# Bundled Vikunja This is the tracker for installs without their own Vikunja (runbook Path B, `docs/guides/slice-1-identities.md` section 2). Mosaic Stack's own install uses the estate instance, Path A, and doesn't use this. `compose.yaml` runs the upstream image at the digest the S3 probes used, `vikunja/vikunja@sha256:e2204a1c...a27cfc` (v2.7.0). It publishes the port on 127.0.0.1 only. Put a TLS proxy in front of it to reach it from another host. Don't change the bind address. ## Start it ```sh export MOSAIC_VIKUNJA_DIR="$HOME/.local/share/mosaic-dev/vikunja" export MOSAIC_VIKUNJA_UID="$(id -u)" MOSAIC_VIKUNJA_GID="$(id -g)" mkdir -p "$MOSAIC_VIKUNJA_DIR/db" "$MOSAIC_VIKUNJA_DIR/files" chmod 700 "$MOSAIC_VIKUNJA_DIR" umask 077 printf 'VIKUNJA_SERVICE_SECRET=%s\n' "$(openssl rand -hex 32)" > "$MOSAIC_VIKUNJA_DIR/env" printf 'VIKUNJA_SERVICE_PUBLICURL=http://127.0.0.1:3456/\n' >> "$MOSAIC_VIKUNJA_DIR/env" docker compose -f packages/tasks/deploy/vikunja/compose.yaml up -d ``` Compose refuses to start when one of the three variables is unset. The env file holds the service secret, which signs every session. It stays outside the repository, mode 0600. Set `MOSAIC_VIKUNJA_PORT` to publish on another port, and change `VIKUNJA_SERVICE_PUBLICURL` to match. Registration is off. Create the owner and `svc-$BIZ` with `vikunja user create` in the container, as runbook section 2 shows, then continue with section 3. The business variable is `tracker.baseUrl: "http://127.0.0.1:3456"`, the origin only. The adapter adds `/api/v2` and refuses a URL with a path. ## Upgrade The digest only changes in a reviewed commit, after the probes in `agents/darkwing/work/slice1-s3/probes.md` are run again against the new image and `tests/fixtures/v2-shapes.json` is recorded again. Back up `$MOSAIC_VIKUNJA_DIR/db` before you pull.