# Plainleaf on ZSpace NAS This deployment runs the account-managed Plainleaf server on the ZSpace NAS. Build the amd64 image on the development machine, then transfer and load it on the NAS; the NAS does not need Docker Hub access. Server configuration, deployment files, and Markdown data remain separate: - Deployment: `个人空间/docker/plainleaf` - Server configuration: `个人空间/docker/plainleaf/data` - Markdown space: `个人空间/笔记管理/Plainleaf` The server listens on NAS port `31230`, runs as the NAS account's UID/GID, and has shell execution disabled. Accounts are stored as password hashes in the server configuration directory. No password belongs in `.env`. The intended `.env` keys are: ```dotenv PLAINLEAF_IMAGE_TAG= PLAINLEAF_UID=1001 PLAINLEAF_GID=1001 PLAINLEAF_PORT=31230 PLAINLEAF_SERVER_PATH=/tmp/zfsv3/sata11/13616066635/data/docker/plainleaf/data PLAINLEAF_SPACE_PATH=/tmp/zfsv3/sata11/13616066635/data/笔记管理/Plainleaf ``` ## Single-user to account-managed migration 1. Keep the existing Markdown directory unchanged and take a NAS snapshot or file-level backup before deployment. 2. Create the empty `PLAINLEAF_SERVER_PATH` directory. It must be writable by `PLAINLEAF_UID:PLAINLEAF_GID`. 3. Remove the old `PLAINLEAF_USER` line from `.env` and add `PLAINLEAF_SERVER_PATH`. 4. Start this Compose project. An empty `/data` opens the setup wizard at `https:///.setup/`. 5. In the wizard, create the administrator account. For the first space use name `Plainleaf`, URL path `/`, and data directory `/notes`. 6. After setup, open `/.spaces/users` to add users and `/.spaces` to assign space access. Administrators always retain access. The migration does not move, rename, or rewrite any Markdown. `users.json`, `spaces.json`, and the server session secret are written only below `PLAINLEAF_SERVER_PATH`. ## Rollback Stop only the `plainleaf` container, restore the previous Compose file and its `PLAINLEAF_USER`, and mount `PLAINLEAF_SPACE_PATH` at `/space` again. Do not delete either data directory. Because the Markdown path never moved, the old single-user container can read it immediately. Do not commit the real `.env` file. Keep HTTPS enabled before exposing the account-managed server publicly.