Kubernetes

Container image

The image is the release tarball, unpacked on a small Debian base: the tarball carries its own Node.js, so nothing is installed from npm and the build needs no internet beyond the base image.

Get the release

Take the Linux file for your nodes' architecture from the Downloads page: linux-x64 for x64 (amd64) nodes, the usual kind, or linux-arm64 for Arm nodes such as AWS Graviton, Azure Cobalt or Google Axion. To see what your nodes are:

shell
kubectl get nodes -L kubernetes.io/arch

Or fetch it from the command line, with the checksums to verify it against:

shell
VERSION=1.2.0
curl -fsSLO https://github.com/Replient/knwlge-releases/releases/download/enterprise-v$VERSION/knwlge-enterprise-$VERSION-linux-x64.tar.gz
curl -fsSLO https://github.com/Replient/knwlge-releases/releases/download/enterprise-v$VERSION/checksums.txt
sha256sum -c --ignore-missing checksums.txt    # macOS: shasum -a 256 -c --ignore-missing checksums.txt

The Dockerfile

Save this as Dockerfile next to the tarball:

Dockerfile
# Knwlge Enterprise Server, built from a release tarball (knwlge.com → Downloads).
# Put this file next to the tarball for your nodes' architecture, then:
#   docker build --platform linux/amd64 --build-arg VERSION=1.2.0 -t <registry>/knwlge-enterprise:1.2.0 .
# For arm64 nodes, use the linux-arm64 tarball:
#   docker build --platform linux/arm64 --build-arg VERSION=1.2.0 --build-arg PLATFORM=linux-arm64 -t ... .
FROM debian:trixie-slim

ARG VERSION
ARG PLATFORM=linux-x64

# ca-certificates for TLS to Knwlge Global and your cloud; git for the worker's ownership
# refresh; tini to pass signals on and reap child processes as PID 1.
RUN apt-get update \
 && apt-get install -y --no-install-recommends ca-certificates git tini \
 && rm -rf /var/lib/apt/lists/*

# Unpacked where the install script would put it.
COPY knwlge-enterprise-${VERSION}-${PLATFORM}.tar.gz /tmp/release.tar.gz
RUN mkdir -p /opt/knwlge-enterprise \
 && tar -xzf /tmp/release.tar.gz -C /opt/knwlge-enterprise \
 && mv "/opt/knwlge-enterprise/knwlge-enterprise-${VERSION}-${PLATFORM}" "/opt/knwlge-enterprise/${VERSION}" \
 && ln -s "/opt/knwlge-enterprise/${VERSION}/bin/knwlge-enterprise" /usr/local/bin/knwlge-enterprise \
 && rm /tmp/release.tar.gz \
 && knwlge-enterprise --version

# config.json, state.json and logs live in the home directory: mount a persistent volume on it.
RUN groupadd --system --gid 10001 knwlge \
 && useradd --system --uid 10001 --gid 10001 --home-dir /var/lib/knwlge-enterprise --create-home knwlge
ENV KNWLGE_ENTERPRISE_HOME=/var/lib/knwlge-enterprise
USER 10001
WORKDIR /var/lib/knwlge-enterprise

EXPOSE 3000
ENTRYPOINT ["tini", "--", "knwlge-enterprise"]
CMD ["start"]
  • It runs as an unprivileged user (uid 10001) and works with a read-only root filesystem: it writes only to its home, /var/lib/knwlge-enterprise, and to /tmp.
  • No configuration or secret is in the image. config.json lives on the volume mounted at its home.
  • knwlge-enterprise --version runs during the build, so a tarball for the wrong platform fails there rather than in your cluster.

Build and push

Build for the nodes, not for the machine you build on — on an Apple silicon Mac, --platform linux/amd64 matters:

shell
REGISTRY=<your registry>      # e.g. acme.azurecr.io, 111122223333.dkr.ecr.us-east-1.amazonaws.com
docker build --platform linux/amd64 --build-arg VERSION=$VERSION -t $REGISTRY/knwlge-enterprise:$VERSION .
docker push $REGISTRY/knwlge-enterprise:$VERSION

# arm64 nodes: the linux-arm64 tarball, and
docker build --platform linux/arm64 --build-arg VERSION=$VERSION --build-arg PLATFORM=linux-arm64 \
  -t $REGISTRY/knwlge-enterprise:$VERSION .

Tag each image with its release version and never reuse a tag: the version is how you upgrade and roll back. Each cloud's guide shows signing in to its registry; on Azure, az acr build builds in the registry without Docker on your machine.

Run it with Docker

The same image runs on a single machine with Docker. The volume plays the part of the persistent volume:

shell
docker volume create knwlge-home

# The setup wizard, interactively, on the volume (answer No to starting the server)
docker run -it --rm -v knwlge-home:/var/lib/knwlge-enterprise knwlge-enterprise:$VERSION setup

# The server, kept running
docker run -d --name knwlge-enterprise --restart unless-stopped \
  -p 127.0.0.1:3000:3000 -v knwlge-home:/var/lib/knwlge-enterprise knwlge-enterprise:$VERSION

docker logs -f knwlge-enterprise
docker exec knwlge-enterprise knwlge-enterprise status
  • Put HTTPS in front of port 3000 (nginx, Caddy, a load balancer); the port is published on the loopback address only, so nothing reaches it except through that proxy.
  • Inside the container localhost is the container itself: a PostgreSQL on the same machine is host.docker.internal (Docker Desktop) or the host's address.
  • To upgrade, build the new version's image, then remove the container and run it again with the new tag; the volume keeps everything.