> ## Documentation Index
> Fetch the complete documentation index at: https://www.towbar.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# HedgeDoc

> HedgeDoc lets people write and edit Markdown notes together in real time.

export const UseCaseNavigation = () => {
  useLayoutEffect(() => {
    const storageKey = "towbar-use-case-open-groups";
    const groupSelector = "#sidebar li[data-title] > button[aria-expanded]";
    let restoring = false;
    let frame = 0;
    function storedGroups() {
      try {
        return new Set(JSON.parse(sessionStorage.getItem(storageKey) || "[]"));
      } catch {
        return new Set();
      }
    }
    function save(groups) {
      try {
        sessionStorage.setItem(storageKey, JSON.stringify([...groups]));
      } catch {}
    }
    function groupName(button) {
      return button.parentElement?.dataset.title;
    }
    function rememberOpenGroups() {
      const groups = new Set();
      for (const button of document.querySelectorAll(groupSelector)) {
        if (button.getAttribute("aria-expanded") === "true") {
          const name = groupName(button);
          if (name) groups.add(name);
        }
      }
      save(groups);
    }
    function restoreOpenGroups() {
      frame = 0;
      const groups = storedGroups();
      if (!groups.size) return;
      restoring = true;
      for (const button of document.querySelectorAll(groupSelector)) {
        if (groups.has(groupName(button)) && button.getAttribute("aria-expanded") === "false") {
          button.click();
        }
      }
      restoring = false;
    }
    function scheduleRestore() {
      if (!frame) frame = requestAnimationFrame(restoreOpenGroups);
    }
    function onClick(event) {
      if (restoring || !(event.target instanceof Element)) return;
      const button = event.target.closest(groupSelector);
      if (button) {
        const name = groupName(button);
        if (!name) return;
        const groups = storedGroups();
        if (button.getAttribute("aria-expanded") === "true") groups.delete(name); else groups.add(name);
        save(groups);
        return;
      }
      if (event.target.closest('a[href^="/docs/use-cases/"]')) {
        rememberOpenGroups();
      }
    }
    const observer = new MutationObserver(scheduleRestore);
    document.addEventListener("click", onClick, true);
    observer.observe(document.getElementById("sidebar") || document.body, {
      childList: true,
      subtree: true
    });
    scheduleRestore();
    return () => {
      document.removeEventListener("click", onClick, true);
      observer.disconnect();
      cancelAnimationFrame(frame);
    };
  }, []);
  return null;
};

<UseCaseNavigation />

<img className="towbar-doc-brand-logo" src="https://mintcdn.com/avgeek/EGkEWLTQnOwecqNx/assets/use-case-logos/hedgedoc.svg?fit=max&auto=format&n=EGkEWLTQnOwecqNx&q=85&s=eaa9891b1a4951b56ac93b2cc6742f65" alt="HedgeDoc logo" aria-hidden="true" width="24" height="24" data-path="assets/use-case-logos/hedgedoc.svg" />

**Upstream source:** [Current installation guide](https://docs.hedgedoc.org/setup/docker/).

PostgreSQL holds notes and accounts; the Service volume preserves uploaded assets. Both must be backed up.

## Towbar manifests

<CodeGroup>
  ```yaml title=".towbar/datastores/hedgedoc-postgres.datastore.yml" theme={"system"}
  id: hedgedoc-postgres
  name: HedgeDoc PostgreSQL
  type: postgres
  container:
    network: application
    networkAlias: hedgedoc-postgres
    resources:
      cpus: 1
      memory: 1g
  secrets:
    runtime:
      - POSTGRES_USER
      - POSTGRES_DB
      - POSTGRES_PASSWORD
  environments:
    production:
      server: 192.0.2.10
  ```

  ```yaml title=".towbar/services/hedgedoc.service.yml" theme={"system"}
  id: hedgedoc
  name: HedgeDoc
  buildServer: null
  deployment:
    type: image
    image: quay.io/hedgedoc/hedgedoc:1.12.0
  container:
    port: 3000
    network: application
    volumes:
      - name: uploads
        mountPath: /hedgedoc/public/uploads
        initialData: image
  environments:
    production:
      server: 192.0.2.10
  rollout:
    type: recreate
    maintenanceMode: true
    reason: Persistent application data uses a single writer
  secrets:
    runtime:
      - CMD_DB_URL
      - CMD_DOMAIN
      - CMD_PROTOCOL_USESSL
  domains:
    primary: hedgedoc.example.com
  tls:
    mode: direct
  ```
</CodeGroup>

## Configure

1. Prepare the example server, connect the repository, and map `production` to the branch containing these manifests. Replace the example server IP and domain. Commit the manifests, then sync the repository and inspect the resolved configuration.
2. Save the initialization values in the table below for the postgres Datastore under **Datastore → Settings → Secrets**. Deploy it first and wait for readiness. These values create the database and user only on an empty volume.
3. Set the Service's declared runtime values under **Service → Settings → Secrets** using the table below. Replace descriptions and placeholders with actual values; do not commit passwords or keys.
4. Keep the Service's named volumes attached across deployments. Towbar's Datastore backup policy does not back up Service volumes, so include them in your own recovery plan.
5. Deploy the Service, then perform the checks below before enabling auto-deploy.

## Datastore values

Save these in each Datastore's **Settings → Secrets** before deploying it. Use the suggested names or choose your own, then use the same names and passwords in the Service connection values below.

| Datastore         | Key                 | Suggested value                                                                           |
| ----------------- | ------------------- | ----------------------------------------------------------------------------------------- |
| HedgeDoc postgres | `POSTGRES_DB`       | hedgedoc                                                                                  |
| HedgeDoc postgres | `POSTGRES_USER`     | hedgedoc                                                                                  |
| HedgeDoc postgres | `POSTGRES_PASSWORD` | Run `openssl rand -hex 32`; save its output and reuse it in the Service connection value. |

## Runtime values

Save these values on the Service after the repository sync. The manifest declares required keys, not their values.

| Key                   | Value to save                                                                                                |
| --------------------- | ------------------------------------------------------------------------------------------------------------ |
| `CMD_DB_URL`          | `postgres://hedgedoc:PASSWORD@hedgedoc-postgres:5432/hedgedoc` (replace `PASSWORD` with `POSTGRES_PASSWORD`) |
| `CMD_DOMAIN`          | hedgedoc.example.com                                                                                         |
| `CMD_PROTOCOL_USESSL` | true                                                                                                         |

## Verify

Create a note and upload an image, then verify both survive a redeploy.

For field constraints, see [Service manifest](/docs/services/manifest) and [Datastore manifest](/docs/datastores/manifest).
