Browse documentation
2026-09-28AutoDataOpen in dashboard

Self-hosting with Docker

Run AutoData on your own infrastructure: image, services, volumes, settings, health check, upgrades and backups.

AutoData ships with a Dockerfile and a docker-compose.yml. By default two containers run from one image: web (API and web app) and worker (pipeline jobs). Optional profiles add PostgreSQL, Redis with Celery, and Nginx.

Quick start

cp .env.example .env
# set SECRET_KEY, ADMIN_PASSCODE and CONNECTOR_CREDENTIALS_FERNET_KEY
docker compose up --build -d
curl -s http://localhost:5000/health

Open http://localhost:5000. Then go to /admin, sign in with your admin passcode, and create user accounts.

Keep settings in the root .env only. The build copies the backend folder into the image, and only the root .env is excluded from that copy.

Services

ServiceProfilePurpose
webdefaultAPI and web app on port 5000 (host port PORT), with a health check on /health
workerdefaultRuns pipeline jobs, several at a time depending on its CPU allowance
dbpostgresPostgreSQL 16 (DB_USER, DB_PASSWORD, DB_PORT)
redis, celery_worker, beatceleryRedis-backed, multi-host job execution
nginxproxyReverse proxy on ports 80 and 443

Enable a profile with, for example, docker compose --profile postgres up -d. The image runs every stage on CPU; no GPU is needed.

Volumes

VolumeHolds
results_data (/app/results)Session outputs, and what inference and retraining replay
upload_data (/app/uploads)Uploaded media
db_data (/app/data)The SQLite database, when DATABASE_URL points there
tmp_queue (/tmp)The job queue shared by web and worker
postgres_data, redis_data, ssl_certsData for the optional profiles

Settings

Required

  • SECRET_KEY: signs sign-in sessions. If it changes, everyone is signed out.
  • ADMIN_PASSCODE: the admin passcode. In production, admin sign-in is disabled until it is set.
  • CONNECTOR_CREDENTIALS_FERNET_KEY: encrypts saved connector credentials. Generate it once and never change it.

Common

VariableDefaultPurpose
PORT5000Host port for web
FLASK_ENVproductionHTTPS-only cookies; serve over HTTPS
ALLOWED_ORIGINS—Allowed CORS origins
DATABASE_URLSQLiteUse sqlite:////app/data/datatoolpack.db, or PostgreSQL with the postgres profile
JOB_BROKER, REDIS_URLlocalUse redis or celery for several hosts
MAX_CONTENT_LENGTH5000000000Largest request, in bytes
SESSION_DIR/opt/autodata/sessionsPoint it at a volume so sign-ins survive container re-creation
APP_BASE_URL—Link base in notification emails
SMTP_HOST, SMTP_PORT, SMTP_USER, SMTP_PASSWORD, SMTP_FROM—Outgoing email for run notifications (all five needed)
DISK_OUTPUT_TTL_SECONDS604800Output file retention (7 days)
ARTIFACT_RETENTION_SECONDS31536000Whole-session retention (1 year)
LLM_ENABLED, LLM_BACKEND1, autoTurn language models off, or choose a local or OpenAI-compatible model
BILLING_ENABLED10 records costs without debiting balances
SFTP_ENABLED, SFTP_PORTfalse, 2222Built-in SFTP inboxes; publish the port yourself
FEATURE_FLAG_STREAMING, FEATURE_FLAG_TRIGGERSfalseStreaming inference and triggers
ALLOW_LOCAL_FILE_CONNECTORSoff in production1 lets a connection point at a file on this server: a file-based SQL URL or a local Delta Lake path
ALLOW_AMBIENT_CLOUD_CREDENTIALSoff in production1 lets a connection saved without cloud keys use the server's own cloud role

Health check

GET /health needs no sign-in. It returns 200 when healthy and 503 when degraded. The body reports:

  • checks for the upload folder, results folder, modules, database and broker;
  • the worker queue state;
  • whether credential encryption is enabled.

Reverse proxy

With FLASK_ENV=production, cookies are sent over HTTPS only, so put a TLS proxy in front of the containers.

  • Forward every path to web on port 5000.
  • Allow request bodies up to 5 GB and read timeouts of about 30 minutes.
  • Set X-Forwarded-For: sign-in rate limits use it.

Upgrading

  1. Back up the database and results.
  2. Make sure no job is running.
  3. Pull the new version, then run docker compose up --build -d.
  4. Check /health.

Database migrations run automatically when web starts. Keep the same SECRET_KEY and credential key. docker compose down -v deletes all volumes, and your data with them.