Skip to content
Tick&

FR · EN

Installation

Four ways to deploy Tick&

Tick& is self-hosted. Two dependencies only — PostgreSQL and Redis, both open source — and four installation paths depending on what your organisation allows on its servers. Two of them need no container engine at all.

Containers — Docker or Podman

The shortest path: one compose file, five services, nothing to compile.

What the compose does

PostgreSQL and Redis first, then a dedicated service that applies migrations once and exits, then the API, then the interface. Two containers starting together cannot run the same migration in parallel.

Podman works too

It is often the engine allowed where Docker is not, since it runs without a privileged daemon. Replace docker compose with podman compose; everything else is identical.

Published images

ghcr.io/tick0001/tick-api and tick-web, public and pullable without authentication. Pin a version rather than following latest: an upgrade should stay a decision.

Linux, without containers

For organisations whose policy forbids a container engine on a server — still common in regulated environments.

What you need

Node 22, PostgreSQL 18, Redis 7 and nginx from upstream repositories. Debian, Ubuntu, RHEL, Rocky and AlmaLinux are covered, with the exact commands for each.

Self-contained archives

Every release ships an archive holding the compiled code and its dependencies. The server needs neither pnpm, nor a compiler, nor the repository.

systemd unit provided

A dedicated service account without a shell, secrets kept out of the unit file, and hardening that leaves only the attachments directory writable.

  • The owner role needs CREATEROLE. The initial migration creates the application role; without that attribute it fails after having already applied part of the schema. This is the most frequent difference from a container deployment, where the PostgreSQL image makes the owner a superuser unasked.
  • The Linux archive is built against glibc. It covers Debian, Ubuntu, RHEL, Rocky and SUSE, but not musl distributions such as Alpine: the native hashing module is not the same binary. On Alpine, use the container images.
  • SELinux blocks the proxy. In enforcing mode nginx may not open a network connection, and the proxy to the API fails with a 502 and no readable explanation. One setsebool fixes it.

This procedure was carried out end to end on a clean Debian 12 machine — packages, migrations, first account creation, startup and sign-in.

Windows Server

For organisations that do not run Linux servers. The API runs natively, with one point to settle first.

  • Redis has no official Windows build, and it is not optional: six queues depend on it, including service level escalation. Three real options — point at an existing Redis on the network, often the cleanest; Memurai, native but commercially licensed in production; or WSL2, with the caveat that a policy forbidding Docker often forbids WSL2 for the same reason.
  • Microsoft's Redis port is to be avoided. Archived and frozen since 2016, it lacks the commands the queues rely on. The symptom is an obscure error on the first queued job, not a refusal at startup.
  • Everything else is straightforward. The four required PostgreSQL extensions ship with the installer, the API reads its configuration from a file rather than environment variables, and the native hashing module has a Windows build.

In every case

A TLS terminator in front

Tick& does not serve TLS itself. It expects Caddy, Traefik, nginx or a corporate load balancer in front. Deploying without one sends passwords in the clear.

Two PostgreSQL roles

The owner holds the tables and bypasses Row-Level Security; it serves migrations only. The application role carries all normal traffic and is subject to the policies. Swapping them would disable isolation silently.

An encryption key kept separately

It encrypts directory and mail-collector secrets stored in the database. Losing it makes them permanently unreadable; storing it beside the backup defeats the point of encrypting them.

The detailed documentation is written in French, in the repository: container deployment, bare-metal Linux, and Windows Server.