Bookmark manager (Go, single binary). Single container, SQLite in a named volume. Default admin (shiori/gopher) is auto-created on first run. Known issue: Shiori v1.7.0's SPA wizard detection panics with HTTP 500 on the first /api/bookmarks request when no session exists. The setup wizard does NOT appear on first visit — log in with the default credentials above and change the password immediately. Port 8080 inside the sidecar namespace. Optional SHIORI_HTTP_SECRET_KEY env var would persist sessions across restarts (not enabled by default).
Shiori with Tailscale Integration
A self-hosted bookmark manager (Go, single binary) running on your tailnet, fronted by a Tailscale sidecar.
Quick Start (Tailscale)
- Copy the example environment file and fill in your values:
cp .env.example .env - Edit
.envand set:TS_AUTHKEY— your Tailscale auth key
- Start the stack:
docker compose up -d - Browse to
https://shiori.<your-tailnet>.ts.netand log in with the default credentials:- Username:
shiori - Password:
gopher
- Username:
- Change the password immediately (Settings → Account).
Note: Shiori v1.7.0 has a known issue where the SPA's "setup wizard" detection panics with HTTP 500 on the first request when no session exists. The wizard does NOT appear on first visit. Just log in with the default credentials above and change the password.
Headscale
If you're using Headscale instead of Tailscale:
- Copy the example environment file:
cp .env.example .env - Edit
.envand set:TS_AUTHKEY— your Headscale auth keyTS_LOGIN_SERVER— your Headscale server URL
- Switch to the Headscale serve config:
cp tailscale/config/serve.headscale.json tailscale/config/serve.json - Edit
serve.jsonand replaceshiori.damconsulting.netwith your actual domain. - Start the stack:
docker compose up -d - Browse to
http://shiori.yourdomain.comand complete the setup wizard.
Configuration
See .env.example for all available options. The app accepts no env vars
beyond what the sidecar requires — Shiori uses SQLite by default and stores
its data in SHIORI_DIR=/srv/shiori (a named volume).
Switching Serve Configs
| Environment | File to use | Notes |
|---|---|---|
| Tailscale (default) | tailscale/config/serve.json |
Supports HTTP + HTTPS with certs |
| Headscale | tailscale/config/serve.headscale.json |
HTTP only |
After changing the serve config, restart the sidecar and the app:
docker compose restart shiori-ts
docker compose restart shiori
Optional: Direct Host Access
Uncomment the ports section in docker-compose.yml if you need direct access without Tailscale:
ports:
- "8080:8080"
Data Backup
Shiori's data (SQLite database + archived bookmarks) lives in the shiori-data named volume. To back it up:
docker run --rm -v shiori-data:/data -v /path/to/backups:/backup alpine \
tar czf /backup/shiori-$(date +%F).tar.gz -C /data .