Skip to content

Deployment

OpenTremor Core ships as a set of Docker images — there is no other distribution format. Choose the topology that matches your infrastructure.

TopologyBest for
Docker (Single-VM)One host, no Kubernetes cluster — Compose + HAProxy + Let’s Encrypt
Helm chartKubernetes — HPA, Ingress, Secret management

DependencyRequiredNotes
Docker + Compose (or a Kubernetes cluster)YesThe only supported install path
MongoDB 7.0+RecommendedNot required when storage.backend: memory

Every topology shares the same YAML configuration file. See Full Reference for every field.

In any real (multi-replica or restart-tolerant) deployment, set JWT_SECRET, LLM_CREDENTIAL_KEY and TWO_FACTOR_SECRET_KEY explicitly via environment variable/Secret. Left unset each defaults to a new random value per process, which does not fail — it silently makes everything encrypted under the previous value unreadable the next time the service restarts:

UnsetWhat breaks on restart
JWT_SECRETEvery session — all users logged out
LLM_CREDENTIAL_KEYStored per-org LLM credentials, SSO client secrets, and a custom GitHub App’s private key and webhook secret — the App’s webhooks start failing and it has to be re-registered
TWO_FACTOR_SECRET_KEYEnrolled TOTP secrets — every user with 2FA on must re-enrol

Generate each once and never change it. There is no re-encryption step anywhere in the codebase, so changing one of these is not a rotation — it is data loss for everything already encrypted under the old value. docker-compose.prod.yaml reads all three from a gitignored .env beside it (see .env.example) and refuses to start if any is missing.

AUTH_API_KEY is required by the same compose file, on the same terms, and the .env.example snippet generates it alongside the other three. It is not an encryption key — nothing is stored under it, so it can be rotated freely — but leaving it empty does not merely omit a bootstrap credential: it disables authentication outright, resolving every caller to a superadmin owner of the default org. That is why compose treats a missing value as fatal rather than defaulting it. See Environment Variables. If using the GitHub App integration with the platform’s own shared App, set it via PATCH /admin/settings after first boot instead — github isn’t read from the config file or env at all, see Platform settings.