Why this Configuration?
- True Data Sovereignty: 100% GDPR-compliant on-premises deployment. You own your configuration and data without vendor lock-in.
- Hardware Agnostic: Optimized and verified across low-power ARM64 SBCs (Raspberry Pi 5) and x86_64 hypervisors (Proxmox VE LXC & VM).
- Engine Freedom: Tested and supported under standard Docker Engine and unprivileged rootless Podman.
- Platform Verification: Rootless and distroless. Provides web UI and MCP server.
Quick Start (Standalone Docker Compose)
The snippet below is immediately ready to run in any standard Docker or Podman environment:
services:
hatchdoor:
image: battermanz/hatchdoor:latest
container_name: njorddeploy-hatchdoor
restart: unless-stopped
ports:
- "42824:42824"
environment:
- "HOST=0.0.0.0"
- "PORT=42824"
- "VAULT_PATH=/data/vault"
- "HATCHDOOR_CACHE_DB=/data/cache/hatchdoor-cache.sqlite3"
volumes:
- "./data/hatchdoor/vault:/data/vault"
- "./data/hatchdoor/cache:/data/cache"
networks:
- njorddeploy_net
networks:
njorddeploy_net:
Start the service directly via the command line: docker compose up -d
Configuration & Environment Variables
Key configuration parameters and defaults derived from the NjordDeploy component template:
| Variable | Default Value | Description |
|---|---|---|
PORT_HATCHDOOR |
42824 |
Port to access the Hatchdoor Web UI and MCP endpoint. |
HATCHDOOR_VAULT_PATH |
/opt/njorddeploy/data/hatchdoor/vault |
Host path containing Markdown notes and documents. |
HATCHDOOR_CACHE_PATH |
/opt/njorddeploy/data/hatchdoor/cache |
Host path for storing generated SQLite search cache. |
Ecosystem & Enterprise Integration
- Reverse Proxy Ingress Ready: Pre-configured for Caddy, Traefik, or Nginx Proxy Manager with automatic Let's Encrypt TLS certificates.
- Zero-Trust Mesh VPN: Seamless integration with WireGuard or Tailscale/Headscale mesh networks for secure remote administration.
- Transactional State Backups: Ready for point-in-time database dumps and container-safe persistent volume freezing.
Effortless Management with NjordDeploy
Deploy, monitor, and update this service with a single click on your own hardware via the NjordDeploy Configurator.