| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
Deploy / deploy (push) Successful in 41s
Single grist-oss container behind the shared Traefik, SQLite storage in /var/grist, logins via Forgejo OIDC. Deployed by Forgejo Actions on push to main, matching the traefik.teurnia.net setup. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
| .forgejo/workflows | ||
| .gitignore | ||
| compose.yml | ||
| README.md | ||
grist.teurnia.net
Grist (open-source edition), behind the shared Traefik on
traefik_proxy, deployed by Forgejo Actions on every push to main.
Single container, SQLite home database and documents under /persist. Logins go through
git.teurnia.net via OpenID Connect.
One-time setup
1. OAuth2 application in Forgejo
In git.teurnia.net → Site Administration → Applications (or User Settings →
Applications for a personal app), create an OAuth2 application:
- Application Name:
Grist - Redirect URI:
https://grist.teurnia.net/oauth2/callback - Confidential Client: enabled
Keep the generated client ID and client secret.
2. Repository configuration in Forgejo
Under Settings → Actions of this repository:
| Kind | Name | Value |
|---|---|---|
| Variable | GRIST_DEFAULT_EMAIL |
Your Forgejo account email — becomes the install admin |
| Variable | GRIST_OIDC_IDP_CLIENT_ID |
Client ID from step 1 |
| Secret | GRIST_OIDC_IDP_CLIENT_SECRET |
Client secret from step 1 |
| Secret | GRIST_SESSION_SECRET |
openssl rand -hex 32 |
GRIST_DEFAULT_EMAIL must match the email Forgejo reports for your account, otherwise you log
in as an ordinary user. Changing it later does not move admin rights — the account is created on
first start.
3. Deploy
Push to main. The workflow runs docker compose -p grist up -d --pull always against the
host's Docker socket, same as the other services on this host.
Configuration notes
- Team site:
GRIST_SINGLE_ORG=teurniais created on first start, owned byGRIST_DEFAULT_EMAIL. WithGRIST_ORG_IN_PATH=falsedocuments live athttps://grist.teurnia.net/doc/…instead of/o/teurnia/doc/…. - Access:
GRIST_FORCE_LOGIN=truesends anonymous visitors straight to Forgejo. Anyone with an account ongit.teurnia.netcan sign in and gets a personal workspace; sharing documents with them is done from Grist. - OIDC compatibility:
GRIST_OIDC_SP_IGNORE_EMAIL_VERIFIEDis required because Forgejo'suserinfoendpoint does not return anemail_verifiedclaim, andGRIST_OIDC_IDP_SKIP_END_SESSION_ENDPOINTbecause Forgejo has no RP-initiated logout endpoint. - Sandbox: formulas run under gVisor, which the image is built for. If formula evaluation
fails on this kernel, set
GRIST_SANDBOX_FLAVOR=unsandboxed. - Edition:
gristlabs/grist-ossis the Apache-2.0 build. Swap it forgristlabs/gristto get the Enterprise feature toggle (free up to two users, activation key beyond that). - First run:
GRIST_IN_SERVICE=trueskips the boot-key screen and the setup wizard, since everything is configured here. The admin panel stays available at/admin.
Data and backups
Everything lives in /var/grist on the host: home.sqlite3 (users, orgs, ACLs),
grist-sessions.db, and docs/ (one SQLite file per document). Stop the container or take a
filesystem snapshot before copying.
Trying the image locally
compose.yml is written for the server — it needs the traefik_proxy network and its OIDC
redirects point at https://grist.teurnia.net. To poke at Grist on this machine, run the image
directly instead:
docker run --rm -p 8484:8484 -v "$PWD/persist:/persist" \
-e GRIST_SESSION_SECRET=dev -e GRIST_DEFAULT_EMAIL=you@example.com \
-e GRIST_IN_SERVICE=true gristlabs/grist-oss:stable