# Trilium's compose file publishes 8080 on every interface, and the firewall it names will not filter it

> Trilium Notes is an AGPL-3.0 hierarchical note application for building large personal knowledge bases, with a single npm workspace per client, server, desktop, mobile, docs, and website target. The file worth reading before you deploy is docker-compose.yml, which binds 8080 to the host, reaches for a firewall that does not filter Docker traffic, and defaults to a floating latest tag.

**TriliumNext/Trilium** — Build your personal knowledge base with Trilium Notes

- Repository: https://github.com/TriliumNext/Trilium
- Website: https://triliumnotes.org
- Stars: 38,026 · Forks: 2,560
- Language: TypeScript
- License: AGPL-3.0
- Published: 2026-08-08 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/triliumnext-trilium

## Port 8080 is published to the host, which makes the instance reachable at the host IP

The compose file maps a single port, `8080:8080`, and the comments around it are unusually candid about what that means. One says that by default Trilium will be available at `http://localhost:8080`. The next says it will also be accessible at `http://<host-ip>:8080`, which is the part that matters on a shared or office network. The comment then suggests limiting that with Docker Networks, reverse proxies, or firewall rules, and immediately warns that using UFW is known to not work with default Docker installations, with a link to the Docker documentation on packet filtering and firewalls. So what this configuration cannot do is rely on a host firewall rule to hide the service, because Docker writes its own rules ahead of the ones you add. The consequence is that the mitigation has to be a network or a proxy, and a reader who skips the comment gets a knowledge base on the LAN.

## The data directory is a plain host folder mounted under /home/node

State lives in a bind mount, `./trilium-data:/home/node/trilium-data`, and the comment at the top of the file says that running the compose command will create or use a `trilium-data` directory next to that file. The mount target names the container user, since the data path sits under a `node` home directory rather than a system path. Two more mounts are read only: `/etc/timezone:/etc/timezone:ro` and `/etc/localtime:/etc/localtime:ro`, so the instance follows the host clock and timezone rather than the container default. What this cannot give you is a storage abstraction, since the data is an ordinary directory on the host. The consequence is that backup, restore, and moving to a new machine are all file operations on that folder, and changing the host side of the volume mapping is the supported way to relocate it.

## The image tag defaults to latest, which the file itself flags as a hazard

The service runs `triliumnext/trilium:latest`, and the comment above it says you can optionally replace `latest` with a version tag such as `v0.90.3`, warning that using `latest` may cause unintended updates to the container. The restart policy is `unless-stopped`, so the container comes back on reboot and there is no version gate in that path. The two facts combine into a real behaviour. A pull followed by a restart cycle can move you to a different release without any action on your part, which for an application holding years of notes is the wrong default. The sample tag in the comment is also stale relative to the release history, where v0.106.0 is the current version, so copying the comment literally gets you a version from a long way back. What to do is pick the tag on purpose and treat the comment as a hint rather than a recommendation.

## After v0.90.4 the sync version moved and direct migration from the original stops

The migration section separates two things that are easy to conflate. For the database, there are no special steps: install TriliumNext as usual and it will use your existing database. For synchronisation, there is a hard boundary. Versions up to and including v0.90.4 are compatible with the latest release of the original project, v0.63.7, while any later version has its sync version incremented, which prevents direct migration. So what a new install cannot do is point itself at a sync server from the older line and negotiate with it, because the two sides no longer agree on a version. The consequence is that moving an existing notebook across the boundary is a database operation, not a synchronisation one, and anyone who relied on the older line as a sync client has to plan for that rather than assume continuity. The project attributes the fork in ownership to the original developer handing the repository to the community project.

## The script called server:start runs the server package's dev target

Every root script is a filtered call into a workspace rather than a real command, with the pattern `pnpm run --filter <target> <script>`. The consequence is that the name on the left and the name on the right are not the same thing, and reading only the left one misleads you. `server:start` filters server and calls `dev`. `server:start-alt` calls `dev-alt`. `server:start-prod` calls `start-prod`, and the desktop equivalents follow the same split with `dev` and `start-prod`, including a `start-prod-no-dir` variant. The electron aliases are pure indirection, since `electron:build` is just `pnpm desktop:build` and `electron:start` is `pnpm desktop:start`. So what the root manifest cannot show you is whether a given start is a development or a production server. Read the right-hand token, not the left.

## The feature list names six UI languages and the switcher links twenty-one

One bullet says the UI is available in English, German, Spanish, French, Romanian, and Chinese in both simplified and traditional scripts. The language switcher at the top of the file links a separate README per language and lists Arabic, Czech, English for the United Kingdom, Greek, Indonesian, Irish, Italian, Japanese, Korean, Polish, Russian, Ukrainian, Urdu, and Uyghur alongside the ones already named. A Weblate badge points at the hosted translation platform. So the two numbers in the same file disagree, and the feature bullet is the smaller one. What the switcher cannot tell you is the completeness of any given translation, since a linked file proves a translation exists rather than that it is current. The consequence is that a reader sizing the international reach of the interface should count the switcher, and a reader shipping a localized deployment should still verify the strings they depend on.

## One application, seven build targets, and a monorepo that also builds its own docs

The workspace targets are client, server, desktop, standalone, mobile, edit-docs, and website, and the root scripts fan out to all of them. A few are peripheral to the application itself: `edit-docs` has its own edit, sync, and build scripts and a separate `edit-docs-config.yaml`, `website` builds the public site, and `mobile:sync` is the only mobile entry point. Around them sit tooling files that describe how the whole thing is assembled, including `pnpm-workspace.yaml`, `pnpm-lock.yaml`, `tsconfig.base.json`, `vitest.config.ts`, two eslint configurations split into `eslint.config.mjs` and `eslint.format.config.mjs`, a `renovate.json`, a `flake.nix` with its lock, a `patches/` directory, and a `codecov.yml`. So what a single change cannot avoid is a wide surface: a server-side change has to be validated against the client, the desktop wrapper, the standalone build, and the mobile sync path, and the docs site is versioned on the same cycle.

## Conclusion

Trilium suits one person or a small group who wants a hierarchical tree with per-note encryption, attributes, scripting, and a REST API on their own machine, and who is willing to read the compose comments before exposing anything. It is a poor fit for a network-facing deployment started by copying the file as shipped, since the port lands on every interface and the UFW suggestion in the comment does not work with a default Docker install. Before deploying, put a reverse proxy or Docker network in front of it, pin the image tag instead of latest, and confirm the AGPL-3.0 terms fit how you intend to share the instance.

## FAQ

### how to install trilium

The repository ships a docker-compose.yml, and the comments in it say that running `docker-compose up` will create or use a `trilium-data` directory next to that file, while `docker-compose up -d` runs it in the background. For other platforms, the README links installation instructions, a Docker setup page, and an upgrading page on docs.triliumnotes.org.

### is trilium notes free

Yes. It is described as a free and open-source cross-platform application and is released under the AGPL-3.0 license. The project also points at third-party resources and communities, including the awesome-trilium list and TriliumRocks.

### is trilium notes safe

The repository ships a SECURITY.md, and the application offers note encryption with per-note granularity plus direct OpenID and TOTP integration for login. The compose file that ships with it maps 8080 to the host and notes the instance is also reachable at the host IP, suggesting Docker networks, a reverse proxy, or firewall rules, with a warning that UFW does not work with default Docker installations.

### is trilium notes open source

It is published under the AGPL-3.0 license with a LICENSE file in the repository root. The README also states that the original developer handed the Trilium repository to the community project that now resides at the TriliumNext organization.

### trilium vs obsidian

The project does not publish that comparison. What it states about itself is that it is a hierarchical note taking application focused on building large personal knowledge bases, that it scales well upwards of 100 000 notes, and that it offers attributes for organization and querying, a REST API for automation, and scripting.

## Sources

- [Official documentation](https://triliumnotes.org)
- [Official README](https://github.com/TriliumNext/Trilium#readme)
- [Project repository](https://github.com/TriliumNext/Trilium)
- [Release notes](https://github.com/TriliumNext/Trilium/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/triliumnext-trilium
