NuFiDocs

Deploying NuFi

From a server to users chatting on it, and the checklist that says you are done.

This section is for the operator standing up an instance that other people will use. Developers running the stack on a laptop want Run the stack locally instead; the compose file is the same, the concerns are not. Every command in this section runs from deploy/platform unless a page says otherwise.

What you need

  • A Linux host. Ubuntu 22.04 LTS is the reference; anything with a current Docker works.
  • Docker Engine 24 or newer with Compose v2.
  • Ports 80 and 443 free for the reverse proxy, or no inbound ports at all with a Cloudflare tunnel.
  • A domain you control.
  • A GitHub token with read:packages, for the images.
  • To start: 12 vCPU, 32 GB RAM, 256 GB SSD. Infra sizing says where that runs out.

Three ways to host

A public host and a reverse proxy. The compose stack on the host, Caddy or Traefik in front, DNS records you control. Docker Compose and SSO and reverse proxy.

A host without a public address. The same stack, exposed through an outbound Cloudflare tunnel, with Cloudflare Access in front of the browser-facing hosts. Cloudflare tunnel.

Railway. How NuFi's own staging runs: the app as a wrapper image built from deploy/railway, the console, the admin panel, Studio and Works as published images, the gateway on a separate host. Release and deploy says which service follows which tag.

All three share Environment variables, GHCR images, Monitoring and alerts and Backup and restore. The two agent products have their own pages: Installing NuFi Studio, Installing NuFi Works, Single sign-on for the agent apps.

Before you let anyone in

  • grep -c replace-me .env prints 0. The stack runs on the example secrets without complaint; nothing else checks this.
  • ALLOW_REGISTRATION is false, or open registration is a decision.
  • HTTPS on every hostname.
  • Subdomain hosting has COOKIE_DOMAIN and COOKIE_SAMESITE=lax on the chat service.
  • One ADMIN account exists and its credentials are somewhere safe.
  • The gateway and scanner images were built from the checkout you deployed (docker compose build litellm-proxy nufi-scanner).
  • ./scripts/smoke-test.sh prints all checks passed, then a person signed in, sent a message, and saw its trace in Langfuse.
  • Backups are scheduled for MongoDB and Postgres, with the authenticated mongodump form, and one restore has been tried.
  • The Slack webhook is in place, so a critical guardrail alert reaches a human.
  • The registry sign-in for the host is recorded where a teammate can find it during an incident.
  • Every image is pinned to a version; main is for staging.