01One-command Docker
Fresh Linux VM or homelab box
Command
shellcurl -fsSL https://raw.githubusercontent.com/neuraparse/taskNebula/main/scripts/quickstart.sh | bashTaskNebula operations
TaskNebula's repo is Docker-first: published image, PostgreSQL 16 with pgvector, Redis 7, optional LiveKit voice rooms, optional cron sidecar, health checks, and explicit update paths.
Docker-firstPinned image v0.7.11GET /api/health

01Install matrix
A fresh Linux VM, a local Docker Desktop demo, a pinned production release, and a source build have different assumptions. Choose the path that matches the operating environment.
01One-command Docker
Command
shellcurl -fsSL https://raw.githubusercontent.com/neuraparse/taskNebula/main/scripts/quickstart.sh | bash02Docker Desktop
Command
shellcurl -fsSLo compose.yml https://raw.githubusercontent.com/neuraparse/taskNebula/main/docker-compose.desktop.yml && docker compose up -d03Pinned production
Command
shellTASKNEBULA_IMAGE=neuraparse/tasknebula:0.7.11 docker compose up -d04Source build
Command
shellgit clone https://github.com/neuraparse/taskNebula.git && cd taskNebula && docker compose up -d --build02Topology
The production Compose file keeps core services always-on and gates automation behind profiles. That reduces surprise-on services for first-time self-hosters.
01Published image first
The default production path pulls neuraparse/tasknebula, while source builds stay available for teams patching the repo.
02Localhost-bound services
The production Compose file binds database, Redis, and web ports to 127.0.0.1 by default so a reverse proxy can own the public edge.
03No Docker socket in web
Self-update is deliberately a signed handoff to an operator-managed updater. The app container does not need Docker socket access.
persistent volume
cache + pub/sub
voice rooms
GET /api/health
standup/janitor/version-check
03Production checklist
Pin the release, generate secrets, preserve state, limit exposure, and verify health before treating the installation as a production service.
Pin TASKNEBULA_IMAGE=neuraparse/tasknebula:0.7.11 outside quick demos.
Generate AUTH_SECRET, REDIS_PASSWORD, and LIVEKIT_API_SECRET per install.
Keep Compose ports bound to 127.0.0.1 and expose through TLS reverse proxy.
Back up postgres_data, redis_data, and uploads_data.
Pull image, restart, then verify GET /api/health.
Enable cron only with docker compose --profile cron up -d cron.
Prefer Admin -> Agent control and workspace settings over long-lived env keys.
04Update flow
The app can detect Docker Hub image pushes, notify super-admins, and send an opt-in signed handoff to an external updater. Manual Docker commands remain first-class.
Pinned update command
shelldocker compose pull web && docker compose up -d
curl -fsS http://localhost:3000/api/healthDocker Hub signal
in-app notice
human gate
manual or signed handoff
health endpoint
Run it yourself
TaskNebula is a self-hostable project-management control plane for teams that want inspectable operations instead of another black-box SaaS.