---
url: >-
  https://flip-chart.ru/developers/en/on-premise/installation/docker-compose/advanced-setup.md
description: >-
  Installing flip on-premise with Docker Compose in High Availability mode:
  external PostgreSQL, Valkey, S3 storage and reverse proxy, plus step-by-step
  setup instructions.
---

# Docker Compose — High Availability

## Requirements

* An application server that meets the [system requirements](/en/on-premise/installation/system-requirements), with [Docker Engine](https://docs.docker.com/engine/install/) and [Docker Compose](https://docs.docker.com/compose/install/)
* PostgreSQL 15 (14 is supported)
* Valkey 9 (standalone mode; Sentinel and Cluster are not supported)
* S3-compatible storage with a bucket that allows anonymous read access
* A reverse proxy with SSL termination (nginx, HAProxy or a cloud load balancer)
* Two DNS names (for the application and the MCP server) and certificates for both
* SMTP server credentials

::: danger Important
The external services must be deployed and reachable over the network from the application server.
:::

## Setup steps

### 1. Files

Use the `deploy/docker-compose` directory from the delivery archive; replace `docker-compose.yaml` with the HA version:

```yaml
# flip on-premise — High Availability
# PostgreSQL, Valkey, S3 storage and the reverse proxy are deployed separately.
# Variables come from the .env file next to docker-compose.yaml

services:
  flip-file-handlers:
    image: ${FLIP_REGISTRY_IMAGE}/flip-file-handlers:${FLIP_VERSION}
    container_name: flip-file-handlers
    restart: unless-stopped
    volumes:
      - ./config/file-handlers/config.yaml:/flip/config/config.yaml:ro
    networks:
      - flip

  flip-backend:
    image: ${FLIP_REGISTRY_IMAGE}/flip-backend:${FLIP_VERSION}
    container_name: flip-backend
    restart: unless-stopped
    depends_on:
      - flip-file-handlers
    ports:
      - "9000:9000"
    volumes:
      - ./config/backend/config.yaml:/flip/cfg/config.yaml:ro
      # PostgreSQL root certificate for SSLmode: verify-full
      # - ./config/backend/ca.pem:/flip/certs/ca.pem:ro
    networks:
      - flip

  flip-frontend:
    image: ${FLIP_REGISTRY_IMAGE}/flip-frontend:${FLIP_VERSION}
    container_name: flip-frontend
    restart: unless-stopped
    depends_on:
      - flip-backend
    ports:
      - "8080:80"
    volumes:
      - ./config/frontend/config.js:/usr/share/nginx/html/app/assets/config.js:ro
    networks:
      - flip

  flip-mcp-server:
    image: ${FLIP_REGISTRY_IMAGE}/flip-mcp-server:${FLIP_VERSION}
    container_name: flip-mcp-server
    restart: unless-stopped
    depends_on:
      - flip-backend
    ports:
      - "8090:8090"
    volumes:
      - ./config/mcp-server/config.yaml:/flip/cfg/config.yaml:ro
    networks:
      - flip

networks:
  flip:
    driver: bridge

```

[Download docker-compose.ha.yaml](/en/deploy/docker-compose.ha.yaml)

The containers publish ports on the host: backend `9000`, frontend `8080`, mcp-server `8090`. If the reverse proxy runs on the same server, you can connect it to the `flip` network instead of publishing the ports.

### 2. Environment variables

The `.env` file sets the image registry and version:

```ini
FLIP_REGISTRY_IMAGE=cr.yandex/crpbj8irels1kqult74e/onpremise
FLIP_VERSION=v1.2.0
```

### 3. Configuration files

Fill in the files in the `config` directory, specifying the addresses of the external PostgreSQL, Valkey and S3:

| File | Description | Key fields |
|---|---|---|
| `config/backend/config.yaml` | [Backend](/en/on-premise/config/backend) | `Postgres`, `RedisClient`, `S3`, `Mail`, secrets |
| `config/file-handlers/config.yaml` | [File-handlers](/en/on-premise/config/file-handlers) | `S3Config`, `RedisConfig` |
| `config/frontend/config.js` | [Frontend](/en/on-premise/config/frontend) | `API_URL`, `S3_URL`, `WEBSOCKET_URL` |
| `config/mcp-server/config.yaml` | [MCP server](/en/on-premise/config/mcp) | `flipApi`, `RedisClient` |

::: danger File permissions
Processes in the containers do not run as root. The configuration files must be readable: `chmod -R a+rX config`.
:::

::: tip PostgreSQL over TLS
For an external database, use `SSLmode: require` or `verify-full`. For `verify-full`, mount the root certificate into the container (see the commented-out line in `docker-compose.ha.yaml`) and set its path in `Postgres.SSLRootCert`.
:::

### 4. S3 storage

* Create a bucket and allow anonymous read access to its objects (the `download` / `public-read` policy).
* Upload the application's media assets: unpack `sources/gifs.tar` and copy the `gifs` directory to the root of the bucket:

```bash
tar -xf sources/gifs.tar -C .
aws --endpoint-url https://s3.example.ru s3 cp gifs s3://flip/gifs --recursive
```

### 5. Reverse proxy

Configure routes and timeouts as in the [nginx configuration](/en/on-premise/config/nginx): WebSocket at `/app/api/v1/ws`, an increased request body limit for `/app/api/v1/flip/backup/upload`, S3 proxying at `/app/s3/`, and a separate virtual host for the MCP server.

### 6. Registry access and startup

```bash
cat ../../credentials/authorized_key.json | docker login --username json_key --password-stdin cr.yandex
docker compose pull
docker compose up -d
docker compose ps
```

The application is available at `https://example.flip-chart.ru/app`. Then proceed to the [first launch](/en/on-premise/installation/first-boot).
