Skip to main content
The air-gap tarball is a self-contained archive that installs Nora on a host with zero internet access. All five container images are baked in via docker save, so install.sh never touches a registry.

What’s in the tarball

The tarball is produced by infra/onprem/build-tarball.sh and named nora-onprem-<version>.tar.gz. Inside you’ll find:

Prerequisites on the target host

  • Docker Engine 20.10+ (docker --version).
  • The Docker Compose plugin (docker compose version).
  • Around 15 GB of free disk for the images.
  • 4 GB of RAM available to Docker.
No repository access, no docker pull, no package download is required on the target.

Install

1

Extract the tarball

2

Run the installer

The script does three things — nothing more, and it never binds a port:
  1. Loads the five service images into your local Docker daemon (pgvector, redis, qdrant, nora-server, nora-llm-bridge).
  2. Copies .env.example to .env.onprem only if .env.onprem doesn’t already exist (safe to re-run for upgrades).
  3. Prints the next-step instructions.
Pass --dry-run to preview without touching Docker.

Configure

Open /opt/nora/.env.onprem and set the values that apply to your deployment.
  • Required — POSTGRES_PASSWORD. The bundled Postgres container’s superuser password. Compose refuses to boot with a CHANGE_ME_* placeholder left in place.
  • Recommended — NORA_LICENSE_FILE. The path to your license JSON, provided by Nora sales. Drop the file next to .env.onprem and set the path. Without one, Nora runs in free tier (1 workspace, 3 flows, 100 daily invokes).
  • Recommended — NORA_AIRGAP=1. Enables the boot probe. The server exits with code 78 at boot if it can still reach the public internet, so a misconfigured egress rule can’t silently break isolation.
  • Optional — SSO and OAuth pairs (GOOGLE_OAUTH_CLIENT_ID/_SECRET, GITHUB_OAUTH_CLIENT_ID/_SECRET). Only useful when the network can reach the provider’s OAuth endpoints. Leave these blank in fully air-gapped installs — local email-and-password accounts still work.

Boot

The stack listens on http://localhost:${NORA_HOST_PORT:-8090}. First boot runs SQL migrations automatically because NORA_RUN_MIGRATIONS=1 is on by default.

Upgrade

When a new tarball arrives, extract it next to the current install and re-run install.sh. Image tags roll forward, compose is re-applied, and database migrations are additive.
Desktop-app operators do the same thing via Nora → [Import Update…]. See Updates.

Uninstall or reset

The -v drops the Postgres and Qdrant volumes — workspaces, users, flows, and vector indexes are gone. Skip -v to keep the data across up and down cycles.

What version am I on?

The tag matches the tarball filename, and it’s also visible under Settings → About in the running SPA.

Troubleshooting

Follow the server logs:
The most common first-install failures:
  • POSTGRES_PASSWORD is still a CHANGE_ME_* placeholder. Compose exits before starting.
  • NORA_LICENSE_FILE path doesn’t exist or isn’t readable by Docker. The server logs the missing path and drops to free tier — attempts to create a second workspace are refused.
  • Host port 8090 is already bound. Set NORA_HOST_PORT to something else in .env.onprem.
  • NORA_AIRGAP=1 but egress isn’t actually blocked. The server exits with code 78. Fix the firewall rules and boot again.

Building the tarball (for release engineers)

From the platform repo on a host with a working Docker daemon:
The output lands in dist/nora-onprem-<version>.tar.gz. The first build takes about 30 minutes (mostly the Rust image); rebuilds with a warm cache are much faster.

Docker Compose

The online version of the same compose file.

Kubernetes (Helm)

Load the tarball images into a private registry, then override the chart values.