Skip to main content

Self-hosting

GOAT is open source, and you can run it on your own infrastructure. This section explains two ways to do that: Docker Compose on a single server, and Kubernetes with Helm.

Community-supported

Self-hosted deployments are community-supported. We do not offer official support for managing your infrastructure. If you would rather not run GOAT yourself, use the hosted version at goat.plan4better.de.

What GOAT consists of​

GOAT is not one program but a set of services that work together. Both deployment options run the same GOAT images, which are published publicly at ghcr.io/plan4better/goat.

ComponentWhat it does
Web appThe user interface you open in the browser.
Core APIUsers, organizations, teams, projects, folders and the metadata of your datasets.
GeoAPIServes the data of your layers as OGC API Features and vector tiles.
ProcessesStarts analyses, imports and other jobs (OGC API Processes) and reports their status.
CatalogThe GOAT data catalog, served as a STAC API.
KeycloakLogin and user accounts.
PostgreSQL with PostGISThe databases of GOAT, Keycloak and Windmill.
GarageS3-compatible object storage for uploaded files and images.
WindmillThe job engine. Its workers run the analysis tools, dataset imports, PDF printing and scheduled tasks.
RedisA cache for the GeoAPI.
CaddyThe reverse proxy in front of everything. It is the only entry point and takes care of HTTPS.

Which option?​

Docker ComposeKubernetes (Helm)
Runs onOne Linux serverA Kubernetes cluster you already operate
IncludedEverything in the table above, including Keycloak, Garage and HTTPSThe GOAT services and Windmill; PostgreSQL (through CloudNativePG) and Redis as optional sub-charts
You provideA server, and a DNS name if you want automatic HTTPSS3 object storage, Keycloak (if users should log in), Ingress and TLS, storage
Setupsetup.sh writes the configuration, smoke.sh checks the installationA values file
Recommendation

For a single server, the Docker Compose bundle is the recommended path. It contains every component, generates all passwords and keys for you, and ships with scripts for checks, backups and restores. Use the Helm chart if you already run Kubernetes and have S3 storage and a Keycloak available.

Next steps​