Edgeweir
Deployment

Deployment overview

Console components, runtime requirements, supported platforms, and process roles.

Components

ComponentDescriptionRequired
Console image ghcr.io/marvinli001/edgeweirlinux/amd64, linux/arm64. One Node.js process: web UI and API (:3000), node channel (:8443), pg-boss worker; ships edgeweir-certd (ACME and DNS records).Yes
PostgreSQL 18Only external dependency. Holds all state, the pg-boss queues, and the sign-in rate-limit counters; LISTEN/NOTIFY broadcasts configuration changes between instances.Yes
ClickHouseRaw access logs and per-minute statistics, enabled with EDGEWEIR_ANALYTICS=clickhouse; see access logs and AccessKeys.No
Edge nodesedgeweir-node on separate hosts; see adding nodes.—

Runtime requirements

ItemRequirementConstraint
ProcessAlways onScale-to-zero or per-request freezing stops the worker and the node streams; see process roles.
PostgreSQL18; the console's database user has CREATE on the target database (schemas drizzle, pgboss) and CREATE on schema publicEarlier versions are untested. Migrations run at startup.
3000/TCPHTTP: web UI, /rpc, /api/v1, /healthz, /install.sh, /downloads/*; the node channel's WebSocket entry /node-channel (closed by default)A reverse proxy may terminate TLS; see ports and reverse proxy.
8443/TCPNode channel (nodes and regional probes): the console terminates TLS and enforces mTLS after enrollmentPublicly reachable, direct or layer-4 passthrough only; or nodes use the WebSocket entry on 3000 and 8443 stays internal.
Master keyEDGEWEIR_MASTER_KEY: base64, at least 32 bytes decoded; generate with openssl rand -base64 32Keep apart from database backups; a lost key leaves encrypted data unreadable; replace it by rotating it.
Session secretBETTER_AUTH_SECRET: derived from the master key when unsetDeployments that set it keep it; the console refuses to start once it is removed.
Architecturelinux/amd64, linux/arm64—
ResourcesNo minimum specificationcompose.yml sets nofile 262144 for ClickHouse.

Supported platforms

PlatformMethodDocumentationStatus
Docker Composecompose.yml: console and bundled PostgreSQL 18docker.en.mdSupported
docker runConsole and PostgreSQL containers on a dedicated Docker networkdocker.en.mdSupported
BaoTa / aaPanel, or any Docker hostdeploy.sh with compose.baota.yml (bundled PostgreSQL) or compose.baota-host.yml (local or cloud PostgreSQL, host network)baota.en.md, deploy-script.en.mdSupported
RailwayConsole image with Railway PostgreSQL 18; web console, optional Railway CLIrailway.en.mdSupported
Fly.ioConsole image with an external PostgreSQL 18; flyctl deployment, Dashboard for secrets, IPs, certificates, and logsfly.en.mdSupported
bunny.net Magic ContainersConsole image with an external PostgreSQL 18; a CDN endpoint for the web console, an Anycast IP for the node channel; Dashboard, optional bunny CLIbunny.en.mdSupported
Renderrender.yaml creates the console and Render Postgres 18 in one click, or manual creation in the Dashboard; nodes connect through the WebSocket entry (edgeweir-node 0.2.0 or later)render.en.mdSupported
ZeaburThe zeabur.yaml template creates the console and PostgreSQL 18 in one click, or manual creation in the Dashboard; runs on a Zeabur Server, the node channel goes through TCP port forwardingzeabur.en.mdSupported

Platform conditions

A platform not listed above must meet every condition in this table.

ConditionDescriptionWhen not met
Always-on processThe process keeps running and never scales to zero for lack of trafficWorker certificate renewal and scheduled jobs, the LISTEN/NOTIFY event bus, and node WatchConfig streams stop.
Public TCP port or WebSocketThe node channel port is exposed as raw TCP, and the platform does not terminate TLS; or the platform's HTTP entry forwards WebSocket and nodes use the WebSocket entryEnrollment fails (CA pin mismatch); mTLS cannot be established.
PostgreSQL 18Reachable from the console, with the privileges aboveThe console waits 60 seconds, then exits.
Persistent secretsEDGEWEIR_MASTER_KEY (and BETTER_AUTH_SECRET when set) stay the same across restarts and redeploysEncrypted data becomes unreadable; the console refuses to start.
Trusted proxy addressPort 3000 receives client connections directly, or the platform proxy connects from fixed addresses that can go into EDGEWEIR_TRUSTED_PROXIESAudit entries and sign-in rate limits see only the proxy address.

Process roles

ROLE selects what the image runs.

ROLERunsListens onContainer health check
all (default)Everything in app and worker3000, 8443GET /healthz
appWeb UI, /rpc, /api/v1, node channel, setup token output, LISTEN/NOTIFY subscription3000, 8443GET /healthz
workerpg-boss queues and schedulesNothingProcess liveness only

Every role runs database migrations at startup.

Worker schedules:

IntervalJobs
Every 10 secondsProbe-driven address reachability and scheduling rule evaluation (one process at a time)
Every minuteAlert checks; DNS sync; traffic and access-log rollups, node upgrade timeouts; certificate issuance and renewal
HourlyPruning old revisions; expiring undelivered purge and prefetch tasks
Every 30 minutesDeleting enrollment tokens expired or used more than 7 days ago
At startupWhen an upgrade changes what the stored configuration compiles to, republishing every cluster once (reason "Configuration recompiled after an upgrade")

Scaling

  • Several app instances and one or more worker instances share one PostgreSQL database.
  • Migrations are serialized by a PostgreSQL advisory lock; instances may start at the same time.
  • Sign-in rate-limit counters live in PostgreSQL, are shared by all instances, and survive restarts.
  • The node channel CA is stored in the database; every app instance issues its server certificate from the same CA, so a layer-4 load balancer may spread 8443 across app instances.
  • All instances run the same image tag and are upgraded together; see upgrades.

Deployment documents

DocumentContents
Docker ComposeCompose and docker run deployment
BaoTa / aaPanelPanel deployment, nginx site, stream passthrough
deploy.sh referenceInstall and upgrade script
RailwayWeb console deployment with CLI equivalents
Fly.ioflyctl deployment and Dashboard steps
bunny.net Magic ContainersDashboard deployment with bunny CLI equivalents
RenderOne-click Deploy to Render, manual creation in the Dashboard, Render CLI
ZeaburOne-click template, manual creation in the Dashboard, Zeabur CLI
Ports, reverse proxy, and trusted proxies3000 and 8443, nginx examples, the node channel's WebSocket entry, EDGEWEIR_TRUSTED_PROXIES
Adding nodesInstall command, install.sh checks, regional probes, downloads mirror
Versions, upgrades, and rollbackImage tags, pinning, upgrade, rollback, signature verification
Backup and recoveryDatabase and master key backup, restore acceptance
Environment variablesEvery variable and its default
Edit on GitHub

On this page