Why this Configuration?
- True Data Sovereignty: 100% GDPR-compliant on-premises deployment. You own your configuration and data without vendor lock-in.
- Hardware Agnostic: Optimized and verified across low-power ARM64 SBCs (Raspberry Pi 5) and x86_64 hypervisors (Proxmox VE LXC & VM).
- Engine Freedom: Tested and supported under standard Docker Engine and unprivileged rootless Podman.
- Platform Verification: Tested on Proxmox LXC: docker (3.1.3, 2026-09-14), podman (7.4.11, 2026-09-14); Proxmox VM: docker (3.1.3, 2026-09-14), podman (7.4.11, 2026-09-14).
Quick Start (Standalone Docker Compose)
The snippet below is immediately ready to run in any standard Docker or Podman environment:
services:
paperless-ngx:
container_name: njorddeploy-paperless-ngx
image: "ghcr.io/paperless-ngx/paperless-ngx:latest"
ports:
- "8000:8000"
environment:
- "PAPERLESS_REDIS=redis://njorddeploy-paperless-broker:6379"
- "PAPERLESS_DBHOST=njorddeploy-paperless-db"
- "PAPERLESS_DBNAME=paperless"
- "PAPERLESS_DBUSER=paperless"
- "PAPERLESS_DBPASS=jp2ioLkJhGfDsAqWe123456_pgpass"
- "PAPERLESS_SECRET_KEY=PasW0rD1nC0mP1eX_K3yS3cR3t_L0nG_R@nD0m_S7r!nG_F0r_P@p3rL3sS"
- "PAPERLESS_URL=http://localhost:8000"
- "USERMAP_UID=0"
- "USERMAP_GID=0"
- "TZ=Etc/UTC"
volumes:
- "./data/paperless-ngx/data:/usr/src/paperless/data"
- "./data/paperless-ngx/media:/usr/src/paperless/media"
- "./data/paperless-ngx/export:/usr/src/paperless/export"
- "./data/paperless-ngx/consume:/usr/src/paperless/consume"
depends_on:
- njorddeploy-paperless-broker
- njorddeploy-paperless-db
networks:
- njorddeploy_net
user: "0:0"
njorddeploy-paperless-broker:
container_name: njorddeploy-paperless-broker
image: redis:7-alpine
volumes:
- "./data/paperless-ngx/redisdata:/data"
networks:
- njorddeploy_net
user: "0:0"
njorddeploy-paperless-db:
container_name: njorddeploy-paperless-db
image: postgres:16-alpine
environment:
- "POSTGRES_USER=paperless"
- "POSTGRES_PASSWORD=jp2ioLkJhGfDsAqWe123456_pgpass"
- "POSTGRES_DB=paperless"
volumes:
- "./data/paperless-ngx/pgdata:/var/lib/postgresql/data"
networks:
- njorddeploy_net
user: "0:0"
networks:
njorddeploy_net:
Start the service directly via the command line: docker compose up -d
Configuration & Environment Variables
Key configuration parameters and defaults derived from the NjordDeploy component template:
| Variable | Default Value | Description |
|---|---|---|
PAPERLESS_WEB_PORT |
8000 |
The host port for accessing the Paperless-ngx web interface. |
PAPERLESS_DBNAME |
paperless |
The name of the PostgreSQL database used by Paperless-ngx. |
PAPERLESS_DBUSER |
paperless |
The username for accessing the PostgreSQL database. |
PAPERLESS_DBPASS |
jp2ioLkJhGfDsAqWe123456_pgpass |
The password for the PostgreSQL database user. |
PAPERLESS_SECRET_KEY |
PasW0rD1nC0mP1eX_K3yS3cR3t_L0nG_R@nD0m_S7r!nG_F0r_P@p3rL3sS |
A unique secret key used for cryptographic signing in Paperless-ngx. Keep this secure. |
USERMAP_UID |
0 |
The User ID (UID) that the Paperless-ngx container will use. Set to 0 for root, or match your host user for permission consistency. |
USERMAP_GID |
0 |
The Group ID (GID) that the Paperless-ngx container will use. Set to 0 for root, or match your host group for permission consistency. |
TZ |
Etc/UTC |
Specify the timezone for the container (e.g., Europe/Berlin, America/New_York). |
Ecosystem & Enterprise Integration
- Reverse Proxy Ingress Ready: Pre-configured for Caddy, Traefik, or Nginx Proxy Manager with automatic Let's Encrypt TLS certificates.
- Zero-Trust Mesh VPN: Seamless integration with WireGuard or Tailscale/Headscale mesh networks for secure remote administration.
- Transactional State Backups: Ready for point-in-time database dumps and container-safe persistent volume freezing.
Effortless Management with NjordDeploy
Deploy, monitor, and update this service with a single click on your own hardware via the NjordDeploy Configurator.