gbrain-aio

gbrain-aio

Docker app from dub19's Repository

Overview

GBrain all-in-one for Unraid: a hosted knowledge base and MCP server for AI agents (Hermes Agent, OpenClaw, Codex). One container runs GBrain, PostgreSQL 17 + pgvector, Caddy TLS, and the job supervisor. Agents connect over HTTPS — Postgres is never exposed.

First run (details are in each field's help text):

  1. Set Postgres Password and Admin Bootstrap Token.
  2. Set LAN Bind and Public URL to your host IP.
  3. Set Brain Path to an empty folder.
  4. Start, then open https://lan:3132/admin/ and paste the token.
  5. Trust the generated CA once.

gbrain-aio

Run GBrain as one container — a hosted knowledge base and MCP server for AI agents. No Postgres setup, no reverse proxy, no worker to manage. Install the Unraid template, set a few values, and it's ready on first boot.

What this is for

GBrain is a self-hosted second brain. Point an AI agent harness at it and it becomes your persistent memory and knowledge store. gbrain-aio packages GBrain so you can run it as a hosted GBrain MCP server for agent frameworks like Hermes Agent, OpenClaw, Codex, and any harness that speaks MCP. Agents connect to it over HTTPS and get queryable memory — not a raw database.

The problem it solves

GBrain will not just run. A real deployment needs five things bolted together:

  1. PostgreSQL + pgvector — all data + vector embeddings live here
  2. A reverse proxy — the admin UI and MCP endpoint need HTTPS
  3. A job worker — background maintenance, nightly "dream," weekly doctor
  4. Embedding + chat models — Ollama for embeddings, plus a chat model
  5. A build — GBrain has no official Docker image

Wiring those by hand on Unraid is the whole problem. gbrain-aio does it for you.

What you get in this container

GBrain, running with its full default setup — the reason you're here:

  • The GBrain HTTP + MCP server on 127.0.0.1:3131, fronted by Caddy TLS on 3132
  • The job supervisor — runs background work
  • Autopilot — self-maintenance every 30 min
  • Nightly dream (02:00) and weekly doctor (Monday 06:00)
  • Schema + sources pre-wired — gbrain-everything, your source federated, sync queued

Plus the supporting infrastructure, all in the same container:

  • PostgreSQL 17 + pgvector — loopback only, never published
  • Caddy TLS — the public face
  • Embedding support — ollama:embeddinggemma @ 768d

Pinned to official garrytan/gbrain releases. Agents connect only through HTTPS — Postgres is never handed to them.

Embeddings & models

A local Ollama is required for embedding — the container indexes every document into vector space and needs ollama:embeddinggemma @ 768d to do it. Only embeddinggemma is supported today.

  • Ollama (required) — the container uses ollama:embeddinggemma @ 768d. Point OLLAMA_BASE_URL at your local Ollama (e.g. http://<lan>:11434). A GPU is strongly recommended — large brains index and query much faster with GPU-backed embeddings.
  • Chat / expansion models — add an Anthropic, OpenAI, Gemini, DeepSeek, Groq, or Voyage API key, or route through the same Ollama instance. Leave chat model fields empty to keep defaults.

First boot does the setup for you

Start empty, and the container:

  1. Runs gbrain init with ollama:embeddinggemma @ 768d
  2. Git-inits the brain if it is not a repo
  3. Registers and federates your source
  4. Writes sync paths and enables the gbrain-everything schema
  5. Sets model routing for Ollama
  6. Enqueues a sync once /health is up

No docker exec required.

Install (Unraid, ~3 min)

  1. Install the template
  2. Set POSTGRES_PASSWORD (alphanumeric) and GBRAIN_ADMIN_BOOTSTRAP_TOKEN (32+ chars)
  3. Leave default appdata paths, set your LAN HTTPS origin, Apply
  4. Wait for init
  5. Open https://<lan>:3132/admin/, paste the token, trust the generated CA once

Requirements

  • Unraid (with Community Applications) or any Docker host
  • A LAN IP you control
  • Ollama at http://<lan>:11434 for embeddings (GPU recommended)

Not included

  • No host PostgreSQL — everything runs inside the container

Persistence

Back up the brain repo, Postgres data, and Caddy certs under /mnt/user/appdata/gbrain-aio/ if you care about the instance.

License

MIT. GBrain under its own upstream license.

Requirements

Docker with Compose. A LAN IP you control. Optional: a local Ollama at http://lan:11434 for embeddings and chat.

Download Statistics

1,079
Total Downloads

Related apps

Explore more like this

Explore all

Details

Repository
dub19/gbrain-aio
Last Updated2026-08-20
First Seen2026-08-19

Runtime arguments

Web UI
https://[IP]:[PORT:3132]
Network
bridge
Shell
sh
Privileged
false

Template configuration

Web UI PortPorttcp

Published HTTPS port (Caddy).

Target
3132
Default
3132
Value
3132
Appdata RootPathrw

Single persistent folder. Sub-folders are created automatically: data/postgres (database), gbrain-home (config, OAuth, runtime.env), caddy (TLS certs + CA).

Target
/data/aio
Default
/mnt/user/appdata/gbrain-aio
Value
/mnt/user/appdata/gbrain-aio
Brain PathPathrw

Host path to the brain markdown repo. Mounted at the fixed target /source/brain; the source id is fixed to 'brain'. Should be an empty folder (or a git repo) that GBrain will initialize.

Target
/source/brain
Default
/mnt/user/my-brain
Value
/mnt/user/my-brain
Postgres UserVariable

Postgres superuser. Keep gbrain.

Target
POSTGRES_USER
Default
gbrain
Value
gbrain
Postgres PasswordVariable

REQUIRED. Alphanumeric only (A-Za-z0-9). Secret. Example: mypass123. Generate: head -c 16 /dev/urandom | base64 | tr -d '+/=' | head -c 16

Target
POSTGRES_PASSWORD
Postgres DBVariable

Postgres database name. Keep gbrain.

Target
POSTGRES_DB
Default
gbrain
Value
gbrain
LAN BindVariable

Your Unraid host LAN IP (e.g. 192.168.1.50). The container binds HTTPS to this IP. This is local-network only, not a public address.

Target
GBRAIN_LAN_BIND
Public URLVariable

Optional. Empty = derived from LAN Bind (https://LAN Bind:3132). Override only for custom port, DNS-name access, reverse proxy, or a Tailscale origin. Must match how clients actually reach the container.

Target
GBRAIN_PUBLIC_URL
Admin Bootstrap TokenVariable

First /admin login token. Must be 32+ chars, alphanumeric + _-. Secret. Generate: head -c 32 /dev/urandom | base64 | tr -d '+/=' | head -c 48

Target
GBRAIN_ADMIN_BOOTSTRAP_TOKEN
Brain UIDVariable

UID for the brain bind mount. Unraid default is 99 (nobody). Keep 99 unless you know otherwise.

Target
BRAIN_UID
Default
99
Value
99
Brain GIDVariable

GID for the brain bind mount. Unraid default is 100 (users). Keep 100 unless you know otherwise.

Target
BRAIN_GID
Default
100
Value
100
Ollama Base URLVariable

OpenAI-compatible endpoint for embeddings + chat. Point at your local Ollama. Example: http://192.168.1.50:11434/v1 (replace with your Ollama host IP). Leave empty to skip local Ollama.

Target
OLLAMA_BASE_URL
Chat ModelVariable

Chat model name used when OLLAMA_BASE_URL is set. Written as together:this name. Leave the default unless you know another model. Empty Ollama URL means no chat model (keyword/embed-or-skip).

Target
CHAT_MODEL
Default
deepseek-v4-flash:cloud
Value
deepseek-v4-flash:cloud
Brain Git Push URLVariable

Optional. After a successful autopilot-cycle, push the mounted brain to this remote. Empty = off. Do not point a test copy at a live canonical remote. The token is not stored in the remote URL.

Target
BRAIN_GIT_PUSH_URL
Brain Git Push TokenVariable

Optional. Masked token for Brain Git Push URL. Empty = unauthenticated push. Never pasted into git remote -v.

Target
BRAIN_GIT_PUSH_TOKEN
Doctor Remediate Max USDVariable

Optional. Weekly doctor exam always runs. Set a number to also run gbrain doctor --remediate --max-usd N for that run's estimate. Empty = exam only. Not a weekly wallet.

Target
DOCTOR_REMEDIATE_MAX_USD
Skillopt EnabledVariable

Optional. Empty = off. Set 1/true/yes/on to enable cycle.skillopt.enabled.

Target
SKILLOPT_ENABLED
Nightly Quality ProbeVariable

Optional. Empty = off. Set 1/true/yes/on to enable autopilot.nightly_quality_probe.enabled.

Target
NIGHTLY_QUALITY_PROBE
Parser Probe EnabledVariable

Optional. Empty = off. Set 1/true/yes/on to enable autopilot.conversation_parser_probe.enabled.

Target
PARSER_PROBE_ENABLED
OpenRouter API KeyVariable

Optional. Enables OpenRouter models (any provider:model id). Secret.

Target
OPENROUTER_API_KEY
Anthropic API KeyVariable

Optional. Enables Claude models for chat/think. Secret.

Target
ANTHROPIC_API_KEY
Chat ProviderVariable

Empty or ollama = route chat/expansion through the ollama recipe (raw gbrain, zero-cost). together = legacy provider_base_urls redirect kept for compatibility. Only used when Ollama Base URL is set.

Target
CHAT_PROVIDER
Extra Runtime ConfigVariable

Universal escape hatch. Comma-separated key=value pairs for ANY gbrain config key (e.g. models.drift=ollama:deepseek-v4-flash:cloud, dream.triage.threshold=0.6). provider_base_urls is refused. Applied after known defaults; explicit entries win.

Target
GBRAIN_EXTRA_CONFIG
Extra Runtime EnvVariable

Optional. Comma-separated KEY=VALUE pairs passed to the runtime environment. Allowlist-only: GBRAIN_EMBEDDING_MULTIMODAL(_MODEL), GBRAIN_EMBEDDING_IMAGE_OCR(_MODEL), GBRAIN_SEARCH_EXCLUDE, GBRAIN_SOURCE_BOOST, GBRAIN_CHAT_FALLBACK_CHAIN, GBRAIN_BACKUP_CHECK(_DAYS), GBRAIN_AUTOPILOT_LABEL, GBRAIN_TRAJECTORY_REGRESSION_THRESHOLD, GBRAIN_EMBED_CONCURRENCY, GBRAIN_RETRIEVAL_REFLEX_*. Anything else is refused at boot.

Target
GBRAIN_EXTRA_ENV
Embedding ModelVariable

Empty = ollama:embeddinggemma. Any provider:model id supported by gbrain init.

Target
EMBEDDING_MODEL
Embedding DimensionsVariable

Empty = 768. Must match the embedding model native width (e.g. bge-m3=1024, nomic=768).

Target
EMBEDDING_DIMENSIONS
Schema PackVariable

Empty = gbrain-everything. Schema pack id passed to gbrain schema use.

Target
SCHEMA_PACK
Autopilot IntervalVariable

Empty = 1800 seconds. Seconds between autopilot cycles.

Target
AUTOPILOT_INTERVAL
Dream TimeVariable

Empty = 02:00 local. HH:MM for the nightly dream cycle.

Target
DREAM_AT
Doctor DayVariable

Empty = monday. Weekday for the weekly doctor exam (mon|tue|...).

Target
DOCTOR_DAY
Doctor TimeVariable

Empty = 06:00. HH:MM for the weekly doctor run.

Target
DOCTOR_AT
Tailscale Origin PolicyVariable

Empty = auto when Unraid per-container Tailscale is enabled (origin = MagicDNS name). off = keep LAN origin. Any URL = explicit origin. Public URL override wins over this.

Target
TS_PUBLIC_URL
Cert Extra DNSVariable

Optional. Comma-separated extra DNS names for the TLS cert SAN (e.g. your MagicDNS name). Empty = only base SAN plus auto-discovered tailnet names.

Target
CERT_EXTRA_DNS
Cert Extra IPsVariable

Optional. Comma-separated extra IPs for the TLS cert SAN (e.g. 100.x.y.z)

Target
CERT_EXTRA_IPS
OpenAI API KeyVariable

Optional. Enables OpenAI models for chat/embeddings. Secret.

Target
OPENAI_API_KEY
Google Gemini API KeyVariable

Optional. Enables Google Gemini models. Secret.

Target
GEMINI_API_KEY
DeepSeek API KeyVariable

Optional. Enables DeepSeek models. Secret.

Target
DEEPSEEK_API_KEY
Groq API KeyVariable

Optional. Enables Groq models. Secret.

Target
GROQ_API_KEY
Voyage API KeyVariable

Optional. Enables Voyage embeddings/rerank. Secret.

Target
VOYAGE_API_KEY