Docker Compose
The recommended deployment method for single-node installations. Runs PostgreSQL, Redis, the migration engine, the core server, and the web console with healthcheck dependencies.
Telmoni open core is designed to be fully self-hosted on your own infrastructure without dependencies on proprietary cloud services. All core functionality—including organization management, project scoping, audit logging, webhook connectors, notifications, and AI search—runs inside your own network perimeter.
The Telmoni deployment consists of five primary components:
flowchart TD Client["Browser / API Client"] --> ReverseProxy["Reverse Proxy (Caddy / Nginx)"] ReverseProxy -->|Port 3000| Web["Web Console (Next.js BFF)"] ReverseProxy -->|Port 8082 /v1| Server["Core Backend (Rust / Tokio)"]
Web -->|Internal HTTP| Server Web -->|Rate limiting & Sessions| Redis[("Redis 7 (Alpine)")]
Server -->|Schema DDL & Migrations| Migrator["Migrator Engine"] Server -->|Auth & Tenancy| Postgres[("PostgreSQL 17 + pgvector")] Server -->|Notifications & Webhooks| Postgres Server -->|Vector Search & Agent| Postgres
Server -.->|Local Embeddings| Ollama["Ollama (nomic-embed-text)"]telmoni serve): A high-performance, single-binary Rust service built on Axum and Tokio. It exposes the REST and internal service APIs on port 8082, executes tenant-isolated database queries with Row-Level Security (RLS), signs webhook payloads, dispatches notifications, and runs automated maintenance loops (retention purges, soft-deletion sagas, and nightly audit verification walks).telmoni/web): A Next.js application that serves the dashboard, handles server-side session cookies (sealed with AUTH_SECRET), proxies authenticated requests to the backend server, and performs edge rate limiting.pgvector: The primary relational store. Telmoni uses native partitioning for the audit ledger and the vector extension for semantic document search. In production, each service module (auth, notifications, agent, migrator) connects using a hardened, least-privilege database role.PEXPIRE), Redis requires no disk snapshots (--save "").telmoni migrate): A one-shot CLI command packaged within the backend binary. It executes pending database migrations and applies owner grants before the server boots.nomic-embed-text embeddings and local LLM inferences. Hosted providers (Anthropic Claude, OpenAI, or Google Gemini) can be configured via environment variables.When moving from a local evaluation or single-node Docker quickstart to a production environment, follow these best practices:
ADMIN_EMAIL / ADMIN_PASSWORD) is provided to bootstrap an instance quickly, we strongly recommend connecting an OpenID Connect (OIDC) identity provider (Okta, Keycloak, Microsoft Entra ID, Authentik, Google Workspace). Once OIDC is tested, disable the password form entirely via DISABLE_LOGIN_FORM=true to eliminate credential stuffing and enforce corporate MFA.crates/migrator/sql/role_hardening.sql to enforce NOBYPASSRLS across auth, notifications, and agent roles.3000 or 8082 directly to the internet. Always terminate TLS using Caddy, Nginx, or a cloud Ingress controller.telmoni rotate weekly via cron or a Kubernetes CronJob to maintain the 4-month forward partition runway and drop expired logs according to your retention policy.CONNECTOR_KEK securely in a secret manager or Cloud KMS. Back up this key alongside your database dumps to ensure connector credentials remain decryptable.Choose the deployment workflow that fits your infrastructure:
Docker Compose
The recommended deployment method for single-node installations. Runs PostgreSQL, Redis, the migration engine, the core server, and the web console with healthcheck dependencies.
Kubernetes & Helm
Deploy scalable, highly available replicas using our production Helm chart located in deploy/charts/telmoni.
Self-Hosted AI Agent
Configure offline vector embeddings with Ollama, hybrid search, read-only tools, and documentation corpus indexing.
Production Hardening
Configure enterprise OIDC, hardened PostgreSQL roles, automated audit partition rotations, and TLS reverse proxies.