docker save, so install.sh never touches a registry.
What’s in the tarball
The tarball is produced byinfra/onprem/build-tarball.sh and named nora-onprem-<version>.tar.gz. Inside you’ll find:
Prerequisites on the target host
- Docker Engine 20.10+ (
docker --version). - The Docker Compose plugin (
docker compose version). - Around 15 GB of free disk for the images.
- 4 GB of RAM available to Docker.
docker pull, no package download is required on the target.
Install
1
Extract the tarball
2
Run the installer
- Loads the five service images into your local Docker daemon (
pgvector,redis,qdrant,nora-server,nora-llm-bridge). - Copies
.env.exampleto.env.onpremonly if.env.onpremdoesn’t already exist (safe to re-run for upgrades). - Prints the next-step instructions.
--dry-run to preview without touching Docker.Configure
Open/opt/nora/.env.onprem and set the values that apply to your deployment.
- Required —
POSTGRES_PASSWORD. The bundled Postgres container’s superuser password. Compose refuses to boot with aCHANGE_ME_*placeholder left in place. - Recommended —
NORA_LICENSE_FILE. The path to your license JSON, provided by Nora sales. Drop the file next to.env.onpremand set the path. Without one, Nora runs in free tier (1 workspace, 3 flows, 100 daily invokes). - Recommended —
NORA_AIRGAP=1. Enables the boot probe. The server exits with code 78 at boot if it can still reach the public internet, so a misconfigured egress rule can’t silently break isolation. - Optional — SSO and OAuth pairs (
GOOGLE_OAUTH_CLIENT_ID/_SECRET,GITHUB_OAUTH_CLIENT_ID/_SECRET). Only useful when the network can reach the provider’s OAuth endpoints. Leave these blank in fully air-gapped installs — local email-and-password accounts still work.
Boot
http://localhost:${NORA_HOST_PORT:-8090}. First boot runs SQL migrations automatically because NORA_RUN_MIGRATIONS=1 is on by default.
Upgrade
When a new tarball arrives, extract it next to the current install and re-runinstall.sh. Image tags roll forward, compose is re-applied, and database migrations are additive.
Uninstall or reset
-v drops the Postgres and Qdrant volumes — workspaces, users, flows, and vector indexes are gone. Skip -v to keep the data across up and down cycles.
What version am I on?
Troubleshooting
Follow the server logs:POSTGRES_PASSWORDis still aCHANGE_ME_*placeholder. Compose exits before starting.NORA_LICENSE_FILEpath doesn’t exist or isn’t readable by Docker. The server logs the missing path and drops to free tier — attempts to create a second workspace are refused.- Host port 8090 is already bound. Set
NORA_HOST_PORTto something else in.env.onprem. NORA_AIRGAP=1but egress isn’t actually blocked. The server exits with code 78. Fix the firewall rules and boot again.
Building the tarball (for release engineers)
From the platform repo on a host with a working Docker daemon:dist/nora-onprem-<version>.tar.gz. The first build takes about 30 minutes (mostly the Rust image); rebuilds with a warm cache are much faster.
Related
Docker Compose
The online version of the same compose file.
Kubernetes (Helm)
Load the tarball images into a private registry, then override the chart values.