Paths on this page are relative to the install directory.
The other Quickstart pages use the descriptive names in the first column. Docker Compose prefixes each volume with the project name, which is the install directory's name. Install elsewhere and the volume prefix changes. The container names and the network stay the same.
| Descriptive name | Real name on the host | Notes |
|---|---|---|
| The install directory | / | The Installer's Compose file, its optional . and deployment/ |
| The Installer's backend container | delamain-backend | The screens, the API and the deploy engine. Also its alias on the shared network |
| The Installer's database container | delamain-postgres | PostgreSQL 16 |
| The one-shot migration container | delamain-backend-init | Applies database migrations, then exits with code 0 |
| The Installer's update helper | delamain-self-updater | Runs only during the Installer's own update. Its log stays after it exits |
| The Installer's secrets volume | delamain_delamain_secrets | jwt., encr., pg., curato. |
| The Installer's database volume | delamain_pgdata | The PostgreSQL data directory: users, configuration, audit trail, job history |
| The Installer's database | delamain | POSTGRES_DATABASE_NAME. Inside the database container it is POSTGRES_DB |
| The Installer's temporary directory | / | TMPDIR. The Installer's update stages its Compose file in self-update/. Needs no backup |
| The shared Docker network | unistream | Created once with docker network create unistream. Shared with DataMind OS |
| The DataMind container registry | unistream. | Where the Installer's and DataMind OS images come from |
| The Installer's image | unistream. | DELAMAIN_IMAGE. The Installer's update tags the previous build :rollback |
| The Installer's release channel | prod | DELAMAIN_CHANNEL |
| The Installer's session cookies | delamain_access_token, delamain_refresh_token | Set in the browser at sign-in |
Check it worked.
docker ps -a --format '{{.Names}}' | grep '^delamain-'
docker volume ls --format '{{.Name}}' | grep '^delamain_'
docker network ls --format '{{.Name}}' | grep -x unistreamThe first command lists the three containers, plus the update helper once an Installer update has run. The second prints the two volumes. The third prints the network.
| Path | What it is | Written by |
|---|---|---|
docker-compose. | The Installer's own stack | You at install. Replaced by the Installer's own update |
docker-compose. | The previous Compose file | The Installer's own update, before it switches |
. | The last Installer update's outcome: ok, rolled-back or failed | The Installer's own update |
. | The Installer's own settings. Optional: without it the defaults below apply | You |
deployment/ | The DataMind OS stack, as published | The Installer. Replaced by every DataMind OS update |
deployment/ | The DataMind OS settings template, as published | The Installer. Replaced by every DataMind OS update |
deployment/ | The settings DataMind OS runs with | The Installer. Rewritten on every save, install and update |
deployment/ | The script that applies the memory limits on the host | The Installer. Replaced by every DataMind OS update |
deployment/ | Your own changes to the DataMind OS stack | You only. The Installer adds it to every Compose command when it exists |
Put changes to the DataMind OS stack in deployment/. A hand edit to a
file the Installer writes is replaced at the next update or save.
Protect deployment/ as
Protect the deployment's environment file
describes. What to back up is on Backup and restore.
. envCreate . beside the Installer's Compose file when you need one of these.
| Variable | Default | What it controls |
|---|---|---|
VERSION | prod-latest | The image tag the Installer runs. See VERSION and the Installer's own update |
NEST_PORT | 8000 | The port the Installer listens on. Keep the default: DataMind OS reaches the Installer on this port over the shared network |
NEST_NODE_ENV | prod | prod or dev. dev adds debug logging and returns real error messages instead of Internal server error. Any other value stops the Installer from starting |
SWAGGER_ENABLED | off | true or 1 serves the API description at / |
JWT_ACCESS_EXPIRY | 1h | How long an access token lives |
JWT_REFRESH_EXPIRY | 7d | How long a browser stays signed in without activity |
DOCKER_SOCK | / | The host's Docker socket, mounted into the Installer. A rootless host uses / |
POSTGRES_USER | postgres | The database role. Fixed after the first start |
POSTGRES_DATABASE_NAME | delamain | The database name. Fixed after the first start |
The Compose file's environment: block sets these and overrides .: POSTGRES_HOST (postgres),
POSTGRES_PORT (5432), DEPLOYMENT_DIR (/), TMPDIR, the image and
channel settings, AZURE_TENANT_ID and AZURE_CLIENT_ID. The Azure client secret is entered on the
screen and stored encrypted in the Installer's database.
On every start the Installer reads these values from the secrets volume. A value in . is
overwritten.
| Variable | File | Created by | What it is |
|---|---|---|---|
JWT_SECRET | jwt. | The Installer, on first start | The session signing key |
NEST_ENCR_KEY | encr. | The Installer, on first start | The key that encrypts stored secrets |
CURATO_SERVICE_TOKEN | curato. | The Installer, on first start | The token DataMind OS uses to call the Installer. Also written to deployment/ |
POSTGRES_PASS | pg. | The database container, on first start | The Installer's database password |
Each file has mode 0600. If one goes missing:
| File missing | Effect |
|---|---|
pg. | The database container writes a new password that the existing database does not accept, so the Installer cannot connect and restarts in a loop. The data stays intact. Restore the file from your backup, see Troubleshooting |
jwt. | A new key is generated and every user is signed out |
encr. | A new key is generated, and the encrypted settings can no longer be read. Restore the file from your backup. See the encr. warning |
curato. | A new token is generated. DataMind OS reaches the Installer again once deployment/ is rewritten and its services are recreated |
The Installer's own update runs the tag prod-latest for that one command. It never writes VERSION
to ..
Your . | What happens |
|---|---|
No VERSION | Every update and every docker compose command runs prod-latest |
VERSION pinned to a tag | The update runs prod-latest. The next docker compose up -d backend returns to your pinned tag |
Leave VERSION unset and update from the Installer pill.
Edit ., then recreate the Installer:
cd /opt/delamain docker compose up -d backend
Check it worked.
docker compose ps docker exec delamain-backend printenv JWT_ACCESS_EXPIRY
The Installer's backend container shows (healthy), and printenv prints the value you set.
It replaces the published Compose file and template, and rewrites deployment/. Your
override file, your . and the volumes are kept.
No. The Installer reads both from the secrets volume on every start. Remove them from . if
they are there.
Delete jwt. from the secrets volume and restart the Installer. It generates a new signing
key, and every session ends.
docker exec delamain-backend rm /usr/src/app/secrets/jwt.secret cd /opt/delamain && docker compose restart backend