Self-Hosted Deployment

Run ScanDrix inside your own VPC or on-prem — Docker Compose, Kubernetes, and air-gapped setups.

Enterprise deployments run entirely within your network: AWS, GCP, or Azure VPC, or a fully air-gapped on-premise environment.

What you get

  • Code never leaves your network (bring internal LLM endpoints: vLLM or Ollama).
  • Same product surface: dashboard, rules, Dry Runs, CLI, Cockpit metrics.
  • Enterprise SSO and your own secret management.

Requirements

ItemMinimum
Compute4 vCPU / 8 GB RAM (API + worker + web)
DatabasePostgreSQL 15+, MongoDB 6+
QueueRabbitMQ 3.12+ with delayed-message exchange plugin
Object storageS3-compatible bucket (or local volume for small installs)
LLM accessInternal endpoints (vLLM/Ollama) or BYOK egress allow-list

Docker Compose (standard install)

bash
# 1. Unpack the release bundle
tar -xzf scandrix-selfhosted-<version>.tar.gz && cd scandrix

# 2. Configure
cp .env.example .env
$EDITOR .env   # set SCANDRIX_SECRET, DATABASE_URL, LLM_BASE_URL...

# 3. Start the stack
docker compose up -d

# 4. Create the first admin
docker compose exec api scandrix bootstrap-admin --email admin@example.com

Open the dashboard on port 8080 (or your reverse proxy's hostname — see Reverse Proxy & TLS).

.env holds real secrets — database URLs, signing keys, provider credentials. Keep it out of version control and load it from your platform's secret manager in production.

Kubernetes

Helm chart with the same components (api, worker, relay, web, postgres, mongodb, rabbitmq):

bash
helm repo add scandrix https://charts.scandrix.dev
helm install scandrix scandrix/scandrix \
  --namespace scandrix --create-namespace \
  --set image.tag=<version> \
  -f values.production.yaml

values.production.yaml should reference your existing managed database/queue endpoints rather than the chart-bundled ones.

Air-gapped notes

  • Mirror container images and the CLI binary to your internal registry.
  • Point LLM_BASE_URL at an internal inference server (vLLM/Ollama) — no egress required.
  • License file is offline-validated; no phone-home telemetry (telemetry can be disabled entirely).

Upgrades

bash
docker compose pull && docker compose up -d

Schema migrations run automatically at startup and are backward-compatible for one minor version — upgrade one minor at a time. Keep a database backup before each upgrade; rollback = restore backup + previous image tag.

Health checks

EndpointPurpose
GET /healthzLiveness — process is up
GET /readyzReadiness — DB + queue reachable
/metricsPrometheus scrape (workers expose queue depth)