Run it on your cloud
So code review and scan data stay on a machine you control. The same Docker Compose file runs on a laptop or on a Linux VM in AWS, Azure, or Google Cloud.
1. Start
From the repo root. This starts Postgres, the API, and the web UI.
cp .env.example .env
npm run compose:upOpen http://localhost:3000. On a VM, use the VM address on port 3000.
2. Put it on AWS, Azure, or Google Cloud
Create a Linux VM with Docker, clone this repo, then set the public site URL and turn off the local login bypass. Compose does not terminate TLS. The cloud load balancer does.
DEV_AUTH_BYPASS=false
NEXTAUTH_URL=https://app.example.com
NEXT_PUBLIC_APP_URL=https://app.example.com
NEXT_PUBLIC_API_URL=https://app.example.comWrite those into .env, then npm run compose:up. Point the load balancer at port 3000. The web container talks to the API inside Compose, so you do not need a public API port.
- AWS — EC2, TLS on an Application Load Balancer, target port 3000.
- Azure — a Linux VM, TLS on Application Gateway, backend port 3000.
- Google Cloud — a Compute Engine VM, TLS on an HTTPS load balancer, port 3000.
Close port 5432 in the cloud firewall. Compose publishes Postgres, and it should not be reachable from the internet. GitHub connection is optional until you connect an account; those keys are listed in .env.example.
3. Upgrade
git pull
npm run compose:up