> ## Documentation Index
> Fetch the complete documentation index at: https://pipedream.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Install & Run

> Run Conduit with Docker in minutes.

Conduit ships as a single Docker image with embedded storage — no external
database or services required. Mount one volume for persistence and you're
running. This page covers the plain `docker run` path; for clusters and
other hosts see [Kubernetes](/docs/conduit/deploy/kubernetes) (Helm chart or raw manifests)
and [Other platforms](/docs/conduit/deploy/other-platforms), and pick a shape on
[Deployment Tiers](/docs/conduit/deploy/availability).

<Steps>
  <Step title="Start the container">
    ```sh theme={null}
    docker run -d --name conduit \
      -p 7272:7272 \
      -v conduit-data:/data \
      -e CONDUIT_BASE_URL=https://conduit.example.com \
      ghcr.io/pipedreamhq/conduit:stable
    ```

    `CONDUIT_BASE_URL` is the externally reachable URL of your instance — it's
    used for OAuth callbacks and MCP discovery, so set it to the address your
    users and AI clients will actually reach.
  </Step>

  <Step title="Sign in and finish setup">
    On first boot, Conduit prints first-run admin credentials to the container
    logs (`docker logs conduit`). Open `/login`, sign in with them, and the
    setup wizard walks you through creating your admin account.

    To choose your own bootstrap credentials instead, set
    `CONDUIT_ADMIN_EMAIL` and `CONDUIT_ADMIN_PASSWORD` (nothing is printed
    then).
  </Step>

  <Step title="Back up your encryption key">
    Conduit encrypts stored secrets (IdP client secrets, SMTP credentials,
    connector tokens) with a key auto-generated at `/data/conduit.key` on
    first boot. **Back this file up** — without it, stored secrets are
    unrecoverable. To manage the key yourself and keep it out of data-volume
    backups, set `CONDUIT_ENCRYPTION_KEY` instead.
  </Step>
</Steps>

## Choosing an image tag

* **`vX.Y.Z`** — a specific release. Pin this in production and upgrade
  deliberately.
* **`stable`** — the newest release. Convenient for evaluation.
* Avoid **`latest`** — it tracks unreleased development, not the newest
  release.

If your environment can't pull from `ghcr.io`, mirror the image into your
own registry (see
[private registries](/docs/conduit/deploy/kubernetes#private-registries-and-air-gapped-installs))
or [build it from source](/docs/conduit/deploy/build-from-source).

## Upgrading

Pull the new tag and recreate the container; the data volume carries
everything over. Database migrations run automatically on boot. Before
upgrading, read the [changelog](/docs/conduit/changelog#unreleased) for the releases
you're jumping across — the **Upgrade notes** section of each release lists
anything that needs operator action.

## TLS

The default deployment runs plain HTTP behind a TLS-terminating reverse
proxy, with `CONDUIT_BASE_URL` set to the `https://` address. To have Conduit
terminate TLS natively instead, set `CONDUIT_TLS_CERT_FILE` and
`CONDUIT_TLS_KEY_FILE`. AI clients require HTTPS for OAuth, so one or the
other is effectively mandatory for real use.

## What the fronting proxy is responsible for

Conduit defends itself against the abuse it can see per request: every request
body is size-capped, headers and request reads are on timeouts
(`ReadHeaderTimeout`, `ReadTimeout`, `IdleTimeout`), and expensive pre-auth work
sits behind per-IP rate limits.

It does **not** bound response writes. `WriteTimeout` is deliberately unset,
because a response deadline would sever the long-lived `/mcp` SSE streams that
AI clients hold open for the duration of a session. A client that requests
responses and then drains them a byte at a time therefore holds connection
state for as long as it likes.

Volumetric abuse — connection floods, slow-read clients, request rates far
above what per-IP limits are meant for — is the fronting proxy's job. If you
expose Conduit's port directly to untrusted networks, you are giving up that
layer. Behind a proxy, also set
[`CONDUIT_TRUSTED_PROXIES`](/docs/conduit/configure/reference#client-ip-attribution)
so per-IP rate limiting sees real client addresses instead of the proxy's.

See the [configuration reference](/docs/conduit/configure/reference) for every
setting.
