Skip to main content
On the embedded (default) tier, Conduit runs anywhere that can provide three things:
  1. One container instance — never more than one against the same data directory. (Multiple instances are the PostgreSQL active-active tier — see Deployment Tiers.)
  2. Persistent block storage mounted at /data. Local disks and network block devices (EBS, GCE PD, Azure Disk) are fine; network filesystems (NFS, EFS, Azure Files, GCS/S3 mounts) are not safe for the embedded database.
  3. An HTTPS URL reaching port 7272, set as CONDUIT_BASE_URL — either a TLS-terminating proxy in front, or native TLS via CONDUIT_TLS_CERT_FILE/CONDUIT_TLS_KEY_FILE.
With CONDUIT_DATABASE_URL set, requirements 1 and 2 disappear (state lives in PostgreSQL), which also makes the scale-to-zero platforms below viable — as long as exactly-one-at-a-time isn’t assumed anywhere else in your setup. Plus, in every case: back up the data volume, and keep the encryption key stored separately from those backups.

Docker Compose

Put a TLS-terminating reverse proxy (Caddy, Traefik, nginx) in front, or add the native-TLS env vars and mount the certificate.

A plain VM

Run the container under the init system so it survives reboots — e.g. podman generate systemd, or a systemd unit wrapping docker run with --restart unless-stopped and a named volume. Snapshot the VM disk (or the volume) for backups.

Fly.io

A good fit: Fly volumes are single-attach block storage, matching Conduit’s model exactly.
Keep exactly one machine (fly scale count 1) and set the encryption key with fly secrets set CONDUIT_ENCRYPTION_KEY=....

Platforms that don’t fit

Serverless container platforms that scale to zero, run concurrent instances, or offer only network-filesystem/object storage (Cloud Run, App Runner, Azure Container Apps in consumption mode, ECS on Fargate with EFS) violate requirements 1 or 2 — Conduit will appear to work and then corrupt data or enforce stale policy under exactly the conditions those platforms create. On ECS, use the EC2 launch type with an EBS-backed volume and a service capped at one task; on anything else, prefer a VM or Kubernetes.