Skip to main content
Installation is a single script. It handles secrets, backend deployment, environment wiring, and service startup in one pass. You do not need to configure anything before running it unless you plan to serve on a real domain (covered below).
1

Clone the repository

Clone OneRep from GitHub and move into the selfhost directory, which contains the installer and the Docker Compose file:
2

Run the installer

Run the install script:
The script asks one question: whether to enable anonymous telemetry (default yes; choosing no means no analytics script is built into the app at all). After that it runs without further input.What the script does:
  1. Writes selfhost/.env with freshly generated secrets
  2. Brings up the Convex backend container
  3. Deploys the Convex functions to the backend
  4. Sets the deployment’s environment variables
  5. Builds and starts the datasource and the app
When it finishes it prints your admin key and the URLs where services are running:
The installer also prints the food database import commands so you have them to hand. See the Food Database guide for the full walkthrough.
3

Verify the install

Open http://127.0.0.1:8081 in your browser. You should see the OneRep sign-in screen. Create an account. It will have full Pro access with no paywall.The dashboard at http://127.0.0.1:6791 is where you inspect data and manage backend environment variables.

Serving on a real domain

The default configuration binds to 127.0.0.1, so the install is reachable only from the machine it runs on. Opening it up means giving three services a hostname each — the app, the Convex client API, and the Convex HTTP actions. They are separate origins and there is no single-port shortcut. For a LAN address, export PUBLIC_HOST before the first run and the installer wires the three plain-HTTP origins for you:
That gets you http://192.168.1.10:8081 from a phone on the same network, which is enough to try it out. For a real domain with TLS, you need a reverse proxy in front, and the Convex socket needs its upgrade headers forwarded or the app will load and never show any data. The Reverse proxy guide has working Caddy, nginx, and Traefik configurations, plus the two settings people get wrong.
Changing the origins in selfhost/.env requires re-running ./install.sh. The app’s backend URLs are compiled into the static bundle, and the backend learns which origin to trust from the installer. A plain docker compose up -d --build updates neither.

Re-running the installer

Re-running ./install.sh is safe at any time. The existing secrets in selfhost/.env are kept, and the deploy is idempotent: functions and environment variables are updated in place. Use this whenever you pull new changes or adjust configuration.