Install it on a server
CrewHall runs as four containers on one machine: Caddy serving the app and terminating HTTPS, the API, Postgres, and optionally a runner that gives agents their workspaces. One modest VPS is enough to start: 2 vCPU, 4 GB of memory, 40 GB of disk, Debian or Ubuntu LTS.
The images are built and published for you; the server pulls them and never compiles anything.
One command
Copy the deployment kit from the repository to the server and run it as root:
scp -r deploy/vps root@your-server:/tmp/crewhall-kit
ssh root@your-server '/tmp/crewhall-kit/provision.sh'It installs Docker, allows only SSH and the web through the firewall, turns on unattended security updates, puts the kit in /opt/crewhall, and installs two timers: a check for a new image every five minutes, and a nightly backup.
--dry-run prints what it would do without doing it. --every 15min checks less often, --no-firewall leaves your firewall alone.
Point the domain at it
One A record, from your domain to the server's IPv4 address (and an AAAA record if it has IPv6). Caddy asks Let's Encrypt for the certificate on first start, which only works once the name resolves, so check with dig +short your-domain before going on.
Start it
cd /opt/crewhall
./setup.sh # generates the secrets into .env, then stops
./setup.sh # after you have checked that file, starts everythingThe first run writes .env with a freshly generated database password, master key and admin password, readable only by root. Check these before the second run:
CREWHALL_PUBLIC_URL—https://your-domainCREWHALL_SITE_ADDRESS—your-domainCREWHALL_ADMIN_EMAIL— the first accountCREWHALL_IMAGE_TAG— a released version, e.g.0.1.0
Then open your domain and sign in as that address; the password is in .env, and you have to change it immediately.
Back up the master key now
CREWHALL_MASTER_KEY decrypts every provider key and integration token. Copy it into your password manager before you do anything else. A database backup without it restores an installation whose keys cannot be read, and nobody can recover it for you.
Agent workspaces
The runner that gives agents a Linux workspace holds the Docker socket, which is root on that machine. It is therefore off unless you ask for it:
# in .env
CREWHALL_RUNNER_URL=http://runner:9000
docker compose -f compose.prod.yml --profile workspaces up -dThen offer "Workspace shell" in Platform → Tools. See Tools for what it does and what bounds it.
