VAPID: the two values are the halves of one P-256 keypair, not independent secrets — the browser verifies that a push is signed by the private key matching the public key it subscribed with. The RANDOMIZED* generators mint each placeholder on its own, so they produced two unrelated strings and web push could never have worked. Generate the pair in mastodon_install_post_setup the way stoat already does, encoded as Mastodon's webpush gem expects: unpadded URL-safe base64 of the 32-byte private scalar and the 65-byte uncompressed public point, sliced out of the SEC1 DER. Verified by rebuilding the key from the emitted private half and re-deriving the public point — openssl accepts it and the point matches. Generated once and never rotated (rotation would invalidate every subscription), but a pair of the wrong shape is replaced, so an install carrying the old unrelated strings heals itself on next install — their public half is 42 chars where a real point is 87. Slots: CFG_<APP>_DB_PASSWORD -> CFG_<APP>_DB_PASSWORD_1 and likewise for DB_ROOT_PASSWORD, across mastodon, owncloud, mattermost, matrix, nextcloud and bookstack, so a database credential is always a numbered slot and a second one is just _2. Renaming a key means reconciliation drops the old and adds the new holding its placeholder, so an existing install regenerates unless the value is carried over first — documented, including that the old file survives as .<app>.config.bak. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
LibrePortal
Your own private corner of the internet — free, open, and yours.
LibrePortal is a self-hosted platform for running the apps you rely on, on your own server: one-click installs, a reverse proxy with automatic SSL, rootless Docker, optional VPN routing, and a clean web dashboard to manage it all.
⚠️ v0.1.0 — early days. Expect rough edges while things settle.
Why LibrePortal
Too many services today treat your data as theirs to take — quietly overstepping boundaries that should never have been crossed. LibrePortal grew out of frustration with that: it's a way to run the apps you depend on on your own server, where your data stays yours. Privacy here isn't a feature to toggle — it's the whole point.
Free & open — forever
The entire platform is free software under the GNU AGPLv3. Self-host it and you get everything — every feature, no paywalls, no telemetry. See our Promise for exactly what that means.
What you get
- 📦 One-click self-hosted apps (Nextcloud, Vaultwarden, Jellyfin, Gitea, …)
- 🔀 Traefik reverse proxy + automatic Let's Encrypt SSL
- 🔒 Rootless Docker, CrowdSec, sane security defaults
- 🛡️ Optional VPN routing (gluetun) for any app
- 🖥️ A web dashboard to install, configure, back up, and monitor everything
Quick start
curl -fsSL https://get.libreportal.org/install.sh | sudo bash
This installs a versioned, checksum-verified release (Debian/Ubuntu, root). Put
data on separate disks with --system-dir= / --containers-dir= / --backups-dir=.
The
get.libreportal.orghost is still being set up — until it's live, build a release and install from it locally (see the docs below).
Documentation
- docs/guide/install-and-use.md — install, place data on separate disks/drives, update, back up, uninstall.
- docs/contributing/development.md — run a dev copy, cut stable/edge releases, and test them before publishing.
LibrePortal Connect (optional)
Self-hosting is free and complete. If you'd rather not fiddle with the tricky parts — like reaching your server from your phone, or keeping off-site backups — LibrePortal Connect will handle them for you. Here's the catch that makes us different: we work like a courier carrying a sealed box. We move your data between your devices and store backup copies, but it stays locked and you hold the only key — we can't open it, and we never run your apps for you. Everything we offer, you can also set up yourself for free. Our Promise spells out exactly where that line sits.
Contributing
PRs welcome — see CONTRIBUTING.md. We use a lightweight
DCO sign-off (git commit -s), no CLA.
Acknowledgments
LibrePortal has been built from scratch since 2023. Its spark of inspiration
was a small installer script from Brian McGonagill (OpenSourceIsAwesome):
gitlab.com/bmcgonag/docker_installs.
From that seed it grew start to finish — refined, extended, and refactored
into the platform it is today.
License
GNU AGPLv3. What's open stays open.