What you need
Platforms
Section titled “Platforms”The current native release workflow targets Linux x64 (Intel/AMD) only. Choose a host compatible with the selected package and its release notes. Native packaging is optional per release, so confirm an actual asset in the download centre before provisioning the host.
| Linux x64 package format | Filename pattern, when published |
|---|---|
| Debian package | plugboard_<version>_amd64.deb |
| RPM package | plugboard-<version>.x86_64.rpm |
Windows, macOS and Linux ARM native release targets are disabled. Source and launcher code retains platform-specific routines, but those need a separately built and validated deployment; they do not establish released installer or archive availability. See portable archive scope.
Runtime and database
Section titled “Runtime and database”| Requirement | Notes | |
|---|---|---|
| Node.js | 24.20.0 or later in the 24.x line | Source installs; use the repository’s declared engine range. Native packages carry their own runtime |
| pnpm | 10.34.5 for 0.12.0-rc.3 | Source installs; use the exact packageManager version and lockfile from the release being built |
| PostgreSQL | 14 or later | 16 is what CI tests against. The bundle carries its own |
| Redis | Optional | Only the legacy people-sync and digest worker use it |
| Object storage | Optional | S3-compatible. MinIO locally, S3 in cloud. Only for logos, photos and exports |
If you are running the bundle, none of the above needs to exist on the machine first.
| Port | Process | Exposure |
|---|---|---|
| 3000 | Web | Behind your proxy, or direct on a trusted LAN |
| 4000 | API | Behind your proxy, or direct on a trusted LAN |
| 443 | Reverse proxy | The only one that should face users |
| 5432 | PostgreSQL | Never exposed beyond the host or the container network |
Both application ports are configurable with WEB_PORT and API_PORT.
The Compose stack publishes nothing by default. It listens on the internal network only, and you attach an ingress profile or your own proxy.
Outbound network access
Section titled “Outbound network access”The application itself needs no outbound access to run. Connectors do, and only the ones you enable.
| If you enable | It reaches |
|---|---|
| Jamf Pro | https://yourorg.jamfcloud.com |
| Microsoft Intune | login.microsoftonline.com, graph.microsoft.com |
| Kandji | https://yourorg.api.kandji.io |
| Mosyle | managerapi.mosyle.com or businessapi.mosyle.com |
| Chrome Enterprise | oauth2.googleapis.com, admin.googleapis.com |
| Google Workspace or Sheets | oauth2.googleapis.com, gmail.googleapis.com, sheets.googleapis.com |
| Zendesk | https://yourorg.zendesk.com |
| Twilio | api.twilio.com |
| Salesforce | https://yourorg.my.salesforce.com |
| ThreatLocker | Your ThreatLocker portal API |
| Apple GSX, CompNow, Dell | The vendor endpoint you configure |
| Automatic updates | The update and download service |
| Usage telemetry | Your telemetry endpoint, if licensed and not disabled |
Connectors that reach systems on your own network instead of the internet are LDAP and Active Directory, Synergetic, Web Help Desk, PaperCut and printers over SNMP. A self-hosted install on the same network reaches them directly.
Outbound fetch guard
Section titled “Outbound fetch guard”Plugboard blocks outbound requests to private, loopback and link-local addresses by default, so a URL you type into a service monitor or webhook cannot reach an internal host.
An on-premises install that monitors LAN addresses has to opt out:
ALLOW_PRIVATE_EGRESS=1Leave it off if your deployment serves more than one institution. See the security model.
Nothing emails anyone until an email connector exists. Repair tracking links, ready-for-collection notices, purchase receipts, monitor alerts, backup failure alerts and scheduled reports all go through it.
You need either an SMTP server you can authenticate to, or a Google Workspace service account with domain-wide delegation. See SMTP and Google Workspace.
Certificates
Section titled “Certificates”HTTPS is expected. The application starts without it and says so in the log, which is enough for a first look on the machine itself. Anything a staff member reaches needs a certificate.
Any of these work:
- A public certificate from Let’s Encrypt, issued automatically by the bundled Caddy profile.
- A wildcard you already own.
- A certificate from your school’s internal CA, including Active Directory Certificate Services.
- A PKCS#12 file, which is what most Windows tooling produces.
SLA calculations, scheduled backups, the overnight update check, TOTP two-factor codes and licence expiry all read the machine’s clock. Run NTP.
The overnight update check uses the machine’s own local time, so a server set to
UTC in a school in Sydney will update at 1am UTC, which is the middle of the
school day. Either fix the timezone or set AUTO_UPDATE_HOUR.
Antivirus
Section titled “Antivirus”Endpoint protection that scans every file write makes the database slow. Exclude
the data directory, .pgdata in the install directory, if you can.