services: broker: # Task queue only; holds nothing worth backing up. image: docker.io/valkey/valkey:9-alpine container_name: paperless-broker restart: unless-stopped volumes: - ./redisdata:/data webserver: # Pin the exact version; read the release notes before bumping. # https://github.com/paperless-ngx/paperless-ngx/releases image: ghcr.io/paperless-ngx/paperless-ngx:3.2.1 container_name: paperless restart: unless-stopped depends_on: - broker # No published ports: only reachable through NPM on the shared `proxy` # network, same as Vaultwarden. `default` reaches the broker. networks: - default - proxy # PAPERLESS_SECRET_KEY lives here — never commit it. See .env.example. env_file: .env environment: PAPERLESS_REDIS: redis://broker:6379 PAPERLESS_DBENGINE: sqlite PAPERLESS_URL: "https://paperless.home.staffenberger.at" PAPERLESS_TIME_ZONE: Europe/Vienna PAPERLESS_OCR_LANGUAGE: deu+eng # The consume folder is an SMB share: no inotify over the network, so poll. PAPERLESS_CONSUMER_POLLING_INTERVAL: 60 # scans//file.pdf gets the tag . PAPERLESS_CONSUMER_RECURSIVE: "true" PAPERLESS_CONSUMER_SUBDIRS_AS_TAGS: "true" # The MFC-L3750CDW can't scan both sides. Two scans into a # `double-sided` subfolder (front sides, then the flipped stack) # are merged into one document. See README. PAPERLESS_CONSUMER_ENABLE_COLLATE_DOUBLE_SIDED: "true" volumes: # Database, search index and the documents themselves. Local on the # NVMe; the nightly export to the NAS is the backup. - ./data:/usr/src/paperless/data - ./media:/usr/src/paperless/media # NAS shares, mounted on the host by systemd automount (see README). # rslave lets the mount that automount creates show up in the container. - type: bind source: /mnt/nas/scans target: /usr/src/paperless/consume bind: propagation: rslave - type: bind source: /mnt/nas/paperless-export target: /usr/src/paperless/export bind: propagation: rslave networks: proxy: external: true