Kubernetes
Container image
The image is the release tarball, unpacked on a small Debian base: the tarball carries its own Node.js, so nothing is installed from npm and the build needs no internet beyond the base image.
Get the release
Take the Linux file for your nodes' architecture from the Downloads page: linux-x64 for x64 (amd64) nodes, the usual kind, or linux-arm64 for Arm nodes such as AWS Graviton, Azure Cobalt or Google Axion. To see what your nodes are:
kubectl get nodes -L kubernetes.io/arch
Or fetch it from the command line, with the checksums to verify it against:
VERSION=1.2.0
curl -fsSLO https://github.com/Replient/knwlge-releases/releases/download/enterprise-v$VERSION/knwlge-enterprise-$VERSION-linux-x64.tar.gz
curl -fsSLO https://github.com/Replient/knwlge-releases/releases/download/enterprise-v$VERSION/checksums.txt
sha256sum -c --ignore-missing checksums.txt # macOS: shasum -a 256 -c --ignore-missing checksums.txt
The Dockerfile
Save this as Dockerfile next to the tarball:
# Knwlge Enterprise Server, built from a release tarball (knwlge.com → Downloads).
# Put this file next to the tarball for your nodes' architecture, then:
# docker build --platform linux/amd64 --build-arg VERSION=1.2.0 -t <registry>/knwlge-enterprise:1.2.0 .
# For arm64 nodes, use the linux-arm64 tarball:
# docker build --platform linux/arm64 --build-arg VERSION=1.2.0 --build-arg PLATFORM=linux-arm64 -t ... .
FROM debian:trixie-slim
ARG VERSION
ARG PLATFORM=linux-x64
# ca-certificates for TLS to Knwlge Global and your cloud; git for the worker's ownership
# refresh; tini to pass signals on and reap child processes as PID 1.
RUN apt-get update \
&& apt-get install -y --no-install-recommends ca-certificates git tini \
&& rm -rf /var/lib/apt/lists/*
# Unpacked where the install script would put it.
COPY knwlge-enterprise-${VERSION}-${PLATFORM}.tar.gz /tmp/release.tar.gz
RUN mkdir -p /opt/knwlge-enterprise \
&& tar -xzf /tmp/release.tar.gz -C /opt/knwlge-enterprise \
&& mv "/opt/knwlge-enterprise/knwlge-enterprise-${VERSION}-${PLATFORM}" "/opt/knwlge-enterprise/${VERSION}" \
&& ln -s "/opt/knwlge-enterprise/${VERSION}/bin/knwlge-enterprise" /usr/local/bin/knwlge-enterprise \
&& rm /tmp/release.tar.gz \
&& knwlge-enterprise --version
# config.json, state.json and logs live in the home directory: mount a persistent volume on it.
RUN groupadd --system --gid 10001 knwlge \
&& useradd --system --uid 10001 --gid 10001 --home-dir /var/lib/knwlge-enterprise --create-home knwlge
ENV KNWLGE_ENTERPRISE_HOME=/var/lib/knwlge-enterprise
USER 10001
WORKDIR /var/lib/knwlge-enterprise
EXPOSE 3000
ENTRYPOINT ["tini", "--", "knwlge-enterprise"]
CMD ["start"]
- It runs as an unprivileged user (uid 10001) and works with a read-only root filesystem: it writes only to its home,
/var/lib/knwlge-enterprise, and to/tmp. - No configuration or secret is in the image.
config.jsonlives on the volume mounted at its home. knwlge-enterprise --versionruns during the build, so a tarball for the wrong platform fails there rather than in your cluster.
Build and push
Build for the nodes, not for the machine you build on — on an Apple silicon Mac, --platform linux/amd64 matters:
REGISTRY=<your registry> # e.g. acme.azurecr.io, 111122223333.dkr.ecr.us-east-1.amazonaws.com
docker build --platform linux/amd64 --build-arg VERSION=$VERSION -t $REGISTRY/knwlge-enterprise:$VERSION .
docker push $REGISTRY/knwlge-enterprise:$VERSION
# arm64 nodes: the linux-arm64 tarball, and
docker build --platform linux/arm64 --build-arg VERSION=$VERSION --build-arg PLATFORM=linux-arm64 \
-t $REGISTRY/knwlge-enterprise:$VERSION .
Tag each image with its release version and never reuse a tag: the version is how you upgrade and roll back. Each cloud's guide shows signing in to its registry; on Azure, az acr build builds in the registry without Docker on your machine.
Run it with Docker
The same image runs on a single machine with Docker. The volume plays the part of the persistent volume:
docker volume create knwlge-home
# The setup wizard, interactively, on the volume (answer No to starting the server)
docker run -it --rm -v knwlge-home:/var/lib/knwlge-enterprise knwlge-enterprise:$VERSION setup
# The server, kept running
docker run -d --name knwlge-enterprise --restart unless-stopped \
-p 127.0.0.1:3000:3000 -v knwlge-home:/var/lib/knwlge-enterprise knwlge-enterprise:$VERSION
docker logs -f knwlge-enterprise
docker exec knwlge-enterprise knwlge-enterprise status
- Put HTTPS in front of port 3000 (nginx, Caddy, a load balancer); the port is published on the loopback address only, so nothing reaches it except through that proxy.
- Inside the container
localhostis the container itself: a PostgreSQL on the same machine ishost.docker.internal(Docker Desktop) or the host's address. - To upgrade, build the new version's image, then remove the container and run it again with the new tag; the volume keeps everything.
