Deploying the intranet
The intranet always runs as a container — Docker or Podman. There is no VM/bare-metal install path: the image bundles the SvelteKit server, the background worker, and the migration/seed tooling. The only external dependency is PostgreSQL and an OIDC provider (Authentik) for sign-in.
Audience
This section is for whoever deploys and operates the service. The rest of the guide (Getting started, Engineer, Reviewer, …) is for end users.
What runs
The stack is a handful of containers built from one image:
| Container | Command | Role |
|---|---|---|
db | postgres:16-alpine | Database (bundled for convenience) |
migrate | pnpm db:migrate | Applies migrations once, then exits |
app | node build | Web server on port 3000 |
worker | node --import tsx src/worker/index.ts | Transactional-outbox dispatcher |
app and worker start only after migrate completes successfully.
Requirements
- Docker Engine 24+ with Compose v2, or Podman 4+ with
podman compose. - PostgreSQL 16 — the compose file bundles one, but any reachable Postgres
works; set
DATABASE_URL. - An OIDC provider. The reference provider is Authentik; any OIDC/OAuth2 provider works (see Single sign-on).
- Outbound network from the container to the provider.
- For production: a TLS-terminating reverse proxy and a hostname.
Node, pnpm, or Postgres are not needed on the host.
Image properties
- Built with
@sveltejs/adapter-node(ADAPTER=node), served bynode build. - Runs as the non-root
nodeuser. - Exposes port
3000; healthcheck pollsGET /login. - Contains the worker and migration/seed entrypoints (overridden per service).
Read next
- Quick start — stand up a local stack.
- Configuration — every environment variable.
- Single sign-on with Authentik.
- Production hardening and Operations.