What lives on the host

Paths on this page are relative to the install directory.

Names on your host

The other Quickstart pages use the descriptive names in the first column. Docker Compose prefixes each volume with the project name, which is the install directory's name. Install elsewhere and the volume prefix changes. The container names and the network stay the same.

Descriptive nameReal name on the hostNotes
The install directory/opt/delamainThe Installer's Compose file, its optional .env and deployment/
The Installer's backend containerdelamain-backendThe screens, the API and the deploy engine. Also its alias on the shared network
The Installer's database containerdelamain-postgresPostgreSQL 16
The one-shot migration containerdelamain-backend-initApplies database migrations, then exits with code 0
The Installer's update helperdelamain-self-updaterRuns only during the Installer's own update. Its log stays after it exits
The Installer's secrets volumedelamain_delamain_secretsjwt.secret, encr.key, pg.pass, curato.token
The Installer's database volumedelamain_pgdataThe PostgreSQL data directory: users, configuration, audit trail, job history
The Installer's databasedelamainPOSTGRES_DATABASE_NAME. Inside the database container it is POSTGRES_DB
The Installer's temporary directory/var/tmp/delamainTMPDIR. The Installer's update stages its Compose file in self-update/. Needs no backup
The shared Docker networkunistreamCreated once with docker network create unistream. Shared with DataMind OS
The DataMind container registryunistream.azurecr.ioWhere the Installer's and DataMind OS images come from
The Installer's imageunistream.azurecr.io/delamain:<VERSION>DELAMAIN_IMAGE. The Installer's update tags the previous build :rollback
The Installer's release channelprodDELAMAIN_CHANNEL
The Installer's session cookiesdelamain_access_token, delamain_refresh_tokenSet in the browser at sign-in

Check it worked.

bash
docker ps -a --format '{{.Names}}' | grep '^delamain-'
docker volume ls --format '{{.Name}}' | grep '^delamain_'
docker network ls --format '{{.Name}}' | grep -x unistream

The first command lists the three containers, plus the update helper once an Installer update has run. The second prints the two volumes. The third prints the network.

The files

PathWhat it isWritten by
docker-compose.ymlThe Installer's own stackYou at install. Replaced by the Installer's own update
docker-compose.yml.pre-updateThe previous Compose fileThe Installer's own update, before it switches
.self-update-statusThe last Installer update's outcome: ok, rolled-back or failedThe Installer's own update
.envThe Installer's own settings. Optional: without it the defaults below applyYou
deployment/docker-compose.ymlThe DataMind OS stack, as publishedThe Installer. Replaced by every DataMind OS update
deployment/.env.unified.templateThe DataMind OS settings template, as publishedThe Installer. Replaced by every DataMind OS update
deployment/.envThe settings DataMind OS runs withThe Installer. Rewritten on every save, install and update
deployment/apply-memory-slices.shThe script that applies the memory limits on the hostThe Installer. Replaced by every DataMind OS update
deployment/docker-compose.override.ymlYour own changes to the DataMind OS stackYou only. The Installer adds it to every Compose command when it exists
Important

Put changes to the DataMind OS stack in deployment/docker-compose.override.yml. A hand edit to a file the Installer writes is replaced at the next update or save.

Protect deployment/.env as Protect the deployment's environment file describes. What to back up is on Backup and restore.

The Installer's own settings

Settings you can change in .env

Create .env beside the Installer's Compose file when you need one of these.

VariableDefaultWhat it controls
VERSIONprod-latestThe image tag the Installer runs. See VERSION and the Installer's own update
NEST_PORT8000The port the Installer listens on. Keep the default: DataMind OS reaches the Installer on this port over the shared network
NEST_NODE_ENVprodprod or dev. dev adds debug logging and returns real error messages instead of Internal server error. Any other value stops the Installer from starting
SWAGGER_ENABLEDofftrue or 1 serves the API description at /api/docs
JWT_ACCESS_EXPIRY1hHow long an access token lives
JWT_REFRESH_EXPIRY7dHow long a browser stays signed in without activity
DOCKER_SOCK/var/run/docker.sockThe host's Docker socket, mounted into the Installer. A rootless host uses /run/user/<uid>/docker.sock
POSTGRES_USERpostgresThe database role. Fixed after the first start
POSTGRES_DATABASE_NAMEdelamainThe database name. Fixed after the first start

Settings fixed in the Compose file

The Compose file's environment: block sets these and overrides .env: POSTGRES_HOST (postgres), POSTGRES_PORT (5432), DEPLOYMENT_DIR (/usr/src/app/deployment), TMPDIR, the image and channel settings, AZURE_TENANT_ID and AZURE_CLIENT_ID. The Azure client secret is entered on the screen and stored encrypted in the Installer's database.

Secrets read from the volume

On every start the Installer reads these values from the secrets volume. A value in .env is overwritten.

VariableFileCreated byWhat it is
JWT_SECRETjwt.secretThe Installer, on first startThe session signing key
NEST_ENCR_KEYencr.keyThe Installer, on first startThe key that encrypts stored secrets
CURATO_SERVICE_TOKENcurato.tokenThe Installer, on first startThe token DataMind OS uses to call the Installer. Also written to deployment/.env
POSTGRES_PASSpg.passThe database container, on first startThe Installer's database password

Each file has mode 0600. If one goes missing:

File missingEffect
pg.passThe database container writes a new password that the existing database does not accept, so the Installer cannot connect and restarts in a loop. The data stays intact. Restore the file from your backup, see Troubleshooting
jwt.secretA new key is generated and every user is signed out
encr.keyA new key is generated, and the encrypted settings can no longer be read. Restore the file from your backup. See the encr.key warning
curato.tokenA new token is generated. DataMind OS reaches the Installer again once deployment/.env is rewritten and its services are recreated

VERSION and the Installer's own update

The Installer's own update runs the tag prod-latest for that one command. It never writes VERSION to .env.

Your .envWhat happens
No VERSIONEvery update and every docker compose command runs prod-latest
VERSION pinned to a tagThe update runs prod-latest. The next docker compose up -d backend returns to your pinned tag

Leave VERSION unset and update from the Installer pill.

Change a setting

Edit .env, then recreate the Installer:

bash
cd /opt/delamain
docker compose up -d backend

Check it worked.

bash
docker compose ps
docker exec delamain-backend printenv JWT_ACCESS_EXPIRY

The Installer's backend container shows (healthy), and printenv prints the value you set.

Questions, answered

Does a DataMind OS update overwrite my changes?

It replaces the published Compose file and template, and rewrites deployment/.env. Your override file, your .env and the volumes are kept.

Can I set JWT_SECRET or POSTGRES_PASS in .env?

No. The Installer reads both from the secrets volume on every start. Remove them from .env if they are there.

How do I sign every user out at once?

Delete jwt.secret from the secrets volume and restart the Installer. It generates a new signing key, and every session ends.

bash
docker exec delamain-backend rm /usr/src/app/secrets/jwt.secret
cd /opt/delamain && docker compose restart backend