Back to articles
Technology Insight

Self-Hosting Trilium Notes: A Guide to Secure, End-to-End Encrypted Synchronization on Linux VPS

June 3, 2026

Introduction to Self-Hosted Knowledge Management

In the digital age, data sovereignty has become a paramount concern for professionals, developers, and businesses alike. While commercial note-taking applications offer convenience, they often compromise on privacy, locking your intellectual capital within proprietary ecosystems. Trilium Notes emerges as a powerful, open-source alternative designed for power users who require a hierarchical, highly customizable, and secure knowledge base.

By self-hosting Trilium Notes on a Linux Virtual Private Server (VPS), you establish a centralized hub for your documentation. However, the true utility of Trilium lies in its ability to maintain seamless, bi-directional synchronization between your local machine and your cloud infrastructure. This technical guide provides a step-by-step walkthrough to deploying Trilium Notes on a Ubuntu/Debian Linux VPS, configuring an Nginx reverse proxy with SSL, and establishing an encrypted sync pipeline to keep your data secure and accessible anywhere.

Prerequisites and System Architecture

Before initiating the deployment, ensure you have the following prerequisites ready:

  • A Linux VPS running Ubuntu 22.04 LTS or newer with a public IPv4 address.
  • A registered domain or subdomain (e.g., notes.yourdomain.com) pointed to your VPS IP address via an A record.
  • SSH access to the server with a non-root user possessing sudo privileges.
  • Trilium Notes desktop client installed on your local workstation (Windows, macOS, or Linux).

Our architecture will utilize Docker Compose for containerized, reproducible deployment, managed behind an Nginx reverse proxy. Nginx will handle incoming HTTPS traffic, terminate the SSL connection using free certificates from Let's Encrypt, and proxy requests securely to the Trilium container.

Step 1: Preparing the Server and Installing Docker

First, log into your Linux VPS via SSH and update the system packages to ensure stability and security:

sudo apt update && sudo apt upgrade -y

Next, install Docker and Docker Compose. Containerization ensures that the Trilium instance runs in an isolated environment with all its dependencies correctly bundled.

sudo apt install docker.io docker-compose -y
sudo systemctl enable --now docker

Verify the installation by checking the Docker version:

docker --version

Step 2: Deploying Trilium Notes Server via Docker Compose

Create a dedicated directory for your Trilium deployment to keep your server organized. This directory will hold the configuration files and persistent data volumes.

mkdir -p ~/trilium-server && cd ~/trilium-server

Create a new file named docker-compose.yml using your preferred text editor:

nano docker-compose.yml

Paste the following configuration into the file. This definition uses the official Trilium image, exposes the service internally on port 8080, and maps a persistent volume to preserve your data across container updates:version: '3' services: trilium-server: image: zadam/trilium:latest restart: always environment: - TRILIUM_DATA_DIR=/home/node/trilium-data ports: - "127.0.0.1:8080:8080" volumes: - ./trilium-data:/home/node/trilium-data

Save and close the file. Launch the container in detached mode:

docker-compose up -d
Security Note: Binding the port to 127.0.0.1:8080 ensures that the Trilium server is not exposed directly to the public internet. It can only be accessed locally or via our reverse proxy, mitigating automated brute-force attacks.

Step 3: Configuring Nginx Reverse Proxy and SSL Encryption

To access Trilium securely via your subdomain, install Nginx and Certbot to automate SSL certificate management:

sudo apt install nginx certbot python3-certbot-nginx -y

Create a new Nginx server block configuration for Trilium:

sudo nano /etc/nginx/sites-available/trilium

Insert the following configuration, replacing notes.yourdomain.com with your actual subdomain:

server {
    listen 80;
    server_name notes.yourdomain.com;

    location / {
        proxy_pass [http://127.0.0.1:8080](http://127.0.0.1:8080);
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

        # WebSockets support for real-time synchronization
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
    }
}

Enable the site configuration by creating a symbolic link to the sites-enabled directory, test the Nginx syntax, and reload the service:

sudo ln -s /etc/nginx/sites-available/trilium /etc/nginx/sites-enabled/
sudo nginx -t
sudo systemctl reload nginx

Now, generate a trusted SSL certificate using Let's Encrypt:

sudo certbot --nginx -d notes.yourdomain.com

Follow the interactive prompts to complete the process. Certbot will automatically modify your Nginx configuration to enforce secure HTTPS connections.

Step 4: Initializing the Server and Enabling Authentication

Open your web browser and navigate to [https://notes.yourdomain.com](https://notes.yourdomain.com). You will be greeted by the Trilium setup wizard. Select "I am a new user and I want to create a new Trilium database".

Set a strong master password. This password encrypts your server-side database and serves as your primary authentication credential. Once completed, log into the web interface to verify that the server instance is functioning correctly.

Step 5: Configuring Bi-Directional Synchronization and Desktop Setup

With the server operating securely, you can now link your local desktop client. This setup enables a bi-directional sync, allowing you to edit notes offline on your computer and sync changes to your VPS effortlessly.

  1. Launch the Trilium Notes desktop application on your personal computer.
  2. On the initial setup screen, select "I want to sync with an existing Trilium instance/server".
  3. Enter your server URL: [https://notes.yourdomain.com](https://notes.yourdomain.com).
  4. Provide your master password to authenticate.

Trilium will initiate an initial handshake and download your node structure. Any modifications made locally will propagate to the server in real-time, and vice versa.

Step 6: Hardening Security with Database Encryption

While the data transit is secured via HTTPS (TLS), encrypting sensitive notes at rest provides defense-in-depth. Trilium natively supports Protected Notes, which enforces end-to-end encryption (E2EE) for specific branches of your note tree.

To utilize this feature, right-click any note or folder in your desktop client, navigate to "Advanced", and select "Protect Note". You will be prompted to define a distinct cryptographic password. When synchronized, these protected notes remain heavily encrypted on your VPS database, ensuring that even if the server is compromised, your most critical credentials, keys, and private journals remain completely unreadable without the encryption key.

Conclusion

By self-hosting Trilium Notes on a private Linux VPS, you successfully bypass the privacy risks associated with public cloud services. The combination of Nginx reverse proxying, Let's Encrypt SSL certificates, bi-directional background synchronization, and per-node database encryption creates a robust, secure, and highly reliable productivity environment. You now possess a sovereign digital second brain tailored to your exact workflow requirements.

Self-Hosting Trilium Notes: A Guide to Secure, End-to-End Encrypted Synchronization on Linux VPS | DPTCloud