Deployment
OpenTremor Core ships as a set of Docker images — there is no other distribution format. Choose the topology that matches your infrastructure.
| Topology | Best for |
|---|---|
| Docker (Single-VM) | One host, no Kubernetes cluster — Compose + HAProxy + Let’s Encrypt |
| Helm chart | Kubernetes — HPA, Ingress, Secret management |
Runtime dependencies
Section titled “Runtime dependencies”| Dependency | Required | Notes |
|---|---|---|
| Docker + Compose (or a Kubernetes cluster) | Yes | The only supported install path |
| MongoDB 7.0+ | Recommended | Not required when storage.backend: memory |
Configuration
Section titled “Configuration”Every topology shares the same YAML configuration file. See Full Reference for every field.
In any real (multi-replica or restart-tolerant) deployment, set JWT_SECRET,
LLM_CREDENTIAL_KEY and TWO_FACTOR_SECRET_KEY explicitly via environment variable/Secret.
Left unset each defaults to a new random value per process, which does not fail — it
silently makes everything encrypted under the previous value unreadable the next time the
service restarts:
| Unset | What breaks on restart |
|---|---|
JWT_SECRET | Every session — all users logged out |
LLM_CREDENTIAL_KEY | Stored per-org LLM credentials, SSO client secrets, and a custom GitHub App’s private key and webhook secret — the App’s webhooks start failing and it has to be re-registered |
TWO_FACTOR_SECRET_KEY | Enrolled TOTP secrets — every user with 2FA on must re-enrol |
Generate each once and never change it. There is no re-encryption step anywhere in the
codebase, so changing one of these is not a rotation — it is data loss for everything
already encrypted under the old value. docker-compose.prod.yaml reads all three from a
gitignored .env beside it (see .env.example) and refuses to start if any is missing.
AUTH_API_KEY is required by the same compose file, on the same terms, and the .env.example
snippet generates it alongside the other three. It is not an encryption key — nothing is stored
under it, so it can be rotated freely — but leaving it empty does not merely omit a bootstrap
credential: it disables authentication outright, resolving every caller to a superadmin owner of
the default org. That is why compose treats a missing value as fatal rather than defaulting it.
See Environment Variables. If using the
GitHub App integration with the platform’s own shared App, set it via
PATCH /admin/settings after first boot instead — github isn’t read from the config file
or env at all, see
Platform settings.