What | What for | If you do not have it |
|---|---|---|
A Linux server with Docker | This is where Kendoshi runs. A small VPS is enough: 1 CPU, 2 GB RAM, 10 GB disk. A NAS with Docker or a Raspberry Pi 4 works too (amd64 or arm64). | Rent a VPS with Ubuntu or Debian at a provider of your choice. Install Docker, see B0. |
A subdomain | For example kendoshi.your-domain.com. This is where the team reaches the server, and Caddy fetches the HTTPS certificate for it. | At your domain provider, create an A record pointing at the server's IP. It can take up to an hour to take effect. |
Ports 80 and 443 open | HTTP and HTTPS reachable from outside. Without port 80 Caddy gets no certificate. | Check the provider's firewall (often a setting in the customer panel); on the server ufw allow 80 and ufw allow 443. |
SSH access to the server | So you can run commands in a terminal: ssh root@your-server-ip | Your provider gives you this with the server. On a Mac the Terminal app is already there. |
The licence line | From your purchase email, starts with PHP1. It unlocks the second and every further user. | Start without it: one user works without a licence, with no time limit. Buy: posthopeproduction.com/store.html |
All commands run on the server, after ssh root@your-server-ip. Paste line by line, press Enter, read the output.
docker compose version
If a version number appears, continue with step 1. If it says command not found, install Docker with the official script (Ubuntu, Debian):
curl -fsSL https://get.docker.com | sh
docker compose version
The template is published as env.example (no leading dot, because Apache does not reliably serve dotfiles) and lands directly as .env with this command. The same guide in the browser: posthopeproduction.com/kendoshi/server.html
mkdir -p ~/kendoshi && cd ~/kendoshi
curl -fsSL https://posthopeproduction.com/kendoshi/docker-compose.release.yml -o docker-compose.yml
curl -fsSL https://posthopeproduction.com/kendoshi/env.example -o .env
openssl rand -hex 32
nano .env
The first line prints a long random value. In nano: set DOMAIN to your subdomain, AUTH_SECRET to the random value. Leave KENDOSHI_LICENSE and BOARDIST_SETUP_TOKEN empty. Save with Ctrl+O, Enter, quit with Ctrl+X. The file then looks like this:
DOMAIN=kendoshi.your-domain.com
AUTH_SECRET=3f9a...long random value...c21e
KENDOSHI_LICENSE=
BOARDIST_SETUP_TOKEN=
docker compose up -d
docker compose ps
The first start pulls the image (about 500 MB) and takes one to two minutes. Afterwards docker compose ps shows app as healthy and caddy as running. During this time Caddy fetches the certificate for your domain.
docker compose logs app | grep Setup-Token
Open https://your-subdomain in the browser. The page asks for the setup token from the log, so that a random first visitor cannot become admin. Enter the token, choose name, email and password. That is your admin account, and the setup route is closed afterwards.
All in the browser, signed in as admin. The order matters: structure first, then licence, then people. If you invite first, you have to grant access to everyone one by one afterwards.
Settings, Workspace: enter your team's name. It appears at the top of the sidebar and in the calendar subscriptions.
Projects are the boards. One project per undertaking or area, for example Release, Office, Client X.
Folders bundle projects in the sidebar. Create them only once there are more than five projects.
Groups are the sections inside a board, for example This week, Later, Waiting. Every project automatically gets a group Done at the bottom.
Start with three projects and two groups each. Structure grows with the team, not ahead of it.
Settings, section License: paste the line from your purchase email (the whole line, from PHP1. to the last character), click "Add license". The page then shows "Licensed to" name (email). No restart. Alternatively put the line into .env as KENDOSHI_LICENSE and run docker compose up -d; the field in the interface is then read-only.
Settings, Team, create an invite link. The link is valid for 14 days and exactly once. One link per person.
Send the link. The person registers with it, choosing name, email and password.
Then, without fail: open Access for the new member and share the folders and projects. Without sharing, the person only sees their inbox and private projects and thinks the server is empty.
Role | May |
|---|---|
Admin | Manage the team, grant access, change settings, write in the wiki, reset passwords. Make someone admin via the three-dot menu next to the member. |
Member | Work in the shared projects, read the wiki, keep their own private projects. |
Everyone | Inbox and private projects are visible to nobody else, not even admins. |
Automations and AI agents get their own member account with their own API token, never an admin account.
Browser: https://your-subdomain, always the complete picture. On the phone use Add to Home Screen, then it behaves like an app.
Kendoshi for Mac, iPhone, iPad: on first launch choose Connect to team, enter the server address https://your-subdomain and your personal API token. Every person fetches their own token: Settings, API token, create token.
Calendar: Settings, Calendar sync, copy the personal feed address, add it in Apple Calendar as a subscription or in Google via URL. Tasks with a time remind you 30 minutes before. The address is personal, never pass it on.
AI: Settings, API token, copy the link. The link goes into Claude under Settings, Connectors, Add custom connector. The AI then reads and writes with exactly that person's rights and can never delete. Since 2.14 the server answers the AI in English, field names included (for example created instead of erstellt, effort instead of aufwand). If you wrote your own scripts against the connector, adjust the field names. Details in the Setup Kit Claude Code and MCP.
Book icon at the bottom of the sidebar. Everyone can read, only admins write. Good for what everybody needs to know: rules, procedures, who to ask. A first page How we use Kendoshi with the three sentences from part D saves many questions later.
The essentials in three sentences, the way they get passed on in a team: Press Q for quick entry. My Day is the start page for the day. The sun brings a task into today.
Deliver mix tomorrow 2pm p1 @alisha #Release /This week
Shortcut | Effect |
|---|---|
tomorrow, fri, next week, 24.7. | Due date |
2pm, 14:30 | Time, creates a reminder |
daily, every monday, every 2 weeks, monthly | Recurrence |
p1 to p4 | Priority, p1 tints the row red |
@name | Assign a person |
#project | Target project; without # the task lands in your own inbox |
/group | Group inside the project |
The shortcuts work in English and German (morgen, jeden montag, 14uhr).
Area | What happens there |
|---|---|
Inbox | Private intake. Everything may land here first, sorting comes later. Checked-off items disappear after 30 seconds. |
My Day | Only today, in blocks from morning to evening. What was marked with the sun or is due today. Suggestions from overdue and urgent items on the right. |
My Work | Everything assigned to you, by date, project or priority. |
Boards | The projects with their groups. Clicking a title opens the detail with notes, subtasks, links and comments with @mentions. |
Calendar | Today, week, month, timeline. Dragging sets date and time. |
Reminders | Settings, Reminders: allow notifications once. Tasks with a time are announced 30 minutes before, in the browser or, with Kendoshi Desktop, as a system notification. |
Completed tasks move to the group Done and stay as a log. Deleted items sit in the trash for 30 days and can be restored. Everything else, from recurring tasks to mail drop, is in the Kendoshi user handbook.
All data lives in a single file: /data/boardist.db inside the Docker volume boardist-data. Next to it license.txt and the folder backups/. Whoever backs up this one file has everything.
cd ~/kendoshi
docker compose exec app cp /data/boardist.db /data/backups/boardist-manual.db
docker cp "$(docker compose ps -q app)":/data/backups/boardist-manual.db ./kendoshi-backup-$(date +%Y-%m-%d).db
The file kendoshi-backup-date.db belongs somewhere else: another machine, a cloud folder, whatever you back up anyway. In addition the server writes a dated backup to /data/backups/ on every start and keeps the last seven. That is the seat belt, not a replacement for a copy outside the server.
On the server open crontab -e and append this line. It saves every night at three to ~/kendoshi-backup-date.db:
0 3 * * * cd ~/kendoshi && docker compose exec -T app cp /data/boardist.db /data/backups/boardist-cron.db && docker cp "$(docker compose ps -q app)":/data/backups/boardist-cron.db ~/kendoshi-backup-$(date +\%Y\%m\%d).db
cd ~/kendoshi
docker compose pull
docker compose up -d
docker-compose.yml pins the version (image: ...:2.14.0). For a new version change the number there and run the two commands. If you always want the newest, use latest. Before every schema change the container writes a copy /data/boardist.pre-push.db and applies the change itself. After the update reload the browser once.
From a backup file on the server (adjust the file name):
cd ~/kendoshi
docker compose stop app
docker cp ./kendoshi-backup-2026-09-18.db "$(docker compose ps -q -a app)":/data/boardist.db
docker compose start app
From an automatic backup inside the container, without pulling the file out first (file name from docker compose exec app ls /data/backups):
docker compose stop app
docker compose run --rm --no-deps --entrypoint sh app -c 'cp /data/backups/boardist-2026-09-18_162741.db /data/boardist.db'
docker compose start app
On the old server: take a manual backup (above) and save the .env file.
On the new server: do part B up to step 3, using the same .env (same AUTH_SECRET, otherwise everyone is signed out).
Restore as above, then point the domain's A record at the new IP.
Forgotten password: there is no email reset. An admin sets a new one under Settings, Team, three-dot menu next to the member, Reset password, and hands it over in person. The person then changes it under Account and security.
Lost device: the person chooses Sign out everywhere under Account and security and revokes their API token.
Member leaves: an admin removes them via the menu next to the member. Their tasks stay, only the access is gone.
Admin locked out: a second admin helps. So appoint two admins from the start.
If the terminal makes you nervous, let yourself be guided. The prompts work with Claude, ChatGPT or any other AI. Prompt 2 needs Claude Code or an AI that is allowed to run commands on the server.
For any AI in a chat. It runs nothing itself; it tells you what to type and reads your output.
You are helping me install Kendoshi Team on my own server. I am not a
technician. Guide me step by step, one step at a time, and wait for my
answer before naming the next one. Each step: one sentence on what happens,
then the finished command to copy, then what I should see as output.
The facts. Stick to them exactly, do not invent anything:
- Kendoshi Team is a Docker image. It needs a Linux server with Docker
Compose v2, a subdomain with an A record pointing at the server, and
ports 80 and 443 open.
- Installation: create the folder ~/kendoshi. Fetch two files:
curl -fsSL https://posthopeproduction.com/kendoshi/docker-compose.release.yml -o docker-compose.yml
curl -fsSL https://posthopeproduction.com/kendoshi/env.example -o .env
- Two values in .env are required: DOMAIN (my subdomain) and AUTH_SECRET
(output of: openssl rand -hex 32). KENDOSHI_LICENSE and
BOARDIST_SETUP_TOKEN stay empty.
- Start: docker compose up -d. Check: docker compose ps (app healthy).
- The first visit in the browser asks for a setup token. It is in the log:
docker compose logs app | grep Setup-Token
- Then create the admin account. The licence is added later in the
interface under Settings, Licence (the line from the purchase email,
starts with PHP1.). Without a licence one user works.
- Backup is one file: /data/boardist.db in the volume boardist-data.
Ask me first: Do I already have a server with SSH access? Do I have a
subdomain? Is Docker installed (docker compose version)? Then start with
the first open point.
If an output does not match what you expect, stop and explain to me in
plain words what went wrong before we continue. Never give me commands
that delete data without saying first what they delete.
For Claude Code on your Mac, with SSH access to the server. Have the server IP, the subdomain and a working ssh login ready. The AI works, you give your OK at three points.
TASK: Install Kendoshi Team on my server.
Server: ssh root@<SERVER-IP> (login already works)
Subdomain: <kendoshi.my-domain.com> (A record points at the server)
Rules:
- Work over ssh on the server, step by step, and show me the output after
each step.
- Three points need my OK before you continue: (1) before you install
Docker, (2) before you run docker compose up -d, (3) before you delete or
overwrite anything.
- Generate AUTH_SECRET with openssl rand -hex 32 directly on the server and
write it into .env. Do not show it to me in the chat.
- Install nothing except Docker. Do not change firewall rules without
asking. Do not touch other containers.
Steps:
1. Check: operating system, docker compose version, whether ports 80 and
443 are free (ss -tlnp), whether the subdomain points at the server IP
(dig +short). Report, then wait.
2. If Docker is missing: curl -fsSL https://get.docker.com | sh (after OK).
3. mkdir -p ~/kendoshi, fetch the two files there:
https://posthopeproduction.com/kendoshi/docker-compose.release.yml as docker-compose.yml
https://posthopeproduction.com/kendoshi/env.example as .env
(curl -fsSL <address> -o <filename>), set DOMAIN and AUTH_SECRET,
leave KENDOSHI_LICENSE and BOARDIST_SETUP_TOKEN empty.
4. Show me the .env without the value of AUTH_SECRET, wait for my OK, then
docker compose up -d.
5. Wait until docker compose ps shows app as healthy. Then
curl -sI https://<subdomain> and name the setup token from
docker compose logs app | grep Setup-Token.
6. Propose a cron line for the nightly backup (do not install it), write
the backup and update commands into a file ~/kendoshi/README.txt.
7. Final report: what is running, where the data lives, what I do next in
the browser (setup token, admin account, licence, invite the team).
My Kendoshi Team server has a problem. Help me find the cause before we
change anything. I run the commands and send you the output.
What I see: <describe here, for example: browser shows a certificate
error / page does not load / invitation is rejected / after the update the
container does not start>
Let me run these commands one after the other and interpret each output:
cd ~/kendoshi && docker compose ps
docker compose logs --tail=50 app
docker compose logs --tail=50 caddy
cat .env | sed 's/AUTH_SECRET=.*/AUTH_SECRET=(set)/'
dig +short <my subdomain>
curl -sI https://<my subdomain>
Known causes, check these first:
- AUTH_SECRET missing in .env: the container does not start, the log says so.
- DNS does not point at the server or port 80/443 is closed: Caddy gets no
certificate, the caddy log shows acme errors.
- "Without a license exactly one user works": not a fault, the licence
is missing.
- "attempt to write a readonly database": the volume is not owned by UID 1000.
- Everyone signed out: AUTH_SECRET was changed, normal.
Only propose a fix once the outputs support it. Before every command that
changes something, tell me what it does and whether a backup is needed.
Message or symptom | Cause and fix |
|---|---|
First visit says "Setup token missing or wrong" | Intended. docker compose logs app | grep Setup-Token |
HTTPS does not work, certificate error | ping your-subdomain must show the server IP. Are ports 80 and 443 open from outside? docker compose logs caddy shows where it hangs. After a DNS change wait up to an hour. |
Container does not start, the log mentions AUTH_SECRET | The value is missing in .env. openssl rand -hex 32, add it, docker compose up -d. |
attempt to write a readonly database | The volume is not owned by user node (UID 1000), for example after a move. Once: docker compose stop app && docker run --rm -v kendoshi_boardist-data:/data alpine chown -R 1000:1000 /data && docker compose start app. Volume name from docker volume ls. |
Invitation says "Without a license exactly one user works" | Not a fault. Install the licence (part C, step 3); the invite link stays valid. |
"This license does not belong to Kendoshi Team" | That is a licence for Zimezumi or Switchy. Use the Kendoshi Team line from the purchase email. |
"The key seems to be copied incompletely" | Copy the whole line, from PHP1. to the last character. Line breaks from the mail client do not matter. |
Everyone suddenly signed out | AUTH_SECRET was changed. Normal, everyone signs in once more. That is why you take the same .env with you when moving. |
New member sees no projects | Access not shared. Settings, Team, next to the member Access, tick folders and projects. |
Update ran, page looks old | Reload the browser. On the phone, add the web app to the home screen once more if the icon stays old. |
Where is the AI assistant | Not part of the server package, no API key needed. AI comes in through the connector link, part C step 6. |
The .env is the server's key file. Never pass it on, never into a chat, include it in your backup.
Three things are personal and belong to nobody else: password, connector link with API token, calendar feed address. If one leaks: revoke the token, regenerate the feed links.
The server is reachable from the internet, so install updates when a new version is out. Two commands, part E.
The AI also reads other people's text through the connector (comments, wiki). If an instruction sits there, it may take it for an order. Do not confirm proposals nobody asked for.
Backup outside the server, every night, one file. Once a month check that the file is there and has a sensible size.
Date | What |
|---|---|
06.10.2026 | Updated to 2.14.0: interface in English and German with the language switch, labels and messages quoted in English, licence button "Add license", groups in quick entry with /group, the server answers the AI in English. |
18.09.2026 | Handbook created from SERVER.md, env.example, docker-compose.release.yml and the entrypoint (2.12.2) plus the user handbook. Parts A to H, three AI prompts. |
18.09.2026 | Download commands changed to curl -fsSL ... -o (template published as env.example). Server page of the Kendoshi website linked. |
24.09.2026 | Updated to 2.12.2: version references, Reminders row instead of the removed alien flat share. |
18.09.2026 | Rewritten in English. All handbooks are English from now on; the German first version is archived. |