Skip to content

Self-hosting

Self-hosting Keyright

Run Keyright in your own infrastructure — Docker, Kubernetes or Windows/IIS, against your own PostgreSQL, fully air-gapped if you need it. This overview covers the architecture and the two moving parts; the rest of the Self-hosting section walks you through deployment, configuration, licensing, wiring your product, and operations.

Keyright comes two ways: managed (we run it) and self-hosted (you run it — a single VM, a Kubernetes cluster, or a fully air-gapped network). The self-hosted build is the same build as the managed service, so every SDK, endpoint and behaviour in these docs applies identically; the only inactive parts are the multi-tenant operator surface and hosted-plan billing.

This page explains what you’re running. When you’re ready to stand it up, jump to the step-by-step deployment guide.

The Self-hosting section, in order

  1. Overview & architecture — you are here.
  2. Deployment guide (step by step) — from zero to a verified, licensed instance.
  3. Configuration reference — every environment variable, secrets, white-label, database.
  4. Licensing & editions — the fail-closed model, the trial, Standard vs Enterprise.
  5. Wire your product to your instance — point your app’s SDK at your own Keyright.
  6. Operations & troubleshooting — scaling, backups, upgrades, air-gapped, FAQ.

Architecture

Self-hosted Keyright has exactly two moving parts — a stateless application and your database:

Your customers' appsactivate · validate (no auth)You / your teamadmin · dashboard · portalHTTPSLoad balancer / reverse proxyTLS termination · forwards to /healthonly if > 1 nodeKeyright app nodestateless · port 8080Keyright app nodestateless · port 8080app only — no database insidePostgreSQL 14+All state — licenses, activations, credits,audit log, KEK-encrypted signing keys
Two moving parts: one or more stateless app nodes, and the PostgreSQL you point them at.
  • The app — ghcr.io/delta1-labs/keyright, one stateless ASP.NET Core service on port 8080. The image is app-only — no database inside. It keeps no state between requests, so you can run as many replicas as you want behind a load balancer, with no session affinity.
  • PostgreSQL 14+ — holds all state. You point the app at it with KEYRIGHT_DB; the app creates and migrates its own schema on first start (there is no SQL to run by hand).

The hot path your customers hit (/v1/activate, /v1/validate) is a signature check plus a seat count, and clients verify licenses offline between activations — so you’re not taking a request per app launch. That is why the app tier is CPU-light and scale is really about redundancy and database capacity (see Operations → Scaling).

What you need, at a glance

  • A container runtime — Docker 24+ with Compose v2, or Kubernetes 1.24+ with Helm 3. Or Windows/IIS with the .NET 8 Hosting Bundle (no containers).
  • PostgreSQL 14+ (16 recommended), UTF-8. The bundles can run one for you for evaluation; for production use your own managed/HA Postgres.
  • A Keyright license or trial key from Delta1 — required to run (Keyright is fail-closed; see Licensing). Contact sales for a 30-day Enterprise trial or a paid license.
  • Outbound internet is not required at runtime — Keyright runs air-gapped.

The editions, briefly

EditionTermFeatures
Enterprise trial30 daysFull Enterprise feature set, to evaluate
Standardannual or perpetualThe complete licensing engine — offline + online activation, node-locking & seats, entitlements & tiers, revocation, the self-service portal, usage metering, all SDKs
Enterpriseannual or perpetualEverything in Standard, plus SSO (SAML/OIDC), white-label dashboard/portal branding, and air-gapped credit blocks

Both paid editions carry unlimited licenses and products — it’s your infrastructure, so no count caps. The full lifecycle (trial vs paid, grace windows, what happens at expiry) is in Licensing & editions.


Ready to stand it up? Start with the step-by-step deployment guide →