Portainer
Deploy Bifrost on Portainer as a Compose stack.
Portainer deploys the repository's docker/compose.yaml as a Stack.
- Stacks → Add stack, and either paste the
docker/compose.yamlor use the Git repository option pointing at this repo. - Under Environment variables, set:
MASTER_KEY—openssl rand -base64 48ENCRYPTION_KEYRING— e.g.{"primary":"<openssl rand -hex 32>"}ACTIVE_ENCRYPTION_KEY_ID—primary
- Deploy the stack. Postgres, Redis and the one-off
migratejob run inside the stack; the gateway listens on internal port4000, the optional dashboard on3001and docs on3000.
The production Compose base publishes no host ports. Attach your reverse proxy to the stack network.
If the proxy runs directly on the same Docker host instead, add loopback-only mappings for gateway
(127.0.0.1:4000:4000), the dashboard (127.0.0.1:3001:3001) and optionally docs
(127.0.0.1:3000:3000) in Portainer's stack editor.
Route the dashboard on its own hostname — it is an independent app at the root of its domain, not a
path on the gateway's. It needs GATEWAY_URL pointing at the gateway on the stack network; the
gateway itself needs no domain unless you want the API published. See
Operator dashboard → Serving it.
Never publish Postgres, Redis, or migrate.
The gateway reaches Postgres/Redis over the internal stack network in plaintext, so there is no TLS handshake and no Bun TLS issue.
If you point at external instances instead, set DATABASE_URL/REDIS_URL in the stack
environment and prefer a managed provider with a public-CA certificate;
a self-signed database over a public port will not work on Bun.