No description
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Johannes Zlattinger a83565a9b6
All checks were successful
Deploy / deploy (push) Successful in 41s
Add Grist deployment for grist.teurnia.net
Single grist-oss container behind the shared Traefik, SQLite storage in
/var/grist, logins via Forgejo OIDC. Deployed by Forgejo Actions on push
to main, matching the traefik.teurnia.net setup.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-09 10:26:05 +02:00
.forgejo/workflows Add Grist deployment for grist.teurnia.net 2026-08-09 10:26:05 +02:00
.gitignore Add Grist deployment for grist.teurnia.net 2026-08-09 10:26:05 +02:00
compose.yml Add Grist deployment for grist.teurnia.net 2026-08-09 10:26:05 +02:00
README.md Add Grist deployment for grist.teurnia.net 2026-08-09 10:26:05 +02:00

grist.teurnia.net

Grist (open-source edition), behind the shared Traefik on traefik_proxy, deployed by Forgejo Actions on every push to main.

Single container, SQLite home database and documents under /persist. Logins go through git.teurnia.net via OpenID Connect.

One-time setup

1. OAuth2 application in Forgejo

In git.teurnia.net → Site Administration → Applications (or User Settings → Applications for a personal app), create an OAuth2 application:

  • Application Name: Grist
  • Redirect URI: https://grist.teurnia.net/oauth2/callback
  • Confidential Client: enabled

Keep the generated client ID and client secret.

2. Repository configuration in Forgejo

Under Settings → Actions of this repository:

Kind Name Value
Variable GRIST_DEFAULT_EMAIL Your Forgejo account email — becomes the install admin
Variable GRIST_OIDC_IDP_CLIENT_ID Client ID from step 1
Secret GRIST_OIDC_IDP_CLIENT_SECRET Client secret from step 1
Secret GRIST_SESSION_SECRET openssl rand -hex 32

GRIST_DEFAULT_EMAIL must match the email Forgejo reports for your account, otherwise you log in as an ordinary user. Changing it later does not move admin rights — the account is created on first start.

3. Deploy

Push to main. The workflow runs docker compose -p grist up -d --pull always against the host's Docker socket, same as the other services on this host.

Configuration notes

  • Team site: GRIST_SINGLE_ORG=teurnia is created on first start, owned by GRIST_DEFAULT_EMAIL. With GRIST_ORG_IN_PATH=false documents live at https://grist.teurnia.net/doc/… instead of /o/teurnia/doc/….
  • Access: GRIST_FORCE_LOGIN=true sends anonymous visitors straight to Forgejo. Anyone with an account on git.teurnia.net can sign in and gets a personal workspace; sharing documents with them is done from Grist.
  • OIDC compatibility: GRIST_OIDC_SP_IGNORE_EMAIL_VERIFIED is required because Forgejo's userinfo endpoint does not return an email_verified claim, and GRIST_OIDC_IDP_SKIP_END_SESSION_ENDPOINT because Forgejo has no RP-initiated logout endpoint.
  • Sandbox: formulas run under gVisor, which the image is built for. If formula evaluation fails on this kernel, set GRIST_SANDBOX_FLAVOR=unsandboxed.
  • Edition: gristlabs/grist-oss is the Apache-2.0 build. Swap it for gristlabs/grist to get the Enterprise feature toggle (free up to two users, activation key beyond that).
  • First run: GRIST_IN_SERVICE=true skips the boot-key screen and the setup wizard, since everything is configured here. The admin panel stays available at /admin.

Data and backups

Everything lives in /var/grist on the host: home.sqlite3 (users, orgs, ACLs), grist-sessions.db, and docs/ (one SQLite file per document). Stop the container or take a filesystem snapshot before copying.

Trying the image locally

compose.yml is written for the server — it needs the traefik_proxy network and its OIDC redirects point at https://grist.teurnia.net. To poke at Grist on this machine, run the image directly instead:

docker run --rm -p 8484:8484 -v "$PWD/persist:/persist" \
  -e GRIST_SESSION_SECRET=dev -e GRIST_DEFAULT_EMAIL=you@example.com \
  -e GRIST_IN_SERVICE=true gristlabs/grist-oss:stable