
Deploy SilverBullet team notes
Authenticated multi-space Markdown notes without a browser runtime
SilverBullet
Just deployed
/data
Deploy and Host SilverBullet team notes on Railway
Authenticated multi-space Markdown notes without a browser runtime.
About Hosting SilverBullet team notes
Run SilverBullet as a single-node workspace for a small trusted team. Create independently authorized Markdown spaces with notes, attachments and the native account dashboard. This recipe uses pinned SilverBullet2.11.1 slim, a generated administrator password and one persistent5000MB volume mounted at /data.
Why Deploy SilverBullet team notes
Explore private per-account spaces and browser-cached note editing without adding a database, broker or external identity provider. The setup wrapper creates an administrator and private /team before listening and fails closed on incomplete account/space configuration. Only the app is public through Railway HTTPS; API tokens are per account. Administrators intentionally access every space, and writers must be trusted collaborators—not hostile tenants.
Common Use Cases
- Keep team handbooks and retained attachments in separately authorized spaces.
- Edit a previously opened and synchronized note during an outage, then reconnect.
- Learn stopped-writer full-root backup and recovery that preserves accounts, permissions, tokens and content.
Dependencies for SilverBullet team notes
One Docker-based SilverBullet service, one single-service /data volume and the sanitized standalone source repository on release-v1, root /. Recipe contract1.0.2 is separate from upstream2.11.1. No Chromium, browser Runtime API, database, broker, SMTP or paid provider is required.
Deployment Dependencies
SB_ADMIN_USER defaults to admin; SB_ADMIN_PASSWORD is generated natively and preserved for initialized deployments. Runtime defaults are SB_FOLDER=/data, SB_HOSTNAME=::, SB_PORT=3000, PORT=3000 and PUID/PGID1000. Generated environment credentials initialize empty installations only; changing them does not reset existing accounts.
Create ordinary accounts and spaces in the dashboard with anonymous access none, explicit memberships and shell capabilities disabled. Keep all space folders within /data. The slim image deliberately denies browser Runtime API requests with503. Git sync, SSO, broader interactive workflows, hostile-tenant operation and HA remain unqualified. Use one replica; a persistent volume does not provide HA.
Offline editing requires a previously synchronized browser and retained service-worker/local state; do not clear unsynchronized browser data. For recovery, stop writers and restore an encrypted archive of the entire /data root into an empty target before startup, including hidden authentication/configuration state and all spaces. Do not accept untrusted archives or CONTAINER_BOOT.md: upstream can execute that file at boot. See the distributed README/SUPPORT/UPGRADE instructions.
Final-source native authentication/private-space allow/deny, restart, real browser server-outage edit/reconnect, distinct fresh-volume full-root restore and a bounded120-read/two-client soak were checked. This is not a capacity, universal vulnerability/license or physical-storage/billing-zero guarantee. Qualification scratch compute is stopped and standard deletions accepted; platform storage retention is disclosed separately. This listing overview is maintained independently of the immutable recipe source and does not change its runtime graph.
Main upstream products
Template Content
SilverBullet
tech-progress/silverbullet-team-notes