Run your own sync server
DaisyTasks syncs through a small relay that stores only end-to-end encrypted blobs. Using ours is a paid subscription; running your own is free and the apps work with it exactly the same way.
What the relay is
- One Rust binary with an SQLite database, shipped as a Docker image (about 256 MB of memory is plenty).
- It never sees your tasks: devices encrypt every change with a key derived from your sync code, and the relay stores the ciphertext.
- It has no accounts. A vault is identified by an id derived from the sync code; a token proves a device may write to it.
- Optional Caddy (automatic HTTPS) and Litestream (continuous backup to S3-compatible storage) come in the same compose file.
You need
- A small Linux server with Docker and a public IP.
- A DNS name for it, for example
sync.example.com. - Optionally, an S3-compatible bucket for backups, at a different provider or region.
Install
Get the relay's source (the server/ and deploy/ folders of the DaisyTasks repository; it will be published with the first public release), then on the server:
cd daisytasks/deploy
cp .env.example .env && chmod 600 .env
$EDITOR .env # COMPOSE_PROFILES=caddy (add ,backup for Litestream),
# DAISYTASKS_DOMAIN=sync.example.com, ACME_EMAIL, bucket keys
docker compose up -d --build
Open ports 80 and 443. Caddy gets a certificate on the first request. Check it:
curl https://sync.example.com/healthz # ok docker compose ps # relay "healthy"
Already running Apache or nginx? Leave caddy out of COMPOSE_PROFILES, proxy your site to 127.0.0.1:8787 and make the proxy overwrite X-Forwarded-For with the client address (the relay rate-limits per IP).
Connect the apps
- In DaisyTasks open Sync, replace the server address with
https://sync.example.comand create a vault. - On your other devices choose Join with code and scan the QR code shown under Link another device.
Settings
| Variable | Default | Meaning |
|---|---|---|
DAISYTASKS_MAX_VAULT_MB | 256 | Storage per vault; beyond it uploads are refused (reads keep working). |
DAISYTASKS_VAULT_WRITES_PER_MIN | 120 | Uploads per vault per minute. |
DAISYTASKS_IP_REQUESTS_PER_MIN | 600 | Requests per client IP per minute. |
DAISYTASKS_UNKNOWN_VAULT_PER_HOUR | 30 | Lookups of unknown vaults per IP per hour; caps sync-code password guessing. |
DAISYTASKS_MAX_WAIT_SECS | 30 | How long the relay holds a request waiting for changes (instant updates). Use 0 behind a proxy with one process per connection. |
DAISYTASKS_TRUST_PROXY | 1 in compose | Read the client IP from X-Forwarded-For. |
Billing (Stripe) is off unless you configure it; a self-hosted relay doesn't need it.
Backups and moving servers
With the backup profile, Litestream copies the database continuously and a new server restores the latest copy automatically before the relay starts. Even without backups nothing is lost for good: every device keeps a full copy, and the first device that syncs with an empty or older server uploads everything again.
Upgrades
git pull docker compose up -d --build
Database migrations run on start-up.