03-kiwix.md
kstack: book: Centerpoint Home Lab chapter: Utilities page: Kiwix tags: [kiwix, offline, wikipedia, zim, authentik]
Overview
Kiwix serves offline ZIM-format content — primarily Wikipedia snapshots and other reference material — accessible without an internet connection. ZIM files are stored on the Ceph OSD volume. The external route is gated behind Authentik ForwardAuth. The internal route has no additional auth middleware.
Access
| Type | URL | Auth |
|---|---|---|
| External | https://kiwix.jeeves5454.ddns.net |
Authentik ForwardAuth + GeoBlock + CrowdSec |
| Internal | https://kiwix.home.local |
No additional auth (Step-CA TLS) |
Configuration
Image: ghcr.io/kiwix/kiwix-serve:latest
Traefik Labels
traefik.http.routers.kiwix-external.rule: Host(`kiwix.jeeves5454.ddns.net`)
traefik.http.routers.kiwix-external.entrypoints: websecure
traefik.http.routers.kiwix-external.tls.certresolver: letsencrypt
traefik.http.routers.kiwix-external.middlewares: plex-geoblock@file,crowdsec-bouncer@file,authentik-auth@docker
traefik.http.routers.kiwix-external.service: kiwix-svc
traefik.http.routers.kiwix-internal.rule: Host(`kiwix.home.local`)
traefik.http.routers.kiwix-internal.entrypoints: websecure
traefik.http.routers.kiwix-internal.tls.certresolver: step-ca
traefik.http.routers.kiwix-internal.service: kiwix-svc
traefik.http.services.kiwix-svc.loadbalancer.server.port: 8080
Volumes / Bind Mounts
| Host Path | Container Path | Purpose |
|---|---|---|
/media/jeeves/1TB_Vol1/Kiwix_Images |
/data |
ZIM content files |
ZIM files are stored on the second Ceph OSD volume (nvme2n1,
/media/jeeves/1TB_Vol1). kiwix-serve auto-discovers all .zim files in
/data on startup and presents them in the library UI.
Notes / Gotchas
- ZIM files can be very large (Wikipedia full English is ~100GB). Ensure adequate space on the Ceph volume before downloading new content.
- New ZIM files can be added by placing them in
/media/jeeves/1TB_Vol1/Kiwix_Images. A container restart is required for kiwix-serve to discover them. - Kiwix has no built-in authentication — the internal route is unprotected on the LAN. The external route relies entirely on Authentik ForwardAuth.
- ZIM files can be downloaded from
library.kiwix.organd transferred to the Ceph volume via FileBrowser or SCP.
Last Updated: 2026-06-17
No comments to display
No comments to display