Self-Hosting
Production checklist
What to check before exposing a self-hosted Cyborg7 relay to your team.
The step-by-step setup is in Docker (cloud relay), the supported way to run a relay. The variables are in Configuration.
Before you go live
- TLS. Put the relay behind a reverse proxy or load balancer that terminates TLS. Machines and browsers should never reach it in the clear.
RELAY_PUBLIC_URL. Set it to thehttps://origin people will type, with no trailing slash. It is compiled into the web UI, so changing it meansdocker compose buildagain.- Secrets. Generate them (
tools/gen-selfhost-secrets.sh deploy/.env) instead of inventing them:CYBORG7_JWT_SECRET(32+ characters),CYBORG7_DAEMON_TOKEN_SECRETandCYBORG7_REFRESH_TOKEN_SECRET. SetCYBORG7_TOKEN_ENC_KEYbefore connecting any integration and keep it with your other secrets; a lost key makes stored integration credentials unreadable. - Email. Set
RESEND_API_KEYandEMAIL_FROMso sign-up one-time codes can be delivered. - Database. Use a managed or otherwise secured PostgreSQL. If its certificate should be verified, set
PG_SSL_MODE=verify-full; if it speaks no TLS, setPG_SSL_MODE=disable. Never commitDATABASE_URL. - Asset storage. Choose a backend with
ASSETS_BACKEND(s3by default, orfs). Withfs, the asset directory must be writable by the container’s unprivileged user. - Redis. Optional for a single relay. Set
REDIS_URLbefore you run more than one relay instance so rate limits are shared. The compose file fixesREDIS_URLto the bundledredisservice and that value wins overdeploy/.env, so to use another Redis editdeploy/docker-compose.yml. - CORS. Set
CYBORG_CORS_ORIGINSto the origins that should reach the relay.
Migrations
The relay does not apply migrations when it boots. The migrate service in deploy/docker-compose.yml applies them on every docker compose up, and you can run it by hand after pulling a new version:
cd deploy
docker compose run --rm migrate
Outside Docker, pnpm db:migrate runs the same entrypoint against DATABASE_URL. Pending migrations are applied and applied ones are skipped, so re-running is safe.
Connect machines
Once the relay answers GET /api/health, connect your machines with cyborg daemon claim or cyborg daemon join; see the self-hosting overview.