All apps · 0 apps
Securo
Docker app from junkerderprovinz's Repository
Overview
Readme
View on GitHub
The Securo personal finance manager on Unraid, from a single template. It uses the PostgreSQL and Redis you already run, or brings its own when you have none.
A one-knight job: I build it, keep it running, work through the issues and add what people ask for, until nothing is missing. It is free, with no accounts, no telemetry, no ads and no paid tier. No asterisk anywhere. Nothing readable ever leaves your own walls. Forged on evenings and weekends, with heart and stubbornness.
If it has earned a place on your server or computer, toss a coin to your knight: it helps cover the costs and keeps the project alive. It also makes this knight's heart beat a little faster. Three ways below, whichever suits you.
Table of Contents
- What it looks like
- What it does
- Getting started
- Bank sync and single sign-on
- How AI is used here
- Support this project
1. What it looks like
The accounts and amounts in these pictures are made up.
The dashboard, served by the container on your server.
Transactions with categories, filters and a running balance.
2. What it does
Securo is a self-hosted finance manager: accounts, transactions, budgets, goals, assets and reports, with imports from OFX, QIF, CAMT and CSV and optional bank sync. Upstream ships it as six containers in a compose file. This image puts them into one, built from the official backend and frontend images:
- Your own databases first. By default Securo connects to the PostgreSQL and Redis containers you already have on Unraid. On the first start it creates its database and enables pgvector there.
- Or everything built in. Set Built-in PostgreSQL and Built-in Redis to
true, and both run inside the container, listen only on127.0.0.1and keep their data in your appdata folder. - A secret key on the first start. It is generated and kept in
secrets.env, so nobody has to invent one. - One port. nginx serves the web app and passes
/api/to the backend. The Celery worker and scheduler run next to it, so bank syncs, recurring transactions and price updates work without extra containers. - A clear stop instead of a crash loop. A missing database host, a wrong password or a PostgreSQL without pgvector ends in one line that says what to change.
- Upstream unchanged. The backend and the web app are the official images of the same version, and the settings from upstream's
.env.examplework as variables.
3. Getting started
- Install Securo from Community Applications.
- Pick your databases:
- PostgreSQL already running? Enter its host, user and password. The server needs pgvector:
pgvector/pgvector:pg16and the PostgreSQL image Immich uses both have it, the plainpostgresimage does not. If the user may create databases, Securo createssecuroon the first start; otherwise create it yourself and runCREATE EXTENSION vector;in it as a superuser. - Redis already running? Enter its host, and its password if it has one. If other apps use database
0on it, give Securo a number of its own under Redis database. - Neither? Set Built-in PostgreSQL and Built-in Redis to
trueand leave the host fields empty.
- PostgreSQL already running? Enter its host, user and password. The server needs pgvector:
- Set App address to the address you open Securo on, such as
http://192.168.1.10:3000orhttps://securo.example.com. Bank sync and single sign-on send you back there. - Start the container. The first start creates the tables, which takes under a minute. It is ready when the log says
SECURO IS READY. - Open the web app and create your account. To keep strangers from signing up, set Registration to
falseafterwards.
With docker run:
docker run -d --name securo \
-p 3000:8080 \
-v /mnt/user/appdata/securo:/data \
-e FRONTEND_URL=http://192.168.1.10:3000 \
-e BUILTIN_POSTGRES=true \
-e BUILTIN_REDIS=true \
junkerderprovinz/securo:latest
A few things worth knowing:
- Passkeys need HTTPS on a domain. Browsers refuse them on
http://192.168.1.10:3000. Put Securo behind your reverse proxy with a certificate, or skip passkeys and use a password with two-factor codes. - Behind a reverse proxy, set Trusted proxies to
2, so the login rate limit counts each visitor on its own instead of all of them as your proxy. - Backups: with the built-in database, stop the container and copy the appdata folder. With your own PostgreSQL, back up the
securodatabase the way you back up the others.
4. Bank sync and single sign-on
All of this stays off until you fill in the fields. Each provider switches itself on once its credentials are present.
| Feature | What to set | Where you get it |
|---|---|---|
| European banks (PSD2) | Enable Banking app ID, and the private key as enable_banking_private.pem in the secrets folder of your appdata |
Create a production application at enablebanking.com. Its redirect URL is your App address followed by /oauth/callback, which needs https |
| US and other banks | SimpleFIN set to true |
A setup token from the SimpleFIN Bridge, pasted into Securo under Accounts |
| Brazilian banks | Pluggy client ID and Pluggy client secret | dashboard.pluggy.ai |
| Single sign-on | OIDC set to true, plus discovery URL, client ID and secret |
Your provider, such as Authentik or Pocket ID. The redirect URI is your App address followed by /api/auth/oidc/callback |
Every other setting from upstream's .env.example works as a container variable with the same name. The optional AI agents are not part of this image yet.
5. How AI is used here
One knight builds this, and AI is one of the tools I work with, the same way I work with an editor or a compiler. It helps me write code and documentation and it checks my work, and that saves me a good many evenings. It does not make the decisions, though. I read and understand everything before it ships, and if something here breaks, that is on me and not on the tool.
You do not have to take my word for it. The code is open and every release note is written by hand. The issue tracker shows how problems actually get handled, including the ones I got wrong the first time. If you find something that is not right, open an issue and I will look at it.
6. Support this project
Questions, bugs, ideas or feature requests? Please open a GitHub issue. Problems with Securo itself, the app rather than the container, are best reported upstream.
A one-knight job: I build it, keep it running, work through the issues and add what people ask for, until nothing is missing. It is free, with no accounts, no telemetry, no ads and no paid tier. No asterisk anywhere. Nothing readable ever leaves your own walls. Forged on evenings and weekends, with heart and stubbornness.
If it has earned a place on your server or computer, toss a coin to your knight: it helps cover the costs and keeps the project alive. It also makes this knight's heart beat a little faster. Three ways below, whichever suits you.
Securo is developed by the Securo project and released under AGPL-3.0. This is an independent packaging for Unraid and is not affiliated with the Securo project.
Requirements
Categories
Download Statistics
Related apps
Explore more like this
Explore allDetails
junkerderprovinz/securo:latestRuntime arguments
- Web UI
http://[IP]:[PORT:8080]/- Network
bridge- Shell
bash- Privileged
- false
- Extra Params
--restart=unless-stopped
Template configuration
Port of the Securo web app.
- Target
- 8080
- Default
- 3000
- Value
- 3000
Attachments, secrets.env with the generated secret key, the secrets folder for an Enable Banking key and, with Built-in PostgreSQL and Redis, their data.
- Target
- /data
- Default
- /mnt/user/appdata/securo
- Value
- /mnt/user/appdata/securo
The address you open Securo on, such as http://192.168.1.10:3000 or https://securo.example.com. Bank sync and single sign-on send you back there.
- Target
- FRONTEND_URL
true runs PostgreSQL 16 with pgvector inside this container, with its data in the Data folder. Leave it false to use your own PostgreSQL.
- Target
- BUILTIN_POSTGRES
- Default
- false|true
- Value
- false
IP or name of your PostgreSQL server. It needs pgvector. Leave it empty with Built-in PostgreSQL.
- Target
- POSTGRES_HOST
A user that may create databases, or the owner of a database you created for Securo. Not used with Built-in PostgreSQL.
- Target
- POSTGRES_USER
- Default
- postgres
- Value
- postgres
Password of the database user. It must not contain @ or %. Not used with Built-in PostgreSQL.
- Target
- POSTGRES_PASSWORD
true runs Redis inside this container. Leave it false to use your own Redis.
- Target
- BUILTIN_REDIS
- Default
- false|true
- Value
- false
IP or name of your Redis server. Leave it empty with Built-in Redis.
- Target
- REDIS_HOST
Whether new people can sign up. Set it to false once your own account exists.
- Target
- REGISTRATION_ENABLED
- Default
- true|false
- Value
- true
Port of your PostgreSQL server.
- Target
- POSTGRES_PORT
- Default
- 5432
- Value
- 5432
Created on the first start if it does not exist and the user may create databases.
- Target
- POSTGRES_DB
- Default
- securo
- Value
- securo
Port of your Redis server.
- Target
- REDIS_PORT
- Default
- 6379
- Value
- 6379
Only when your Redis server asks for one.
- Target
- REDIS_PASSWORD
Database number on your Redis server. Give Securo one no other app uses, since its task queue shares the name every Celery app uses.
- Target
- REDIS_DB
- Default
- 0
- Value
- 0
How many proxies stand in front of Securo, counting the one inside this container. 1 without a reverse proxy, 2 behind one. The login rate limit counts visitors by the address this finds.
- Target
- TRUSTED_PROXY_HOPS
- Default
- 1
- Value
- 1
Signs the login tokens. Leave it empty to get a generated one, kept in secrets.env. Changing it signs everyone out.
- Target
- SECRET_KEY
Bank sync for about 2500 European banks. Put the application's private key into the secrets folder of the Data folder as enable_banking_private.pem. The redirect URL to register is your App address followed by /oauth/callback, over https.
- Target
- ENABLE_BANKING_APP_ID
Bank sync for US and other banks through the SimpleFIN Bridge. You paste a setup token into Securo under Accounts.
- Target
- SIMPLEFIN_ENABLED
- Default
- false|true
- Value
- false
The beta bridge hands out demo tokens for trying it. For real banks use https://bridge.simplefin.org.
- Target
- SIMPLEFIN_API_URL
- Default
- https://beta-bridge.simplefin.org
- Value
- https://beta-bridge.simplefin.org
Bank sync for Brazilian banks, from dashboard.pluggy.ai.
- Target
- PLUGGY_CLIENT_ID
The client secret that belongs to the Pluggy client ID.
- Target
- PLUGGY_CLIENT_SECRET
Sign-in through Authentik, Pocket ID or another OIDC provider. The redirect URI to register is your App address followed by /api/auth/oidc/callback.
- Target
- OIDC_ENABLED
- Default
- false|true
- Value
- false
Shown on the sign-in button.
- Target
- OIDC_PROVIDER_NAME
- Default
- OIDC
- Value
- OIDC
Ends in /.well-known/openid-configuration.
- Target
- OIDC_DISCOVERY_URL
From the application you created at your provider.
- Target
- OIDC_CLIENT_ID
From the application you created at your provider.
- Target
- OIDC_CLIENT_SECRET
false allows only OIDC sign-in. Securo refuses to start that way until OIDC is fully set up.
- Target
- LOCAL_AUTH_ENABLED
- Default
- true|false
- Value
- true
Optional key for exchange rates between your currencies, from openexchangerates.org.
- Target
- OPENEXCHANGERATES_APP_ID
User that owns the files in the Data folder. 99 is nobody on Unraid.
- Default
- 99
- Value
- 99
Group that owns the files in the Data folder. 100 is users on Unraid.
- Default
- 100
- Value
- 100