Docker Compose Quickstart
Docker Compose is the fastest way to get a production-ready Telmoni instance running on a single host. The stack bundles PostgreSQL 17 with pgvector, Redis 7 Alpine, the automated database migrator, the Rust core backend server, and the Next.js web console.
Prerequisites
Section titled “Prerequisites”Before starting, ensure your host has the following tools installed:
- Docker Engine (v24.0 or newer)
- Docker Compose (v2.20 or newer)
openssl(for cryptographically secure secret generation)
Deployment steps
Section titled “Deployment steps”-
Obtain the Docker Compose configuration
Clone the Telmoni repository or download the production compose specification:
Terminal window git clone https://github.com/telmoni/telmoni.gitcd telmoniThe production compose file is located at
deploy/compose/docker-compose.yml. -
Generate secrets and configure environment variables
Create a
.envfile in the project root:Terminal window cp .env.example .envTelmoni requires two cryptographic secrets to start:
SERVICE_SECRET: A shared token used by the web console to sign and authenticate internal RPC calls to the backend server.AUTH_SECRET: A 32-byte secret used to seal and decrypt session cookies.CONNECTOR_KEK: The Key Encryption Key used to encrypt connector secrets and webhook tokens at rest.
Generate random values using
openssl:Terminal window # Generate 32-byte hex stringsopenssl rand -hex 32Update your
.envfile with the generated secrets and set your initial administrator credentials:Terminal window # SecretsSERVICE_SECRET=f3b9c7e2a1d4... # Output from openssl rand -hex 32AUTH_SECRET=8e6a1c5d0f2b... # Output from openssl rand -hex 32CONNECTOR_KEK=local:0000000000000000000000000000000000000000000000000000000000000000# Public application URL (change if serving behind a domain or reverse proxy)APP_URL=http://localhost:3000AUTH_URL=http://localhost:3000NEXT_PUBLIC_APP_URL=http://localhost:3000# Database settingsPOSTGRES_USER=telmoniPOSTGRES_PASSWORD=your_secure_db_passwordPOSTGRES_DB=telmoni# Bootstrap initial administrator account (quickstart / setup only)ADMIN_EMAIL=admin@example.comADMIN_PASSWORD=your_super_secret_admin_passwordALLOW_SIGN_UP=falseVERIFY_EMAIL=false[!NOTE]
ADMIN_EMAILandADMIN_PASSWORDare intended only for initial bootstrapping, local evaluation, and offline setups. For production environments, we strongly recommend configuring an OpenID Connect (OIDC) identity provider and disabling username/password logins viaDISABLE_LOGIN_FORM=true. See Production Hardening & OIDC. -
Start the Telmoni stack
Run the compose file in detached mode:
Terminal window docker compose -f deploy/compose/docker-compose.yml up -dDocker Compose executes the services in sequence:
- Starts
postgresandredisand waits for their healthchecks to pass. - Launches the transient
migratecontainer, which applies all schema DDL and table grants, then exits cleanly (exit 0). - Starts the
servercontainer on internal port8082. - Starts the
webcontainer on port3000.
- Starts
-
Verify container health
Check that all services are healthy and running:
Terminal window docker compose -f deploy/compose/docker-compose.yml psExpected output:
NAME IMAGE COMMAND SERVICE STATUStelmoni-postgres pgvector/pgvector:pg17 "postgres -c max_con…" postgres Up (healthy)telmoni-redis redis:7-alpine "redis-server --save…" redis Up (healthy)telmoni-migrate ghcr.io/telmoni/server:latest "telmoni migrate" migrate Exited (0)telmoni-server ghcr.io/telmoni/server:latest "telmoni serve" server Up (healthy)telmoni-web ghcr.io/telmoni/web:latest "docker-entrypoint.s…" web Up -
Log in to the console
Open your browser and navigate to
http://localhost:3000. Log in with theADMIN_EMAILandADMIN_PASSWORDyou configured in your.envfile. Upon your first login, Telmoni automatically creates your default Organization and primary Project.
Enabling local AI agent search (optional)
Section titled “Enabling local AI agent search (optional)”Telmoni includes an AI context agent with vector similarity search. You can run embeddings and chat inference completely locally using Ollama without sending any data to external APIs.
-
Start the stack with the
agentprofile:Terminal window docker compose -f deploy/compose/docker-compose.yml --profile agent up -d -
Pull the embedding model into the persistent
ollama_modelsvolume:Terminal window docker compose -f deploy/compose/docker-compose.yml exec ollama ollama pull nomic-embed-text -
Set the agent environment variables in your
.envfile:Terminal window AGENT_MODEL_PROVIDER=openaiAGENT_MODEL_URL=http://ollama:11434/v1AGENT_MODEL=llama3.2EMBEDDINGS_URL=http://ollama:11434/v1EMBEDDINGS_MODEL=nomic-embed-text -
Restart the server container to apply the changes:
Terminal window docker compose -f deploy/compose/docker-compose.yml restart server
Maintenance commands
Section titled “Maintenance commands”Viewing live service logs
Section titled “Viewing live service logs”# Follow logs for the core backend serverdocker compose -f deploy/compose/docker-compose.yml logs -f server
# Follow logs for the web consoledocker compose -f deploy/compose/docker-compose.yml logs -f webRotating audit partitions
Section titled “Rotating audit partitions”The audit log uses monthly PostgreSQL partitions. To maintain the 4-month forward partition runway and drop tables beyond your retention policy, execute:
docker compose -f deploy/compose/docker-compose.yml run --rm migrate telmoni rotateStopping the stack
Section titled “Stopping the stack”# Stop containers (preserves database and redis volumes)docker compose -f deploy/compose/docker-compose.yml down
# Stop containers and remove all persistent data (destructive)docker compose -f deploy/compose/docker-compose.yml down -v