Getting Started
Ghostfolio is an open source (AGPL-3.0) wealth management app for tracking your net worth across stocks, ETFs and cryptocurrencies. Available as an open web service in Eyevinn Open Source Cloud, it stores its data in a PostgreSQL database and uses a Valkey (Redis-compatible) instance, so the Ghostfolio instance itself is stateless.
Prerequisites
- If you have not already done so, sign up for an Eyevinn OSC account
opensslon your machine
Step 1: Create a PostgreSQL database
Create an instance of the PostgreSQL service (see Service: PostgreSQL). Set a password and set PostgresDb to ghostfolio. Leave the user at its default (postgres).
Open the instance details and note the internal cluster address, which has the form <tenant>-<name>.birme-osc-postgresql.svc.cluster.local. Your database URL is:
postgresql://postgres:<password>@<tenant>-<name>.birme-osc-postgresql.svc.cluster.local:5432/ghostfolio
Ghostfolio creates and migrates the database schema automatically on every start.
Step 2: Create a Valkey instance
Create an instance of the Valkey service (see Service: Valkey). The Password option is optional. The instance details show only an external address, so use the internal address instead, which has the form <tenant>-<name>.valkey-io-valkey.svc.cluster.local, port 6379.
Step 3: Generate secrets
Generate two long random strings and keep them in your password manager:
openssl rand -hex 32
openssl rand -hex 32
Use the first as AccessTokenSalt and the second as JwtSecretKey. Never change AccessTokenSalt after you have created accounts. Ghostfolio derives users' security tokens from it, and a different salt locks everyone out.
Step 4: Store the values as secrets
Navigate to the Ghostfolio service and go to the "Service Secrets" tab. Click "New Secret" and create:
ghostdburl: the PostgreSQL URL from Step 1ghostsalt: the first random string from Step 3ghostjwt: the second random string from Step 3ghostredispw: the Valkey password, only if you set one
Step 5: Create the Ghostfolio instance
Create an instance of the Ghostfolio service and fill in:
| Field | Required | Description |
|---|---|---|
| Name | Yes | Instance name, alphanumeric only |
| DatabaseUrl | Yes | {{secrets.ghostdburl}} |
| RedisHost | Yes | The Valkey internal address from Step 2 |
| RedisPort | No | Defaults to 6379 |
| RedisPassword | No | {{secrets.ghostredispw}}, leave empty if the Valkey has no password |
| AccessTokenSalt | Yes | {{secrets.ghostsalt}} |
| JwtSecretKey | Yes | {{secrets.ghostjwt}} |
Wait until the instance status is green and "running". The first start takes a minute or two while the database is set up.
Step 6: First sign-in
Open the instance URL in your browser while signed in to OSC and click "Get Started". Ghostfolio creates an anonymous account and shows a security token once. Save it in your password manager, you use it to sign in later.
The first account created on a fresh instance gets the admin role, so create your own account right after the instance starts.
Configuration
| Setting | Required | Description |
|---|---|---|
| DatabaseUrl | Yes (sensitive) | postgresql://postgres:<password>@<postgres-internal-dns>:5432/ghostfolio |
| RedisHost | Yes | Valkey internal address |
| RedisPort | No | Valkey port, default 6379 |
| RedisPassword | No (sensitive) | Valkey password, empty if none |
| AccessTokenSalt | Yes (sensitive) | Long random string. Must stay the same across restarts |
| JwtSecretKey | Yes (sensitive) | Long random string. Keep it secret |
All data lives in PostgreSQL. The default market data source is Yahoo Finance, which needs no key. Other data provider API keys and optional features are not exposed as options.
Limitations
- Behind the OSC sign-in only. The OSC sign-in protects every path except
/, which redirects to a protected page. The whole UI and the API require an OSC sign-in, so apps outside OSC cannot reach the API. In the first minute or two after creating an instance, some requests can get an odd 404 before the access rules settle. Wait and retry. - Keep the
AccessTokenSalt. Changing it makes existing security tokens stop working and locks users out. - The first account created is the admin, so sign up immediately after creating the instance.
- No backup is configured. Back up the PostgreSQL instance, it holds all your portfolio data.
- Personal finance data is sensitive. Protect your OSC account.
- Not tested: importing activities, data providers, OIDC or Google sign-in, a Valkey password, TLS to PostgreSQL, and upgrades.