Trilium Notes
Organize notes, documents and ideas in a linked workspace.
Choose your deployment and the way you want to use Selfhost. The instructions below follow that choice.
Set up Trilium Notes
Editable Compose files in your own directory.
- Complete the initial note database and password setup.
- Configure OIDC and link your own account from Trilium Options.
selfhost app --directory ./trilium init trilium Initialization writes portable files and does not start the app. Review compose.yaml, the private .env and any files in files/, then start it:
selfhost app --directory ./trilium startNo Selfhost dashboard or background service is needed. You can also start these files directly:
cd trilium
docker compose -f compose.yaml up -dConnect an existing installation
Use Existing apps → Link an app in the dashboard, or the CLI’s existing-app commands. Choose Trilium Notes, its URL and, optionally, its exact Docker container on a connected server.
Save existing.json with your app URL. Add server_id and container for container inspection and actions.
{
"profile": "trilium",
"name": "Trilium Notes",
"url": "https://app.example.com"
}selfhost existing link --file existing.json
selfhost existing list
selfhost existing inspect EXISTING_IDLinking enables the existing-app profile’s supported inspection and actions. It does not import Compose or attach the new-deployment settings and onboarding profiles described below.
Existing app commands, permissions and unlinkingBefore configuring integrations
- Environment settings take precedence over config.ini. Sync server, session duration and native backups are configurable.
- Disconnect the existing OIDC account before changing providers.
- Native OIDC replaces the password sign-in after account linking; keep a recovery copy of configuration.
Trilium Notes integrations
Compose service: trilium. These operations use the profile saved when this deployment is created.
- After configuring OIDC, connect your existing Trilium account through its Options interface. Disconnect that account before switching providers. Selfhost does not replace or rebind the existing account.
Native settings
Changes use the app’s Compose environment. Unrelated settings are preserved.
Supported fields (10)
- Instance name
instance-name - string
- Read-only mode
readonly - stringChoices: true, false
- Disable native backups
disable-backup - Leave false unless another complete and tested backup method is in place. stringChoices: true, false
- Trusted reverse proxy
trusted-proxy - Use exact proxy IPs/CIDRs; avoid trusting arbitrary forwarding headers. string
- Remember-me lifetime
session-duration - Seconds. string
- Sync server URL
sync-host - string
- OIDC public URL
public-url - string
- OIDC issuer
oidc-issuer - string
- OIDC client ID
oidc-client - string
- OIDC client secret
oidc-secret - secret
Save a JSON map of the field IDs you want to change as changes.json. Replace FIELD_ID with an ID from the supported fields above, and use its declared value type. Review the plan and replace REVIEWED_REVISION with the revision it returns.
{
"FIELD_ID": "YOUR_VALUE"
}selfhost app --directory ./trilium config trilium
selfhost app --directory ./trilium plan trilium changes.json
selfhost app --directory ./trilium apply trilium changes.json --revision REVIEWED_REVISION Saved changes need service recreation to become active. Existing interpolated environment values stay under your control in .env or Compose.
Identity provider login
Selfhost can register a client with a supported provider and configure this app. Callback path: /callback.
No administrator role is assigned by Selfhost. Check the app’s first-login policy and retain a local recovery account.
Save connection.json and replace the URLs. Supply SELFHOST_IDP_TOKEN privately in your shell.
{
"provider": "zitadel",
"issuer": "https://identity.example.com",
"app_url": "https://app.example.com",
"name": "Trilium Notes"
}selfhost app --directory ./trilium connect-account trilium connection.json
selfhost app --directory ./trilium connect-plan trilium connection.json
selfhost app --directory ./trilium connect trilium connection.json --revision REVIEWED_REVISIONTest sign-in in a separate browser session. HTTPS domains and HTTP loopback development origins are supported by Selfhost; the chosen app and provider must also accept the resulting callback. Provider permissions, localhost and recovery.
Versions and updates
This deployment uses the following images. Existing projects retain their saved recipe and images. A new catalogue version does not silently update them.
- trilium:
triliumnext/trilium:v0.105.0
Review compatibility and back up app data before an update. Choose an image version and review the change.
Keep control of your setup
Selfhost remains optional. Your app runs using ordinary Compose files, its own settings and persistent data. Keep the Compose project name and volumes to preserve storage. Configuration exports and setting backups do not include application data.
Standalone CLI guide · Backups and removal · Trilium Notes documentation