> ## Documentation Index
> Fetch the complete documentation index at: https://www.towbar.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Umami

> Umami is a privacy-focused website analytics tool for tracking visits, pages, and events.

export const UseCaseNavigation = () => {
  useLayoutEffect(() => {
    const storageKey = "towbar-use-case-open-groups";
    const groupSelector = "#sidebar li[data-title] > button[aria-expanded]";
    let restoring = false;
    let frame = 0;
    function storedGroups() {
      try {
        return new Set(JSON.parse(sessionStorage.getItem(storageKey) || "[]"));
      } catch {
        return new Set();
      }
    }
    function save(groups) {
      try {
        sessionStorage.setItem(storageKey, JSON.stringify([...groups]));
      } catch {}
    }
    function groupName(button) {
      return button.parentElement?.dataset.title;
    }
    function rememberOpenGroups() {
      const groups = new Set();
      for (const button of document.querySelectorAll(groupSelector)) {
        if (button.getAttribute("aria-expanded") === "true") {
          const name = groupName(button);
          if (name) groups.add(name);
        }
      }
      save(groups);
    }
    function restoreOpenGroups() {
      frame = 0;
      const groups = storedGroups();
      if (!groups.size) return;
      restoring = true;
      for (const button of document.querySelectorAll(groupSelector)) {
        if (groups.has(groupName(button)) && button.getAttribute("aria-expanded") === "false") {
          button.click();
        }
      }
      restoring = false;
    }
    function scheduleRestore() {
      if (!frame) frame = requestAnimationFrame(restoreOpenGroups);
    }
    function onClick(event) {
      if (restoring || !(event.target instanceof Element)) return;
      const button = event.target.closest(groupSelector);
      if (button) {
        const name = groupName(button);
        if (!name) return;
        const groups = storedGroups();
        if (button.getAttribute("aria-expanded") === "true") groups.delete(name); else groups.add(name);
        save(groups);
        return;
      }
      if (event.target.closest('a[href^="/docs/use-cases/"]')) {
        rememberOpenGroups();
      }
    }
    const observer = new MutationObserver(scheduleRestore);
    document.addEventListener("click", onClick, true);
    observer.observe(document.getElementById("sidebar") || document.body, {
      childList: true,
      subtree: true
    });
    scheduleRestore();
    return () => {
      document.removeEventListener("click", onClick, true);
      observer.disconnect();
      cancelAnimationFrame(frame);
    };
  }, []);
  return null;
};

<UseCaseNavigation />

<img className="towbar-doc-brand-logo" src="https://mintcdn.com/avgeek/Wq-9tmR7jDSzqtpH/assets/use-case-logos/umami.svg?fit=max&auto=format&n=Wq-9tmR7jDSzqtpH&q=85&s=1414f37a5c075c5ce427da04879a8c10" alt="Umami logo" aria-hidden="true" width="24" height="24" data-path="assets/use-case-logos/umami.svg" />

**Upstream source:** [Current installation guide](https://docs.umami.is/docs/install).

Umami needs PostgreSQL for accounts, websites, and analytics events. Deploy its Datastore first, then save a connection URL on the Umami Service; Towbar does not copy database credentials between them.

## Towbar manifests

<CodeGroup>
  ```yaml title=".towbar/datastores/umami-postgres.datastore.yml" theme={"system"}
  id: umami-postgres
  name: Umami PostgreSQL
  type: postgres
  container:
    network: application
    networkAlias: umami-postgres
    resources:
      cpus: 1
      memory: 1g
  secrets:
    runtime:
      - POSTGRES_USER
      - POSTGRES_DB
      - POSTGRES_PASSWORD
  environments:
    production:
      server: 192.0.2.10
  ```

  ```yaml title=".towbar/services/umami.service.yml" theme={"system"}
  id: umami
  name: Umami
  buildServer: null
  deployment:
    type: image
    image: ghcr.io/umami-software/umami:3.4@sha256:6cd9d24a836fac5c226c3c90cb25141d4560b7270b7827f393ccf09bf3f83b18
  container:
    port: 3000
    network: application
  environments:
    production:
      server: 192.0.2.10
  secrets:
    runtime:
      - DATABASE_URL
  domains:
    primary: umami.example.com
  tls:
    mode: direct
  ```
</CodeGroup>

## Configure

1. Prepare the example server, connect the repository, and map `production` to the branch containing these manifests. Replace the example server IP and domain. Commit the manifests, then sync the repository and inspect the resolved configuration.
2. Save the initialization values in the table below for the postgres Datastore under **Datastore → Settings → Secrets**. Deploy it first and wait for readiness. These values create the database and user only on an empty volume.
3. Set the Service's declared runtime values under **Service → Settings → Secrets** using the table below. Replace descriptions and placeholders with actual values; do not commit passwords or keys.
4. Deploy the Service, then perform the checks below before enabling auto-deploy.

## Datastore values

Save these in each Datastore's **Settings → Secrets** before deploying it. Use the suggested names or choose your own, then use the same names and passwords in the Service connection values below.

| Datastore      | Key                 | Suggested value                                                                           |
| -------------- | ------------------- | ----------------------------------------------------------------------------------------- |
| Umami postgres | `POSTGRES_DB`       | umami                                                                                     |
| Umami postgres | `POSTGRES_USER`     | umami                                                                                     |
| Umami postgres | `POSTGRES_PASSWORD` | Run `openssl rand -hex 32`; save its output and reuse it in the Service connection value. |

## Runtime values

Save these values on the Service after the repository sync. The manifest declares required keys, not their values.

| Key            | Value to save                                                                                         |
| -------------- | ----------------------------------------------------------------------------------------------------- |
| `DATABASE_URL` | `postgresql://umami:PASSWORD@umami-postgres:5432/umami` (replace `PASSWORD` with `POSTGRES_PASSWORD`) |

## Verify

Sign in, change the default administrator password, add a site, and verify a test visit appears. Redeploy Umami and confirm the site and visit remain.

For field constraints, see [Service manifest](/docs/services/manifest) and [Datastore manifest](/docs/datastores/manifest).
