Docker Compose
Install the platform on a single host with the official Docker Compose definition, covering secrets,TLS, backups, upgrades, and troubleshooting steps.
The platform repository includes a Compose definition that runs the platform, PostgreSQL, SeaweedFS, and Chrome headless on a single host.
For work tasks that require independent scaling, managed data services or running updates, use Kubernetes deployment.
Requirements
Section titled ‘Requirements’- A Linux host with Docker Engine and Docker Compose v2
- A DNS record for the host name you will use
- A TLS-terminating reverse proxy or load balancer
- A SMTP relay if you want the platform to send emails
- Enough memory for the platform and its dependencies; only the provided PostgreSQL configuration requires 4 GB of shared buffers
Install the platform
Section entitled “Install the platform”-
Clone the repository
Terminal window git clone https://github.com/getprobo/probo.gitcd proboKeep
compose.prod.yamland thecompose/directory together. The composite definition mounts the PostgreSQL initialization script and the SeaweedFS configuration in that directory. -
Generate application secrets
Terminal window umask 077openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 \-out oauth2-signing-key.pemexport PROBOD_ENCRYPTION_KEY="$(openssl rand -base64 32)"export PROBOD_AUTH_COOKIE_SECRET="$(openssl rand -base64 32)"export PROBOD_AUTH_PASSWORD_PEPPER="$(openssl rand -base64 32)"export PROBOD_TRUST_AUTH_TOKEN_SECRET="$(openssl rand -base64 32)"Changing the encryption, signature or authentication secrets after the existence of users and data may invalidate sessions or make stored data inaccessible.
-
Create the environment file
Replace
probo.example.comand the SMTP values, then run:Terminal window cat > .env <<EOFPROBOD_ENCRYPTION_KEY=${PROBOD_ENCRYPTION_KEY}PROBOD_AUTH_COOKIE_SECRET=${PROBOD_AUTH_COOKIE_SECRET}PROBOD_AUTH_PASSWORD_PEPPER=${PROBOD_AUTH_PASSWORD_PEPPER}PROBOD_TRUST_AUTH_TOKEN_SECRET=${PROBOD_TRUST_AUTH_TOKEN_SECRET}PROBOD_BASE_URL=https://probo.example.comPROBOD_API_ADDR=0.0.0.0:8080PROBOD_API_CORS_ALLOWED_ORIGINS=https://probo.example.comPROBOD_SMTP_ADDR=smtp.example.com:587PROBOD_SMTP_USER=replace-with-smtp-userPROBOD_SMTP_PASSWORD=replace-with-smtp-passwordPROBOD_SMTP_TLS_REQUIRED=truePROBOD_MAILER_SENDER_EMAIL=no-reply@example.comEOFTerminal window chmod 600 .env oauth2-signing-key.pem -
Add the required OAuth signing key
The current
compose.prod.yamldoes not pass the OAuth signature key on the platform. Createcompose.local.yaml:services:probo:environment:PROBOD_OAUTH2_SERVER_SIGNING_KEY: ${PROBOD_OAUTH2_SERVER_SIGNING_KEY}PROBOD_SMTP_ADDR: ${PROBOD_SMTP_ADDR}PROBOD_SMTP_USER: ${PROBOD_SMTP_USER}PROBOD_SMTP_PASSWORD: ${PROBOD_SMTP_PASSWORD}PROBOD_SMTP_TLS_REQUIRED: ${PROBOD_SMTP_TLS_REQUIRED}PROBOD_MAILER_SENDER_EMAIL: ${PROBOD_MAILER_SENDER_EMAIL}Export the key before each Composite order:
Terminal window export PROBOD_OAUTH2_SERVER_SIGNING_KEY="$(cat oauth2-signing-key.pem)" -
Review the rendered configuration
Terminal window docker compose \-f compose.prod.yaml \-f compose.local.yaml \configDo not proceed if a requested value is empty. the rendered output contains secrets, so do not save it or share it.
-
Start the Services
Terminal window docker compose \-f compose.prod.yaml \-f compose.local.yaml \up -d -
Verify startup
Terminal window docker compose \-f compose.prod.yaml \-f compose.local.yaml \psdocker compose \-f compose.prod.yaml \-f compose.local.yaml \logs --tail=100 probocurl --fail http://127.0.0.1:8080/A successful HTTP response and a functional service
proboconfirm that the application is accessible. Also test authentication, file uploading and email delivery before inviting users.
Put the platform behind HTTPS
“Put the platform behind HTTPS”StopTLS at a reverse proxy or load balancer and send requests to the port 8080. Keep the original titles ___ZBT_I18N_RUNTIME_BLOCK_188__, X-Forwarded-For and X-Forwarded-Proto.
The Compose definition provided publishes the platform, PostgreSQL, SeaweedFS, and Chrome ports on each host interface.
- restriction of incoming traffic with the host or cloud firewall;
- expose only the ports ___ZBT_I18N_RUNTIME_BLOCK_191__ and ___ZBT_I18N_RUNTIME_BLOCK_192__ via the reverse proxy;
- To prevent external access to ports
5432,8443,8081,8333,8443,9222and9333; - Replace the PostgreSQL and SeaweedFS credentials combined or use external managed services;
- Place the platform image in a tested version instead of
latest.
Installing a certificate in the platform container does not configureTLSitself.
Data and backups
Section “Data and Backups”The implementation stores are presented in three volumes named:
probo-datafor local platform data;postgres-datafor PostgreSQL;seaweedfs-datafor storing objects.
Backup PostgreSQL and SeaweedFS as a single recovery point. a dump of databases without its corresponding objects can leave document records whose files cannot be restored.
Create a database dump with:
docker compose \ -f compose.prod.yaml \ -f compose.local.yaml \ exec -T postgres \ pg_dump -U postgres -d probod --format=custom > probod.dumpUse a volume-conscious backup tool or instant storage capture for SeaweedFS. Stop writing while making an offline volume backup and test restoration on another host. Copy ___ZBT_I18N_RUNTIME_BLOCK_202__, oauth2-signing-key.pem and any proxy configuration into the encrypted backup system separately.
Upgrade
Posts Tagged ‘Upgrade’Read the launch notes and first make a tested backup, then drag and recreate the containers:
export PROBOD_OAUTH2_SERVER_SIGNING_KEY="$(cat oauth2-signing-key.pem)"
docker compose \ -f compose.prod.yaml \ -f compose.local.yaml \ pull
docker compose \ -f compose.prod.yaml \ -f compose.local.yaml \ up -dCheck the platform logs and repeat the functional checks used during installation.Data base migrations are executed when the platform starts; do not interrupt the start while a migration is executed.
Troubleshooting
Section “Troubleshooting”the platform exits during startup
“The platform exits during startup”docker compose \ -f compose.prod.yaml \ -f compose.local.yaml \ logs --tail=200 proboIf logs report a missing PROBOD_OAUTH2_SERVER_SIGNING_KEY, confirm that the key is exported to the current shell and that both Composite files are included in the order.
PostgreSQL is unhealthy
PostgreSQL is unhealthydocker compose \ -f compose.prod.yaml \ -f compose.local.yaml \ logs --tail=200 postgres
docker compose \ -f compose.prod.yaml \ -f compose.local.yaml \ exec postgres pg_isready -U postgres -d probodThe PostgreSQL settings provided require much more than 4 GB of total host memory. If PostgreSQL is killed by the kernel, increase the host memory or revise its configuration before lowering the limits.
Uploads or PDF generation fail
Section titled “Uploads or PDF generation fail”Check the platform logs, SeaweedFS and Chrome:
docker compose \ -f compose.prod.yaml \ -f compose.local.yaml \ logs --tail=200 probo seaweedfs chromeSee the environment variable reference when optional integrations are added or runtime behavior is changed.