> ## Documentation Index
> Fetch the complete documentation index at: https://www.towbar.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Matomo

> Matomo tracks website and app usage through visitor reports and goals.

export const UseCaseNavigation = () => {
  useLayoutEffect(() => {
    const storageKey = "towbar-use-case-open-groups";
    const groupSelector = "#sidebar li[data-title] > button[aria-expanded]";
    let restoring = false;
    let frame = 0;
    function storedGroups() {
      try {
        return new Set(JSON.parse(sessionStorage.getItem(storageKey) || "[]"));
      } catch {
        return new Set();
      }
    }
    function save(groups) {
      try {
        sessionStorage.setItem(storageKey, JSON.stringify([...groups]));
      } catch {}
    }
    function groupName(button) {
      return button.parentElement?.dataset.title;
    }
    function rememberOpenGroups() {
      const groups = new Set();
      for (const button of document.querySelectorAll(groupSelector)) {
        if (button.getAttribute("aria-expanded") === "true") {
          const name = groupName(button);
          if (name) groups.add(name);
        }
      }
      save(groups);
    }
    function restoreOpenGroups() {
      frame = 0;
      const groups = storedGroups();
      if (!groups.size) return;
      restoring = true;
      for (const button of document.querySelectorAll(groupSelector)) {
        if (groups.has(groupName(button)) && button.getAttribute("aria-expanded") === "false") {
          button.click();
        }
      }
      restoring = false;
    }
    function scheduleRestore() {
      if (!frame) frame = requestAnimationFrame(restoreOpenGroups);
    }
    function onClick(event) {
      if (restoring || !(event.target instanceof Element)) return;
      const button = event.target.closest(groupSelector);
      if (button) {
        const name = groupName(button);
        if (!name) return;
        const groups = storedGroups();
        if (button.getAttribute("aria-expanded") === "true") groups.delete(name); else groups.add(name);
        save(groups);
        return;
      }
      if (event.target.closest('a[href^="/docs/use-cases/"]')) {
        rememberOpenGroups();
      }
    }
    const observer = new MutationObserver(scheduleRestore);
    document.addEventListener("click", onClick, true);
    observer.observe(document.getElementById("sidebar") || document.body, {
      childList: true,
      subtree: true
    });
    scheduleRestore();
    return () => {
      document.removeEventListener("click", onClick, true);
      observer.disconnect();
      cancelAnimationFrame(frame);
    };
  }, []);
  return null;
};

<UseCaseNavigation />

<img className="towbar-doc-brand-logo" src="https://mintcdn.com/avgeek/EGkEWLTQnOwecqNx/assets/use-case-logos/matomo.svg?fit=max&auto=format&n=EGkEWLTQnOwecqNx&q=85&s=ccf4d7b812af6271da9a4e4226fec281" alt="Matomo logo" aria-hidden="true" width="24" height="24" data-path="assets/use-case-logos/matomo.svg" />

**Upstream source:** [Current installation guide](https://matomo.org/faq/how-to-install/install-matomo-with-docker/).

Matomo needs MariaDB/MySQL for site and reporting data. The Service volume preserves its configuration, plugins, and uploaded assets. Add a scheduled archive task after the first site is working; relying only on browser-triggered archiving is not a long-term plan.

## Towbar manifests

<CodeGroup>
  ```yaml title=".towbar/datastores/matomo-mariadb.datastore.yml" theme={"system"}
  id: matomo-mariadb
  name: Matomo MariaDB
  type: mariadb
  container:
    network: application
    networkAlias: matomo-mariadb
    resources:
      cpus: 1
      memory: 1g
  secrets:
    runtime:
      - MYSQL_ROOT_PASSWORD
      - MYSQL_DATABASE
      - MYSQL_USER
      - MYSQL_PASSWORD
  environments:
    production:
      server: 192.0.2.10
  ```

  ```yaml title=".towbar/services/matomo.service.yml" theme={"system"}
  id: matomo
  name: Matomo
  buildServer: null
  deployment:
    type: image
    image: matomo:5.5.0-apache
  container:
    port: 80
    network: application
    volumes:
      - name: html
        mountPath: /var/www/html
        initialData: image
  environments:
    production:
      server: 192.0.2.10
  rollout:
    type: recreate
    maintenanceMode: true
    reason: Persistent application data uses a single writer
  secrets:
    runtime:
      - MATOMO_DATABASE_HOST
      - MATOMO_DATABASE_DBNAME
      - MATOMO_DATABASE_USERNAME
      - MATOMO_DATABASE_PASSWORD
  domains:
    primary: matomo.example.com
  tls:
    mode: direct
  ```
</CodeGroup>

## Configure

1. Prepare the example server, connect the repository, and map `production` to the branch containing these manifests. Replace the example server IP and domain. Commit the manifests, then sync the repository and inspect the resolved configuration.
2. Save the initialization values in the table below for the mariadb Datastore under **Datastore → Settings → Secrets**. Deploy it first and wait for readiness. These values create the database and user only on an empty volume.
3. Set the Service's declared runtime values under **Service → Settings → Secrets** using the table below. Replace descriptions and placeholders with actual values; do not commit passwords or keys.
4. Keep the Service's named volumes attached across deployments. Towbar's Datastore backup policy does not back up Service volumes, so include them in your own recovery plan.
5. Deploy the Service, then perform the checks below before enabling auto-deploy.

## Datastore values

Save these in each Datastore's **Settings → Secrets** before deploying it. Use the suggested names or choose your own, then use the same names and passwords in the Service connection values below.

| Datastore      | Key                   | Suggested value                                                                           |
| -------------- | --------------------- | ----------------------------------------------------------------------------------------- |
| Matomo mariadb | `MYSQL_DATABASE`      | matomo                                                                                    |
| Matomo mariadb | `MYSQL_USER`          | matomo                                                                                    |
| Matomo mariadb | `MYSQL_PASSWORD`      | Run `openssl rand -hex 32`; save its output and reuse it in the Service connection value. |
| Matomo mariadb | `MYSQL_ROOT_PASSWORD` | Run `openssl rand -hex 32` again for a separate root password.                            |

## Runtime values

Save these values on the Service after the repository sync. The manifest declares required keys, not their values.

| Key                        | Value to save                  |
| -------------------------- | ------------------------------ |
| `MATOMO_DATABASE_HOST`     | matomo-mariadb                 |
| `MATOMO_DATABASE_DBNAME`   | Same value as MYSQL\_DATABASE. |
| `MATOMO_DATABASE_USERNAME` | Same value as MYSQL\_USER.     |
| `MATOMO_DATABASE_PASSWORD` | Same value as MYSQL\_PASSWORD. |

## Verify

Complete the installer, add a site, and verify its tracking request appears. Set up Matomo's `core:archive` schedule before collecting regular traffic.

For field constraints, see [Service manifest](/docs/services/manifest) and [Datastore manifest](/docs/datastores/manifest).
