Docker Deployment
Lumio ships a production Docker Compose setup in the repository root. CD publishes signed backend and frontend images to GHCR for every release tag.
Configuration
Generate a root .env with fresh secrets:
npm run setup:env # or: make setup
The generated file targets development, so review it before production. Compose refuses to start without:
POSTGRES_USER,POSTGRES_PASSWORDJWT_SECRET,JWT_REFRESH_SECRETINTEGRATIONS_ENCRYPTION_KEY
Compose builds DATABASE_URL from the POSTGRES_* values. For a public deployment also set:
FRONTEND_URL(defaults tohttp://localhost:3000) orCORS_ORIGINSto the public frontend origin — the backend refuses to start in production without an allowed originAUTH_COOKIE_SAMESITE=none(HTTPS only) when the frontend and API sit on different registrable domains, andAUTH_COOKIE_DOMAINto share cookies across subdomainsMETRICS_AUTH_TOKENif you scrape/api/v1/metrics
Start services
Run the published images:
docker compose pull
docker compose up -d
Pin a release with LUMIO_IMAGE_TAG in .env. make start builds the images locally instead
(docker compose up -d --build).
This starts:
- PostgreSQL 14
- Redis 7
- NestJS backend
- Next.js frontend
Migrations run automatically when the backend starts (RUN_MIGRATIONS=true). PostgreSQL and Redis publish their
ports on 127.0.0.1 only.
Optional: receipt maps
docker compose --profile maps --profile geocoder up -d
Then set TILESERVER_URL=http://tileserver:8080 and GEOCODER_URL=http://nominatim:8080 for the backend and
restart it. MAP_PBF_URL selects the OpenStreetMap extract. See Receipt Maps.