Skip to content

Docker Compose

The Compose deployment runs Flow-Like on one Linux Docker host. It bundles PostgreSQL, authenticated Redis and RustFS object storage. Its default execution mode gives each run a fresh gVisor sandbox, supervised by a native Rust manager.

Use Compose when one host meets your capacity and recovery requirements. Adding replicas increases process capacity on that host; it does not provide host failover.

Browser and desktop clients reach the web app, API and signaling through the edge proxy. API replicas share the database, Redis and object storage.

Interactive executions go through the internal execution gateway to a manager. Background executions enter Redis; queue bridges consume them and dispatch to the same managers. A queue bridge runs no workflow code in the default mode.

Each manager prepares an inventory of unused runner and gateway containers. Preparation initializes trusted runtime code before a request arrives. After reserving a slot, the manager supplies one signed dispatch, streams its events, then destroys the containers. The next execution receives a different sandbox.

The runner has no container network. It reaches its permitted callback routes, object buckets and configured HTTPS integrations through its own Unix socket proxy. See Execution Backends for the isolation boundary and integration limits.

ComponentResponsibility
Edge proxy, web, API and signalingClient access, authentication and collaboration
Execution managers and queue bridgesAdmission, background dispatch, supervision and cancellation
Disposable runners and gatewaysOne execution and its permitted outbound traffic
CompilerBounded HTTP compilation of custom WASM nodes
PostgreSQL and db-initApplication metadata and gated schema initialization
RedisQueues, execution state, caches and signaling coordination
RustFS and storage bootstrapPrivate object buckets and scoped temporary credentials
Sink servicesSchedules and configured event adapters

The optional monitoring profile adds Prometheus, Grafana, Tempo and datastore exporters.

Follow Prerequisites and Installation. Setup generates a private environment file, pins the published ghcr.io/rheosoph images by digest, then checks the host before starting services. Building images locally remains available for modified or unpublished code.

For a separate installation containing only trusted internal workflows, setup-env.py --mode trusted enables shared workers. That mode does not isolate hostile tenants per execution.

  • Configuration explains environment variables and public URLs.
  • Storage covers RustFS, signing endpoints and external storage.
  • Inbound email adds Postfix for inbound email events.
  • Scaling separates active capacity from warm reserves.
  • Monitoring describes collection and alert delivery.
  • Troubleshooting covers admission, storage and recovery failures.