- One container instance — never more than one against the same data directory. (Multiple instances are the PostgreSQL active-active tier — see Deployment Tiers.)
- Persistent block storage mounted at
/data. Local disks and network block devices (EBS, GCE PD, Azure Disk) are fine; network filesystems (NFS, EFS, Azure Files, GCS/S3 mounts) are not safe for the embedded database. - An HTTPS URL reaching port 7272, set as
CONDUIT_BASE_URL— either a TLS-terminating proxy in front, or native TLS viaCONDUIT_TLS_CERT_FILE/CONDUIT_TLS_KEY_FILE.
CONDUIT_DATABASE_URL set, requirements 1 and 2 disappear (state lives
in PostgreSQL), which also makes the scale-to-zero platforms below viable —
as long as exactly-one-at-a-time isn’t assumed anywhere else in your setup.
Plus, in every case: back up the data volume, and keep the
encryption key stored separately from those backups.
Docker Compose
A plain VM
Run the container under the init system so it survives reboots — e.g.podman generate systemd, or a systemd unit wrapping docker run with
--restart unless-stopped and a named volume. Snapshot the VM disk (or the
volume) for backups.
Fly.io
A good fit: Fly volumes are single-attach block storage, matching Conduit’s model exactly.fly scale count 1) and set the encryption key
with fly secrets set CONDUIT_ENCRYPTION_KEY=....