.config/applydesk-tls/applydesk-ca.crt        # Fedora, Arch
# Debian/Ubuntu: sudo cp ~/.config/applydesk-tls/applydesk-ca.crt /usr/local/share/ca-certificates/applydesk.crt && sudo update-ca-certificates
# Chrome also needs: certutil -d sql:$HOME/.pki/nssdb -A -t C,, -n "Apply Desk Local CA" -i ~/.config/applydesk-tls/applydesk-ca.crt

# 3. Only for a token or API key (subscription login needs nothing)
cp app/.env.example app/.env && $EDITOR app/.env

# 4. Start
docker compose -f app/docker-compose.yml up -d --build

*.localhost resolves to your machine automatically; no DNS or /etc/hosts edit.

Day to day

docker compose -f app/docker-compose.yml ps                  # status
docker compose -f app/docker-compose.yml logs -f applydesk   # logs
docker compose -f app/docker-compose.yml restart applydesk   # after code changes
docker compose -f app/docker-compose.yml down                # stop
docker compose -f app/docker-compose.yml exec applydesk python -m app selftest

Restarting signs you out (sessions are kept in memory). Check the Runs page first so you don't cut off a running task.

Notes

  • The container runs as your user (UID/GID, default 1000) so files it writes stay yours.
  • bubblewrap needs user namespaces inside the container; app/deploy/seccomp-bwrap.json is Docker's default profile plus only those syscalls.
  • On SELinux hosts, label=disable avoids relabelling your home directories.
  • Port 443 already taken? Change the ports of router in app/docker-compose.yml.

Clone this wiki locally