rootset-api (API and migration commands), rootset-worker (background jobs) and rootset-web (UI). They share the same release version. You do not need Node.js, pnpm, GitHub Packages credentials or a local source build to run published images.
Rootset 0.1.0 is
available with public API, worker and UI images for Linux AMD64 and ARM64. Use
the installation files attached to your chosen release.
Requirements
- Docker Engine and Docker Compose 2.23.1 or later, which supports the inline configuration used for bundled PostgreSQL.
- PostgreSQL 18: your own database or the optional bundled PostgreSQL service.
- An existing private S3-compatible bucket for export artifacts.
- SMTP for verification, invitations and account recovery. Set the port and TLS mode to match your provider.
ROOTSET_SMTP_SECURE=trueuses implicit TLS;falseuses SMTP/STARTTLS, commonly on port 587. - Separate UI and API HTTPS origins for an internet-facing installation.
1. Download the release installation files
Choose a published version from GitHub Releases. Replace0.1.0 below with that version.
ROOTSET_VERSION in .env to the chosen release version; it selects the same version for API, worker and UI; migrations use the API image.
2. Configure your services
Edit.env, replacing every placeholder. Generate the application secret and encryption key separately with openssl rand -hex 32. Retain both across restarts. Set the configuration values for PostgreSQL, S3 and SMTP.
For your own PostgreSQL instance, set ROOTSET_DATABASE_URL to one ordinary database owner with permission to create schemas and the pgcrypto extension. Do not use a superuser or BYPASSRLS role. API, worker and migrations share this URL. A pre-existing Rootset prelaunch schema is not a supported upgrade target.
For bundled PostgreSQL, use the local-db profile, set POSTGRES_PASSWORD, and set ROOTSET_DATABASE_URL=postgres://rootset:<same-password>@postgres:5432/rootset. The bundled service creates the ordinary rootset owner for you. Use a URL-safe password such as the hex output of openssl rand -hex 32.
3. Pull and start
4. Claim the installation
For a local preview, openhttp://localhost:4300. Enter the configured ROOTSET_SECRET privately to claim setup, verify your email, and create the first Admin and single workspace. Use Create database to begin.
Public origins
Terminate HTTPS at your reverse proxy. SetROOTSET_WEB_URL=https://rootset.example.com and ROOTSET_API_URL=https://rootset-api.example.com. Route those origins to ports 4300 and 4310 respectively. The UI reads the API origin at runtime. Authentication, REST, MCP and downloads use the API directly. Same-parent domains keep browser cookie access straightforward; test sign-in when deploying across unrelated sites.
The Compose file binds ports to loopback by default. If your reverse proxy runs in a container, connect it to the Compose network or deliberately configure a reachable bind address. Do not expose PostgreSQL publicly. See security and troubleshooting.