Separate containers
docker/compose.yaml runs the same image as three containers: PostgreSQL, the API with the admin UI, and the proxy.
They share the secrets, settings come from the environment as with docker run:
docker compose -f docker/compose.yaml up -d --buildENCRYPTION_KEY and API_SECRET_KEY, if not set, are generated on the first start and kept in the secrets
volume. Set them, and the volume stores no secrets. Keys generated by an earlier start stay there unused: delete
them from the volume once you set your own.
To move to your own keys later, pass the generated ones from the volume, or rotate ENCRYPTION_KEY with
ENCRYPTION_OLD_KEYS, see TLS: with a new key stored certificates can’t be read. A
new API_SECRET_KEY only logs everyone out.
To customize ports, the database, TLS and the rest, take docker/compose.yaml as a starting point and edit your copy.