docker run path; for clusters and
other hosts see Kubernetes (Helm chart or raw manifests)
and Other platforms, and pick a shape on
Deployment Tiers.
1
Start the container
CONDUIT_BASE_URL is the externally reachable URL of your instance — it’s
used for OAuth callbacks and MCP discovery, so set it to the address your
users and AI clients will actually reach.2
Sign in and finish setup
On first boot, Conduit prints first-run admin credentials to the container
logs (
docker logs conduit). Open /login, sign in with them, and the
setup wizard walks you through creating your admin account.To choose your own bootstrap credentials instead, set
CONDUIT_ADMIN_EMAIL and CONDUIT_ADMIN_PASSWORD (nothing is printed
then).3
Back up your encryption key
Conduit encrypts stored secrets (IdP client secrets, SMTP credentials,
connector tokens) with a key auto-generated at
/data/conduit.key on
first boot. Back this file up — without it, stored secrets are
unrecoverable. To manage the key yourself and keep it out of data-volume
backups, set CONDUIT_ENCRYPTION_KEY instead.Choosing an image tag
vX.Y.Z— a specific release. Pin this in production and upgrade deliberately.stable— the newest release. Convenient for evaluation.- Avoid
latest— it tracks unreleased development, not the newest release.
ghcr.io, mirror the image into your
own registry (see
private registries)
or build it from source.
Upgrading
Pull the new tag and recreate the container; the data volume carries everything over. Database migrations run automatically on boot. Before upgrading, read the changelog for the releases you’re jumping across — the Upgrade notes section of each release lists anything that needs operator action.TLS
The default deployment runs plain HTTP behind a TLS-terminating reverse proxy, withCONDUIT_BASE_URL set to the https:// address. To have Conduit
terminate TLS natively instead, set CONDUIT_TLS_CERT_FILE and
CONDUIT_TLS_KEY_FILE. AI clients require HTTPS for OAuth, so one or the
other is effectively mandatory for real use.
What the fronting proxy is responsible for
Conduit defends itself against the abuse it can see per request: every request body is size-capped, headers and request reads are on timeouts (ReadHeaderTimeout, ReadTimeout, IdleTimeout), and expensive pre-auth work
sits behind per-IP rate limits.
It does not bound response writes. WriteTimeout is deliberately unset,
because a response deadline would sever the long-lived /mcp SSE streams that
AI clients hold open for the duration of a session. A client that requests
responses and then drains them a byte at a time therefore holds connection
state for as long as it likes.
Volumetric abuse — connection floods, slow-read clients, request rates far
above what per-IP limits are meant for — is the fronting proxy’s job. If you
expose Conduit’s port directly to untrusted networks, you are giving up that
layer. Behind a proxy, also set
CONDUIT_TRUSTED_PROXIES
so per-IP rate limiting sees real client addresses instead of the proxy’s.
See the configuration reference for every
setting.