Getting Started

Ghostfolio is an open source (AGPL-3.0) wealth management app for tracking your net worth across stocks, ETFs and cryptocurrencies. Available as an open web service in Eyevinn Open Source Cloud, it stores its data in a PostgreSQL database and uses a Valkey (Redis-compatible) instance, so the Ghostfolio instance itself is stateless.

Prerequisites

Step 1: Create a PostgreSQL database

Create an instance of the PostgreSQL service (see Service: PostgreSQL). Set a password and set PostgresDb to ghostfolio. Leave the user at its default (postgres).

Open the instance details and note the internal cluster address, which has the form <tenant>-<name>.birme-osc-postgresql.svc.cluster.local. Your database URL is:

postgresql://postgres:<password>@<tenant>-<name>.birme-osc-postgresql.svc.cluster.local:5432/ghostfolio

Ghostfolio creates and migrates the database schema automatically on every start.

Step 2: Create a Valkey instance

Create an instance of the Valkey service (see Service: Valkey). The Password option is optional. The instance details show only an external address, so use the internal address instead, which has the form <tenant>-<name>.valkey-io-valkey.svc.cluster.local, port 6379.

Step 3: Generate secrets

Generate two long random strings and keep them in your password manager:

openssl rand -hex 32
openssl rand -hex 32

Use the first as AccessTokenSalt and the second as JwtSecretKey. Never change AccessTokenSalt after you have created accounts. Ghostfolio derives users' security tokens from it, and a different salt locks everyone out.

Step 4: Store the values as secrets

Navigate to the Ghostfolio service and go to the "Service Secrets" tab. Click "New Secret" and create:

  • ghostdburl: the PostgreSQL URL from Step 1
  • ghostsalt: the first random string from Step 3
  • ghostjwt: the second random string from Step 3
  • ghostredispw: the Valkey password, only if you set one

Step 5: Create the Ghostfolio instance

Create an instance of the Ghostfolio service and fill in:

Field Required Description
Name Yes Instance name, alphanumeric only
DatabaseUrl Yes {{secrets.ghostdburl}}
RedisHost Yes The Valkey internal address from Step 2
RedisPort No Defaults to 6379
RedisPassword No {{secrets.ghostredispw}}, leave empty if the Valkey has no password
AccessTokenSalt Yes {{secrets.ghostsalt}}
JwtSecretKey Yes {{secrets.ghostjwt}}

Wait until the instance status is green and "running". The first start takes a minute or two while the database is set up.

Step 6: First sign-in

Open the instance URL in your browser while signed in to OSC and click "Get Started". Ghostfolio creates an anonymous account and shows a security token once. Save it in your password manager, you use it to sign in later.

The first account created on a fresh instance gets the admin role, so create your own account right after the instance starts.

Configuration

Setting Required Description
DatabaseUrl Yes (sensitive) postgresql://postgres:<password>@<postgres-internal-dns>:5432/ghostfolio
RedisHost Yes Valkey internal address
RedisPort No Valkey port, default 6379
RedisPassword No (sensitive) Valkey password, empty if none
AccessTokenSalt Yes (sensitive) Long random string. Must stay the same across restarts
JwtSecretKey Yes (sensitive) Long random string. Keep it secret

All data lives in PostgreSQL. The default market data source is Yahoo Finance, which needs no key. Other data provider API keys and optional features are not exposed as options.

Limitations

  • Behind the OSC sign-in only. The OSC sign-in protects every path except /, which redirects to a protected page. The whole UI and the API require an OSC sign-in, so apps outside OSC cannot reach the API. In the first minute or two after creating an instance, some requests can get an odd 404 before the access rules settle. Wait and retry.
  • Keep the AccessTokenSalt. Changing it makes existing security tokens stop working and locks users out.
  • The first account created is the admin, so sign up immediately after creating the instance.
  • No backup is configured. Back up the PostgreSQL instance, it holds all your portfolio data.
  • Personal finance data is sensitive. Protect your OSC account.
  • Not tested: importing activities, data providers, OIDC or Google sign-in, a Valkey password, TLS to PostgreSQL, and upgrades.

Resources