Self-host Kimai with Docker Compose
Zeiterfassung und Rechnungsstellung für Freelancer, Projektteams und Agenturen.
kimai
mysql
mariadb:12.2.2-noble
mysql-mysql-data-init
busybox
mysql-mysql-socket-init
busybox
mysql-mysql-tmp-init
busybox
The steps below take a few minutes end to end.
Requirements
You'll need these installed on the machine you're deploying to:
Docker
Packages Kimai and everything it depends on into an isolated container, so it runs the same way on your machine as it does everywhere else.
Install guideDocker Compose
Reads docker-compose.ymland starts everything in it together. Ships with Docker Desktop. On Linux servers it's usually a separate install.
Install guide1. Docker compose setup and file
Create a folder for Kimai and save the file below into it as docker-compose.yml. It describes every container the stack needs — Kimaiitself and any supporting services, such as its database — along with the ports, volumes and environment variables each one uses. You'll also need an empty .env file in the same folder; Docker Compose reads it automatically and uses it to fill in the ${VARIABLE}references you'll see in the file below.
docker-compose.yml
version: "3.9"
services:
kimai:
image: kimai/kimai2:apache
restart: unless-stopped
ports:
- 8001:8001
environment:
ADMINMAIL: admin@example.com
ADMINPASS: admin123
APP_SECRET: ${RANDOM_APP_SECRET}
DATABASE_URL: mysql://app:${RANDOM_MYSQL_PASSWORD}@127.0.0.1:3306/app
RANDOM_MYSQL_PASSWORD: ${RANDOM_MYSQL_PASSWORD}
TRUSTED_HOSTS: localhost
TRUSTED_PROXIES: REMOTE_ADDR
volumes:
- data:/opt/kimai/var/data
- cache:/opt/kimai/var/cache
- kimai-log:/opt/kimai/var/log
- apache-run:/var/run/apache2
- apache-log:/var/log/apache2
- apache-lock:/var/lock/apache2
- tmp:/tmp
healthcheck:
test:
- CMD
- curl
- -f
- http://localhost:8001/
interval: 10s
timeout: 5s
retries: 5
mysql:
image: mariadb:12.2.2-noble
restart: unless-stopped
network_mode: service:kimai
environment:
MARIADB_DATABASE: app
MARIADB_PASSWORD: ${RANDOM_MYSQL_PASSWORD}
MARIADB_ROOT_PASSWORD: ${RANDOM_MYSQL_ROOT_PASSWORD}
MARIADB_USER: app
volumes:
- mysql-data:/var/lib/mysql
- mysql-tmp:/tmp
- mysql-socket:/run/mysqld
depends_on:
mysql-mysql-data-init:
condition: service_completed_successfully
mysql-mysql-socket-init:
condition: service_completed_successfully
mysql-mysql-tmp-init:
condition: service_completed_successfully
mysql-mysql-data-init:
image: busybox
volumes:
- mysql-data:/var/lib/mysql
command:
- chown
- 999:999
- /var/lib/mysql
mysql-mysql-socket-init:
image: busybox
volumes:
- mysql-socket:/run/mysqld
command:
- chown
- 999:999
- /run/mysqld
mysql-mysql-tmp-init:
image: busybox
volumes:
- mysql-tmp:/tmp
command:
- chown
- 999:999
- /tmp
volumes:
apache-lock: null
apache-log: null
apache-run: null
cache: null
data: null
kimai-log: null
mysql-data: null
mysql-socket: null
mysql-tmp: null
tmp: null
Volumes
Kimai stores its data in named Docker volumes, so it survives container restarts and updates:
- data mounted at /opt/kimai/var/data: Kimai's persistent app data, including the application secret (.appsecret) it generates on first run.
- cache mounted at /opt/kimai/var/cache: Kimai's compiled Symfony application cache, rebuilt at startup.
- kimai-log mounted at /opt/kimai/var/log: Kimai's runtime application log files.
- apache-run mounted at /var/run/apache2: Runtime directory for Apache's pid file.
- apache-log mounted at /var/log/apache2: Apache's access and error log files.
- apache-lock mounted at /var/lock/apache2: Apache's runtime mutex lock files.
- tmp mounted at /tmp: Temporary working files and PHP session storage.
2. Secret generation
Kimai needs a few randomly generated secrets — for example, database passwords or an internal session key — before it can start. These are referenced from docker-compose.ymlabove but don't live in it, so they need to end up in your .env file. Pick one of the two options below.
Generating secrets…
3. Start Kimai with Docker Compose
From the folder with docker-compose.yml and .env, run:
Terminal
Start Kimai and all its supporting services in the background.
docker compose up -dThe -d flag runs the stack in the background so it keeps running after you close the terminal. Docker will pull the images the first time, which can take a minute or two.
To check on it afterwards: docker compose ps shows whether containers are healthy, and docker compose logs -f follows their logs if something looks wrong. Once it's running, open http://localhost:8001 in your browser.