Self-Hosted Deployment
Run ScanDrix inside your own VPC or on-prem — Docker Compose, Kubernetes, and air-gapped setups.
Enterprise deployments run entirely within your network: AWS, GCP, or Azure VPC, or a fully air-gapped on-premise environment.
What you get
- Code never leaves your network (bring internal LLM endpoints: vLLM or Ollama).
- Same product surface: dashboard, rules, Dry Runs, CLI, Cockpit metrics.
- Enterprise SSO and your own secret management.
Requirements
| Item | Minimum |
|---|---|
| Compute | 4 vCPU / 8 GB RAM (API + worker + web) |
| Database | PostgreSQL 15+, MongoDB 6+ |
| Queue | RabbitMQ 3.12+ with delayed-message exchange plugin |
| Object storage | S3-compatible bucket (or local volume for small installs) |
| LLM access | Internal endpoints (vLLM/Ollama) or BYOK egress allow-list |
Docker Compose (standard install)
# 1. Unpack the release bundle
tar -xzf scandrix-selfhosted-<version>.tar.gz && cd scandrix
# 2. Configure
cp .env.example .env
$EDITOR .env # set SCANDRIX_SECRET, DATABASE_URL, LLM_BASE_URL...
# 3. Start the stack
docker compose up -d
# 4. Create the first admin
docker compose exec api scandrix bootstrap-admin --email admin@example.com
Open the dashboard on port 8080 (or your reverse proxy's hostname — see Reverse Proxy & TLS).
.env holds real secrets — database URLs, signing keys, provider credentials. Keep it out of version control and load it from your platform's secret manager in production.
Kubernetes
Helm chart with the same components (api, worker, relay, web, postgres, mongodb, rabbitmq):
helm repo add scandrix https://charts.scandrix.dev
helm install scandrix scandrix/scandrix \
--namespace scandrix --create-namespace \
--set image.tag=<version> \
-f values.production.yaml
values.production.yaml should reference your existing managed database/queue endpoints rather than the chart-bundled ones.
Air-gapped notes
- Mirror container images and the CLI binary to your internal registry.
- Point
LLM_BASE_URLat an internal inference server (vLLM/Ollama) — no egress required. - License file is offline-validated; no phone-home telemetry (telemetry can be disabled entirely).
Upgrades
docker compose pull && docker compose up -d
Schema migrations run automatically at startup and are backward-compatible for one minor version — upgrade one minor at a time. Keep a database backup before each upgrade; rollback = restore backup + previous image tag.
Health checks
| Endpoint | Purpose |
|---|---|
GET /healthz | Liveness — process is up |
GET /readyz | Readiness — DB + queue reachable |
/metrics | Prometheus scrape (workers expose queue depth) |