# Radicale - Naptár és névjegyek (CalDAV / CardDAV szerver) # Domain: ${SUBDOMAIN}.${DOMAIN} # Database: None (file-based — every calendar and address book is a folder of .ics/.vcf files) # RAM: ~40M (mem_limit: 128M) | Pi-compatible: Yes (amd64, arm64, arm/v7) # # Environment variables: # DOMAIN - Your domain (e.g., demo-felhom.eu) # RADICALE_USER - A bejelentkezési név (az űrlapon megadható, alapból "csalad") # RADICALE_PASSWORD - A jelszó (telepítéskor generálva, az alkalmazás oldalán látható) # # The upstream image (ghcr.io/kozea/radicale, the Radicale project's own) ships NO config, and Radicale 3's # default `auth type` is `denyall` — nobody can log in. So the start command writes the login file from the # box's generated password (bcrypt, 0600, on the data volume) ON THE FIRST START ONLY, then starts Radicale with # htpasswd auth. There is never a moment without a login (no install window, checklist 3.5). The password is # read from the environment, never pasted into program code (checklist 3.8). # FIRST START ONLY, measured 2026-10-01 on 9202: the box never puts a `type: password` value into a backup (an # internet-reachable login; controller `PortableSecretEnvVars`) and makes a NEW one on a restore after a remove, # expecting the app's own login to come back WITH ITS DATA. The first version rewrote the file at every start — # a remove + restore then replaced the household's login with a value no page shows, and every phone lost its # calendar. Written once, the login file lives on the data volume and comes back with the calendars. services: radicale: image: ghcr.io/kozea/radicale:3.8.1 container_name: radicale restart: unless-stopped environment: - TZ=Europe/Budapest - RADICALE_USER=${RADICALE_USER} - RADICALE_PASSWORD=${RADICALE_PASSWORD} entrypoint: - /bin/sh - -c - | [ -s /var/lib/radicale/users ] || /app/bin/python -c 'import os, bcrypt; f = "/var/lib/radicale/users"; u = os.environ["RADICALE_USER"]; p = os.environ["RADICALE_PASSWORD"].encode(); open(f, "w").write(u + ":" + bcrypt.hashpw(p, bcrypt.gensalt()).decode() + "\n"); os.chmod(f, 0o600)' || exit 1 exec /app/bin/python /app/bin/radicale --hosts 0.0.0.0:5232 --auth-type htpasswd --auth-htpasswd-filename /var/lib/radicale/users --auth-htpasswd-encryption bcrypt --storage-filesystem-folder /var/lib/radicale/collections volumes: - radicale_data:/var/lib/radicale networks: - traefik-public deploy: resources: limits: memory: 128M healthcheck: test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:5232/.web/"] interval: 30s timeout: 5s retries: 3 start_period: 20s labels: - "traefik.enable=true" - "traefik.http.routers.radicale.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)" - "traefik.http.routers.radicale.entrypoints=websecure" - "traefik.http.routers.radicale.tls=true" - "traefik.http.routers.radicale.tls.certresolver=letsencrypt" - "traefik.http.services.radicale.loadbalancer.server.port=5232" volumes: radicale_data: networks: traefik-public: external: true