Template catalog
Falak ships a curated catalog of 32 templates, versioned with Falak. Every template pins its image versions (no latest), has working health checks, and is validated in Falak’s CI. All catalog templates are version 1.0.0. Generated inputs are created once, when you deploy.
Legend for inputs: generated values are random (secret(n): n characters A–Z, a–z, 0–9; password(n): n unambiguous characters with upper, lower and digits).
At a glance
Section titled “At a glance”| Template | Category | Images | Public service (port) | Min. RAM | Stateful |
|---|---|---|---|---|---|
| Adminer | Databases | adminer:6.1.1 |
adminer (8080) | 64 MB | no |
| Appsmith | Dev tools | appsmith/appsmith-ce:v2.4.2 |
appsmith (80) | 4096 MB | yes |
| BookStack | CMS | linuxserver/bookstack:26.09.20260929, mariadb:11.8.9 |
bookstack (80) | 512 MB | yes |
| changedetection.io | Monitoring | ghcr.io/dgtlmoon/changedetection.io:0.60.8 |
changedetection (5000) | 256 MB | yes |
| code-server | Dev tools | codercom/code-server:4.139.1 |
code-server (8080) | 1024 MB | yes |
| Directus | CMS | directus/directus:12.4.1, postgres:17.11-alpine |
directus (8055) | 1024 MB | yes |
| Excalidraw | Dev tools | excalidraw/excalidraw@sha256:f7ee194addd607bf831d2af0f0a34463dd4225e426cf35199ef0b12a803398e9 |
excalidraw (80) | 64 MB | no |
| Forgejo | Dev tools | codeberg.org/forgejo/forgejo:16.0.5 |
forgejo (3000) | 512 MB | yes |
| Ghost | CMS | ghost:6.65.0-alpine, mysql:8.4.11 |
ghost (2368) | 1024 MB | yes |
| Gitea | Dev tools | gitea/gitea:1.27.3 |
gitea (3000) | 512 MB | yes |
| Grafana | Monitoring | grafana/grafana:13.2.2 |
grafana (3000) | 512 MB | yes |
| Langflow | AI | langflowai/langflow:1.12.3, postgres:17.11-alpine |
langflow (7860) | 2048 MB | yes |
| listmonk | Communication | listmonk/listmonk:v6.2.0, postgres:17.11-alpine |
listmonk (9000) | 256 MB | yes |
| Mailpit | Dev tools | axllent/mailpit:v1.31.3 |
mailpit (8025) | 128 MB | no |
| Matomo | Analytics | matomo:5.14.0-apache, mariadb:11.8.9 |
matomo (80) | 1024 MB | yes |
| Meilisearch | Databases | getmeili/meilisearch:v1.54.0 |
meilisearch (7700) | 512 MB | yes |
| Metabase | Analytics | metabase/metabase:v0.63.18.2, postgres:17.11-alpine |
metabase (3000) | 2048 MB | yes |
| MinIO | Storage | pgsty/minio:RELEASE.2026-08-04T00-00-00Z, caddy:2.11.4-alpine |
minio (9000), console (8080) | 512 MB | yes |
| n8n | Automation | n8nio/n8n:2.40.7 |
n8n (5678) | 512 MB | yes |
| Nextcloud | Storage | nextcloud:34.0.4-apache, mariadb:11.8.9, redis:8.8.3-alpine |
nextcloud (80) | 1024 MB | yes |
| NocoDB | Databases | nocodb/nocodb:2026.09.0, postgres:17.11-alpine |
nocodb (8080) | 512 MB | yes |
| ntfy | Communication | binwiederhier/ntfy:v2.28.0 |
ntfy (80) | 128 MB | yes |
| Ollama + Open WebUI | AI | ghcr.io/open-webui/open-webui:v0.11.4, ollama/ollama:0.35.0 |
open-webui (8080) | 4096 MB | yes |
| Paperless-ngx | Storage | ghcr.io/paperless-ngx/paperless-ngx:3.2.1, redis:8.8.3-alpine |
paperless (8000) | 1024 MB | yes |
| Plausible Analytics | Analytics | ghcr.io/plausible/community-edition:v3.2.1, postgres:16.15-alpine, clickhouse/clickhouse-server:24.12.6.70-alpine |
plausible (8000) | 2048 MB | yes |
| Qdrant | AI | qdrant/qdrant:v1.19.1 |
qdrant (6333) | 512 MB | yes |
| Redis Stack | Databases | redis/redis-stack:7.4.0-v8, caddy:2.11.4-alpine |
insight (8080) | 512 MB | yes |
| Umami | Analytics | ghcr.io/umami-software/umami:3.4.0, postgres:17.11-alpine |
umami (3000) | 512 MB | yes |
| Uptime Kuma | Monitoring | louislam/uptime-kuma:2.5.5 |
uptime-kuma (3001) | 256 MB | yes |
| Vaultwarden | Dev tools | vaultwarden/server:1.37.3 |
vaultwarden (80) | 128 MB | yes |
| Wiki.js | CMS | requarks/wiki:2.5.315, postgres:17.11-alpine |
wiki (3000) | 512 MB | yes |
| WordPress | CMS | wordpress:7.1.2-php8.3-apache, mariadb:11.8.9 |
wordpress (80) | 512 MB | yes |
Adminer
Section titled “Adminer”Database manager in one page for PostgreSQL, MySQL, MariaDB, SQLite and more. Docs
| Input | Type | Default |
|---|---|---|
DEFAULT_SERVER |
string | db |
Adminer asks for database credentials on every login and stores nothing.
Appsmith
Section titled “Appsmith”Low-code platform for internal tools, admin panels and dashboards (Community Edition). Docs
| Input | Type | Default |
|---|---|---|
APPSMITH_ENCRYPTION_PASSWORD |
secret | generated secret(32) |
APPSMITH_ENCRYPTION_SALT |
secret | generated secret(32) |
Needs at least 4 GB of RAM.
BookStack
Section titled “BookStack”Simple wiki and documentation platform organised into shelves, books and pages. Docs
| Input | Type | Default |
|---|---|---|
APP_KEY |
secret | generated secret(32) |
DB_PASSWORD |
secret | generated password(32) |
DB_ROOT_PASSWORD |
secret | generated password(32) |
Sign in with admin@admin.com / password after the first deploy and change both right away.
changedetection.io
Section titled “changedetection.io”Watch web pages for changes and get notified by email, Slack, Discord, ntfy and more. Docs
| Input | Type | Default |
|---|---|---|
TIMEZONE |
select | UTC |
Set a password under Settings → General right away: the app is open until you do.
code-server
Section titled “code-server”VS Code in the browser, running on your server behind a password. Docs
| Input | Type | Default |
|---|---|---|
PASSWORD |
secret | generated password(24) |
The workspace is the container’s /home/coder (a named volume). It cannot reach the server’s own files.
Directus
Section titled “Directus”Instant REST + GraphQL API and no-code data studio on top of PostgreSQL. Docs
| Input | Type | Default |
|---|---|---|
ADMIN_EMAIL |
required | |
ADMIN_PASSWORD |
secret | generated password(24) |
SECRET |
secret | generated secret(64) |
POSTGRES_PASSWORD |
secret | generated password(32) |
Excalidraw
Section titled “Excalidraw”Virtual whiteboard for hand-drawn style diagrams and sketches. Docs
No inputs.
Drawings stay in each browser (local storage) or in exported files. The server only serves the app.
Forgejo
Section titled “Forgejo”Community-run Git forge with pull requests, issues, packages and Actions (a Gitea fork). Docs
| Input | Type | Default |
|---|---|---|
FORGEJO_SECRET_KEY |
secret | generated secret(64) |
FORGEJO_INTERNAL_TOKEN |
secret | generated secret(105) |
DISABLE_REGISTRATION |
boolean | false |
Git over HTTPS only (SSH is disabled). The first registered user becomes the admin.
Publishing platform for blogs, newsletters and paid memberships, with MySQL. Docs
| Input | Type | Default |
|---|---|---|
MYSQL_PASSWORD |
secret | generated password(32) |
MYSQL_ROOT_PASSWORD |
secret | generated password(32) |
MAIL_FROM |
optional |
Lightweight self-hosted Git service with pull requests, issues, packages and Actions. Docs
| Input | Type | Default |
|---|---|---|
GITEA_SECRET_KEY |
secret | generated secret(64) |
GITEA_INTERNAL_TOKEN |
secret | generated secret(105) |
DISABLE_REGISTRATION |
boolean | false |
Only the web UI (HTTP, port 3000) is a public service.
Grafana
Section titled “Grafana”Dashboards and alerting for metrics, logs and traces from any data source (OSS edition). This is a separate Grafana for your own use, not Falak’s built-in one. Docs
| Input | Type | Default |
|---|---|---|
GF_SECURITY_ADMIN_USER |
string | admin |
GF_SECURITY_ADMIN_PASSWORD |
secret | generated password(24) |
GF_PLUGINS_PREINSTALL |
string | empty |
Langflow
Section titled “Langflow”Visual builder for AI agents and RAG pipelines, served as APIs. Docs
| Input | Type | Default |
|---|---|---|
LANGFLOW_SUPERUSER |
string | admin |
LANGFLOW_SUPERUSER_PASSWORD |
secret | generated password(24) |
LANGFLOW_SECRET_KEY |
secret | generated secret(48) |
POSTGRES_PASSWORD |
secret | generated password(32) |
Sign in with the admin username and the generated password (shown in the service variables). New sign-ups are inactive until the admin approves them.
listmonk
Section titled “listmonk”High-performance newsletter and mailing list manager with PostgreSQL. Docs
| Input | Type | Default |
|---|---|---|
ADMIN_USER |
string | admin |
ADMIN_PASSWORD |
secret | generated password(24) |
POSTGRES_PASSWORD |
secret | generated password(32) |
TIMEZONE |
select | UTC |
Mailpit
Section titled “Mailpit”Email testing: catches outgoing mail (SMTP and send API) and shows it in a web inbox. Docs
| Input | Type | Default |
|---|---|---|
MAILPIT_PASSWORD |
secret | generated password(24) (web UI) |
MAX_MESSAGES |
number | 5000 |
Not stateful: safe to run on several servers.
Matomo
Section titled “Matomo”Full-featured, privacy-respecting web analytics with heatmaps, goals and funnels. Docs
| Input | Type | Default |
|---|---|---|
DB_PASSWORD |
secret | generated password(32) |
DB_ROOT_PASSWORD |
secret | generated password(32) |
Open the URL after the first deploy to finish the installer. The database settings are filled in.
Meilisearch
Section titled “Meilisearch”Lightning-fast, typo-tolerant search engine with a REST API and hybrid (AI) search. Docs
| Input | Type | Default |
|---|---|---|
MEILI_MASTER_KEY |
secret | generated secret(32) |
MEILI_NO_ANALYTICS |
boolean | true |
Metabase
Section titled “Metabase”Business intelligence and dashboards anyone on your team can use, with PostgreSQL as its app database. Docs
| Input | Type | Default |
|---|---|---|
MB_ENCRYPTION_SECRET_KEY |
secret | generated secret(32) |
POSTGRES_PASSWORD |
secret | generated password(32) |
TIMEZONE |
select | UTC |
S3-compatible object storage with its web console. Uses a community build, because upstream stopped publishing images. Docs
| Input | Type | Default |
|---|---|---|
MINIO_ROOT_USER |
string | admin |
MINIO_ROOT_PASSWORD |
secret | generated password(32) |
Two public services: minio (the S3 API, port 9000) and console (the web console behind Caddy, port 8080). Each gets its own domain.
Workflow automation with 400+ integrations, code when you need it, and AI agents. Docs
| Input | Type | Default |
|---|---|---|
N8N_ENCRYPTION_KEY |
secret | generated secret(32). Keep it: stored credentials cannot be decrypted without it. |
TIMEZONE |
select | UTC (used by schedule triggers) |
Nextcloud
Section titled “Nextcloud”Files, calendar, contacts and office in one self-hosted cloud — a Google Drive alternative. Docs
| Input | Type | Default |
|---|---|---|
NEXTCLOUD_ADMIN_USER |
string | admin |
NEXTCLOUD_ADMIN_PASSWORD |
secret | generated password(24) |
DB_PASSWORD |
secret | generated password(32) |
DB_ROOT_PASSWORD |
secret | generated password(32) |
The first start installs Nextcloud and takes a few minutes. Sign in with the admin user and the generated password.
NocoDB
Section titled “NocoDB”Open-source Airtable alternative: spreadsheets, forms and APIs on top of your data. Docs
| Input | Type | Default |
|---|---|---|
NC_AUTH_JWT_SECRET |
secret | generated secret(48) |
POSTGRES_PASSWORD |
secret | generated password(32) |
Push notifications to your phone or desktop from any script with a simple HTTP PUT/POST. Docs
| Input | Type | Default |
|---|---|---|
DEFAULT_ACCESS |
select | read-write |
With read-write, anyone can publish and subscribe. For private topics, pick deny-all and add users with ntfy user add in the server terminal.
Ollama + Open WebUI
Section titled “Ollama + Open WebUI”Run open LLMs (Llama, Qwen, Mistral…) on your server with a ChatGPT-style interface. Docs
| Input | Type | Default |
|---|---|---|
WEBUI_SECRET_KEY |
secret | generated secret(48) |
ENABLE_SIGNUP |
boolean | true |
Pull a model from Admin Panel → Settings → Models (for example llama3.2:3b). Models run on the CPU, so size the server to the model. The first account becomes the admin.
Paperless-ngx
Section titled “Paperless-ngx”Scan, OCR and index your paper documents into a searchable archive. Docs
| Input | Type | Default |
|---|---|---|
PAPERLESS_ADMIN_USER |
string | admin |
PAPERLESS_ADMIN_PASSWORD |
secret | generated password(24) |
PAPERLESS_SECRET_KEY |
secret | generated secret(64) |
PAPERLESS_OCR_LANGUAGE |
string | eng |
Sign in with the admin user and the generated password.
Plausible Analytics
Section titled “Plausible Analytics”Privacy-friendly, cookie-free web analytics (Community Edition) with ClickHouse and PostgreSQL. Docs
| Input | Type | Default |
|---|---|---|
SECRET_KEY_BASE |
secret | generated secret(64) |
POSTGRES_PASSWORD |
secret | generated password(32) |
DISABLE_REGISTRATION |
select | invite_only |
Needs at least 2 GB of RAM (ClickHouse).
Qdrant
Section titled “Qdrant”Vector database for semantic search and RAG, with a web dashboard at /dashboard. Docs
| Input | Type | Default |
|---|---|---|
QDRANT_API_KEY |
secret | generated secret(40) |
Send the API key in the api-key header. The dashboard is at /dashboard.
Redis Stack
Section titled “Redis Stack”Redis with JSON, search, time series and probabilistic structures, plus the RedisInsight GUI behind a password. Docs
| Input | Type | Default |
|---|---|---|
REDIS_PASSWORD |
secret | generated password(32) |
INSIGHT_PASSWORD |
secret | generated password(24) |
Only the RedisInsight UI (insight, behind Caddy with a password) is public. Redis itself is not exposed to the internet.
Simple, fast, privacy-focused web analytics; a Google Analytics alternative. Docs
| Input | Type | Default |
|---|---|---|
APP_SECRET |
secret | generated secret(64) |
POSTGRES_PASSWORD |
secret | generated password(32) |
Uptime Kuma
Section titled “Uptime Kuma”Self-hosted uptime monitoring with status pages and 90+ notification channels. Docs
| Input | Type | Default |
|---|---|---|
TIMEZONE |
select | UTC |
Vaultwarden
Section titled “Vaultwarden”Lightweight Bitwarden-compatible password manager server; works with all Bitwarden apps. Docs
| Input | Type | Default |
|---|---|---|
ADMIN_TOKEN |
secret | generated secret(48) |
SIGNUPS_ALLOWED |
boolean | true |
Wiki.js
Section titled “Wiki.js”Modern wiki with a Markdown and visual editor, search and fine-grained permissions. Docs
| Input | Type | Default |
|---|---|---|
POSTGRES_PASSWORD |
secret | generated password(32) |
Open the URL after the first deploy to create the admin account. The setup page is open until you do.
WordPress
Section titled “WordPress”The world’s most popular CMS, on Apache with MariaDB. Docs
| Input | Type | Default |
|---|---|---|
DB_PASSWORD |
secret | generated password(32) |
DB_ROOT_PASSWORD |
secret | generated password(32) |
TABLE_PREFIX |
string | wp_ |
To deploy WordPress from your own repository instead, use the WordPress preset.