# Memos

> Install Memos from the App Store, create the administrator behind the setup lock, close sign-ups, back up the notes database and keep Memos up to date.

Source: https://zopanel.net/docs/app-memos  
Updated: 2026-10-09

Memos is a lightweight, self-hosted note-taking app: short notes, to-dos and a daily log written in Markdown, with tags, search and file attachments, usable from a phone or desktop browser. Choose it when you want a private alternative to Google Keep or Flomo for yourself, a family or a small team, with the notes stored on your own server.

## Requirements

| Item | Value |
| --- | --- |
| Image | `neosmemo/memos:0.31` |
| Memory limit | 256 MB, 1 CPU |
| Free disk to install | About 1.1 GB on the Docker disk (the image plus 1 GB kept free for the server) |
| Database | SQLite, inside the app's data folder |
| Docker | Installed by the administrator (**App Store → Install Docker**) |

The new website counts toward the account's website limit. As a customer, your package must allow Docker apps and have 256 MB of **RAM (MB)** left for the app. See [App Store and S3 storage](/docs/apps).

## Install Memos

### As the administrator

1. Point the domain's A record (for example `notes.example.com`) to the server. SSL can only be issued once DNS resolves.
2. Open **App Store** and click **Install** on the **Memos** card.
3. Fill in the fields (table below) and click **Install**. The task log shows the image download and the container start.
4. When the task finishes, open the new website and go to its **Docker** tab.

### As a customer

Open **App Store** from the menu. The card at the top shows your quota, for example "Your plan: 0 of 2 applications · memory 0 of 2048 MB." If it says "Applications are not included in your plan. Ask your provider to enable them.", your package has **Docker apps** set to `0`. Otherwise the steps are the same as above, without the **Owner** field: the app always belongs to your own account.

### Install fields

| Field | What to enter |
| --- | --- |
| **Domain** | The domain or subdomain for Memos, without `http://`. It must not already be used by another website. |
| **Owner** | Administrators only: the hosting account that owns the website and the app. |
| **Free SSL (Let's Encrypt)** | On by default. The certificate is requested after the container starts. If DNS does not point to the server yet, the log says "SSL could not be issued yet" and you can issue it later on the **SSL** tab. |

Memos has no extra install fields. ZoPanel does not set any Memos environment variables; everything is configured inside the app.

## Finish the setup behind the setup lock

In Memos, the first account created becomes the administrator. To stop a stranger from claiming it first, ZoPanel locks every new Memos install: visitors see "This app is being set up" until you open it.

1. On the website's **Docker** tab, the **Setup lock is on** card is shown. Click **Open the app (only for me)**. This sets a cookie in your browser (valid 30 days) and opens Memos.
2. Create your account on the first screen (user name and password). This account is the instance administrator (Memos calls it the host).
3. Close sign-ups if the notes are only for you or a fixed group (next section).
4. Go back to the **Docker** tab and click **Setup finished — open to everyone**. The message "The app is now open to everyone" confirms it.

**Important:** Do not skip step 4 if other people or your phone's browser need to reach Memos: until you click it, only a browser holding the setup cookie gets through.

## Essential settings in Memos

Open the settings from the sidebar while signed in as the administrator.

- **User registration.** By default anyone who can reach the site can create an account. Turn on **Disallow user registration** in the administrator's system settings, then create accounts for other people yourself from the members settings. Menu names can change between Memos releases; check the [Memos documentation](https://usememos.com/docs) if you do not find it.
- **Access for visitors.** Memos 0.31 has an instance access setting that decides what visitors who are not signed in can see, separately from each memo's visibility (private, protected, public). Review it before you share public memos.
- **Attachment storage.** In the storage settings, attachments can be kept in the database, on the local file system, or in S3-compatible storage. Database and local storage both live in the app's data folder on the server, so the backup below covers them.

To keep attachments in a ZoPanel bucket instead, publish S3 storage on a domain first (see [App Store and S3 storage](/docs/apps)). The container reaches that domain over HTTPS on port 443; it cannot reach the S3 API on 127.0.0.1.

## Data and backups

| What | Where on the server |
| --- | --- |
| Database (`memos_prod.db`) and local attachments | `/var/lib/zopanel-apps/<instance>/data/` (mounted at `/var/opt/memos` in the container) |
| Environment file (root only) | `/var/lib/zopanel-apps/<instance>/.env` |
| Container name | `zp-app-<instance>` |

`<instance>` is the domain with dots replaced by hyphens: `notes.example.com` becomes `notes-example-com`.

**ZoPanel's account backups do not include this folder.** Full account backups and incremental (restic) snapshots cover the account's website folders under `/home`, its databases and its mail. App data lives in `/var/lib/zopanel-apps`, outside the account, so it is not in those backups, does not appear in the File Manager and does not count toward the account's disk quota. It is backed up by the **Backups** card on the website's **Docker** tab instead. The configuration backup (`.zpb`) restores the app's record in the panel, not its notes.

To back up Memos, click **Back up now** on the **Backups** card of the website's **Docker** tab. Administrators can also set a **Schedule** (**Off**, **Every day** or **Every week**; off by default) and how many copies to **Keep** (1–60, default 7), then click **Save**. Each backup archives `/var/lib/zopanel-apps/<instance>/` into `/var/backups/zopanel-apps/<instance>/YYYYMMDD-HHMMSS.tar.gz`, a folder only root can read that does not count toward the account's disk quota. The container is paused (not stopped) for the few seconds of the copy, so the SQLite database is consistent. Older copies beyond **Keep** are removed, and a failed scheduled backup sends administrators the **Backup failed** alert.

To restore, an administrator clicks **Restore** next to a backup. Memos is stopped and its data replaced with the archive; the current data is kept aside until the restored app starts, and put back if it does not. Changes made since the backup are lost. Each backup also has a delete button (administrators only), and deleting the app together with its files deletes its backups too. Customers can click **Back up now** and see the list; the schedule and restores are done by the provider.

The archives stay on the same server. Copy important ones off it (for example with `scp` or `rclone` from `/var/backups/zopanel-apps/<instance>/`) and store them encrypted, since they contain your notes and the `.env` file. To restore on another server, install Memos on the same domain there, copy the archive into `/var/backups/zopanel-apps/<instance>/` on the new server and click **Restore** on its **Backups** card. Docker runs containers in a separate user-ID range (`userns-remap`), so this works only if both servers use the same `dockremap` range; compare `grep dockremap /etc/subuid` on both.

Customers can also use Memos' own export features for important notes.

## Update Memos

Administrators click **Update to latest** on the **Docker** tab. ZoPanel pulls the image again, recreates the container with the same settings and keeps the data folder. The image tag `0.31` follows bug-fix releases of the 0.31 line; a newer line arrives when a ZoPanel update moves the catalog to it.

Memos migrates its database on start and does not support going back to an older version afterwards. Make a backup (**Back up now**) before each update. Customers do not see the update button: ask your provider to update the app.

## Network limits

Every App Store container is cut off from the server's internal network. For Memos this means:

- Webhooks and links to private addresses (`10.x`, `172.16–31.x`, `192.168.x`, `127.x`, the cloud metadata address `169.254.169.254`) are refused. Webhooks to public HTTPS endpoints work.
- On the server itself, the container reaches only ports 80, 443, 25, 465, 587 and DNS, never the panel, MySQL/MariaDB, PostgreSQL or Redis.
- Single sign-on (OAuth/OIDC) providers on the internet work, because they are public addresses.

## Troubleshooting

| Symptom or message | What to do |
| --- | --- |
| "This app is being set up" | The setup lock is still on. Click **Open the app (only for me)** in the same browser, or **Setup finished — open to everyone**. |
| "This website is very busy right now" | Memos is starting or restarting. The page reloads by itself; check **Application output** on the **Docker** tab if it persists. |
| "not enough disk space: this app needs about 1.1 GB free…" | Free space on the server's Docker disk, then install again. |
| "your plan allows 1 application(s)" / "Memos needs 256 MB of memory; your plan has…" | The package limit is reached. Remove another app or ask for a larger package. |
| "the app did not start listening: …" | The container did not open its port within 2 minutes. The message ends with the last log lines; read them, then click **Restart**. |
| Someone else's account appears | Sign-ups are open. Delete the account in Memos' member settings and turn on **Disallow user registration**. |
| Notes lost after deleting the website | Deleting a website with **Also delete all files** ticked also deletes `/var/lib/zopanel-apps/<instance>` and the app's backups. Restore from a copy you kept off the server. |

## Related

- [App Store and S3 storage](/docs/apps)
- [What each app does](/docs/app-catalog)
- [Packages and limits](/docs/packages-limits)
- [Backups](/docs/backups)
- [Memos documentation](https://usememos.com/docs)
