04-drawio.md
kstack: book: Centerpoint Home Lab chapter: Utilities page: Draw.io tags: [drawio, diagrams, productivity]
Overview
Draw.io (now diagrams.net) is a self-hosted diagramming application for creating network diagrams, flowcharts, architecture diagrams, and more. This instance is stateless — diagrams are saved locally by the browser or to connected storage (Google Drive, OneDrive, etc.), not on the server. External-only access with GeoBlock and CrowdSec.
Access
| Type | URL | Auth |
|---|---|---|
| External | https://drawio.jeeves5454.ddns.net |
GeoBlock + CrowdSec (no auth) |
No authentication middleware — Draw.io is accessible to anyone who bypasses GeoBlock. The app itself has no user accounts.
Configuration
Image: jgraph/drawio:latest
Runtime: Java 11 / Apache Tomcat
Key Environment Variables
| Variable | Value / Notes |
|---|---|
DRAWIO_BASE_URL |
https://drawio.jeeves5454.ddns.net |
PUBLIC_DNS |
drawio.jeeves5454.ddns.net |
DRAWIO_GOOGLE_CLIENT_ID |
jeeves5454@gmail.com (Google integration) |
LETS_ENCRYPT_ENABLED |
false (TLS handled by Traefik) |
Traefik Labels
traefik.http.routers.drawio.rule: Host(`drawio.jeeves5454.ddns.net`)
traefik.http.routers.drawio.entrypoints: websecure
traefik.http.routers.drawio.tls.certresolver: letsencrypt
traefik.http.routers.drawio.middlewares: plex-geoblock@file,crowdsec-bouncer@file,drawio-headers
traefik.http.middlewares.drawio-headers.headers.customrequestheaders.X-Forwarded-Proto: https
traefik.http.services.drawio.loadbalancer.server.port: 8080
Volumes / Bind Mounts
None — Draw.io is completely stateless. All diagram data is stored client-side (browser localStorage or connected cloud storage).
Notes / Gotchas
LETS_ENCRYPT_ENABLED=falseis correct — Traefik handles TLS termination. The Draw.io container itself serves plain HTTP on port 8080.- The
X-Forwarded-Proto: httpsheader is required so Draw.io generates correct HTTPS URLs for embedded resources and exports. - Diagrams are not stored on the server. To preserve diagrams, save them to a
local file (
.drawio/.xml) or configure a cloud storage backend in the Draw.io UI. DRAWIO_GOOGLE_CLIENT_IDenables the Google Drive integration in the file picker. Users must authorise their own Google account in the app.
Last Updated: 2026-06-17
No comments to display
No comments to display