Skip to content

What you need

The current native release workflow targets Linux x64 (Intel/AMD) only. Choose a host compatible with the selected package and its release notes. Native packaging is optional per release, so confirm an actual asset in the download centre before provisioning the host.

Linux x64 package format Filename pattern, when published
Debian package plugboard_<version>_amd64.deb
RPM package plugboard-<version>.x86_64.rpm

Windows, macOS and Linux ARM native release targets are disabled. Source and launcher code retains platform-specific routines, but those need a separately built and validated deployment; they do not establish released installer or archive availability. See portable archive scope.

Requirement Notes
Node.js 24.20.0 or later in the 24.x line Source installs; use the repository’s declared engine range. Native packages carry their own runtime
pnpm 10.34.5 for 0.12.0-rc.3 Source installs; use the exact packageManager version and lockfile from the release being built
PostgreSQL 14 or later 16 is what CI tests against. The bundle carries its own
Redis Optional Only the legacy people-sync and digest worker use it
Object storage Optional S3-compatible. MinIO locally, S3 in cloud. Only for logos, photos and exports

If you are running the bundle, none of the above needs to exist on the machine first.

Port Process Exposure
3000 Web Behind your proxy, or direct on a trusted LAN
4000 API Behind your proxy, or direct on a trusted LAN
443 Reverse proxy The only one that should face users
5432 PostgreSQL Never exposed beyond the host or the container network

Both application ports are configurable with WEB_PORT and API_PORT.

The Compose stack publishes nothing by default. It listens on the internal network only, and you attach an ingress profile or your own proxy.

The application itself needs no outbound access to run. Connectors do, and only the ones you enable.

If you enable It reaches
Jamf Pro https://yourorg.jamfcloud.com
Microsoft Intune login.microsoftonline.com, graph.microsoft.com
Kandji https://yourorg.api.kandji.io
Mosyle managerapi.mosyle.com or businessapi.mosyle.com
Chrome Enterprise oauth2.googleapis.com, admin.googleapis.com
Google Workspace or Sheets oauth2.googleapis.com, gmail.googleapis.com, sheets.googleapis.com
Zendesk https://yourorg.zendesk.com
Twilio api.twilio.com
Salesforce https://yourorg.my.salesforce.com
ThreatLocker Your ThreatLocker portal API
Apple GSX, CompNow, Dell The vendor endpoint you configure
Automatic updates The update and download service
Usage telemetry Your telemetry endpoint, if licensed and not disabled

Connectors that reach systems on your own network instead of the internet are LDAP and Active Directory, Synergetic, Web Help Desk, PaperCut and printers over SNMP. A self-hosted install on the same network reaches them directly.

Plugboard blocks outbound requests to private, loopback and link-local addresses by default, so a URL you type into a service monitor or webhook cannot reach an internal host.

An on-premises install that monitors LAN addresses has to opt out:

Terminal window
ALLOW_PRIVATE_EGRESS=1

Leave it off if your deployment serves more than one institution. See the security model.

Nothing emails anyone until an email connector exists. Repair tracking links, ready-for-collection notices, purchase receipts, monitor alerts, backup failure alerts and scheduled reports all go through it.

You need either an SMTP server you can authenticate to, or a Google Workspace service account with domain-wide delegation. See SMTP and Google Workspace.

HTTPS is expected. The application starts without it and says so in the log, which is enough for a first look on the machine itself. Anything a staff member reaches needs a certificate.

Any of these work:

  • A public certificate from Let’s Encrypt, issued automatically by the bundled Caddy profile.
  • A wildcard you already own.
  • A certificate from your school’s internal CA, including Active Directory Certificate Services.
  • A PKCS#12 file, which is what most Windows tooling produces.

See HTTPS and certificates.

SLA calculations, scheduled backups, the overnight update check, TOTP two-factor codes and licence expiry all read the machine’s clock. Run NTP.

The overnight update check uses the machine’s own local time, so a server set to UTC in a school in Sydney will update at 1am UTC, which is the middle of the school day. Either fix the timezone or set AUTO_UPDATE_HOUR.

Endpoint protection that scans every file write makes the database slow. Exclude the data directory, .pgdata in the install directory, if you can.