Skip to content

Keyright · Self-hosted

Run Keyright in your own infrastructure

The same licensing backend that powers our managed cloud — deployed inside your network, on your database, under your control. Fully air-gapped capable. Also available fully managed if you'd rather we run it.

Pull the image

docker pull ghcr.io/delta1-labs/keyright:2.0.1

One product, your choice

Managed or self-hosted

Identical build and features either way — the only difference is who runs it. Move between them without changing your integration.

Managed (SaaS)

We host it. Start free.

  • We run the issuing service, database and portal
  • Zero ops — automatic upgrades and backups
  • Global uptime and scaling handled for you
  • Start free in minutes, no infrastructure
See managed pricing

Self-hosted

You host it. Air-gapped capable.

  • Runs entirely inside your infrastructure
  • Works fully air-gapped — no phone-home
  • Your data never leaves your compliance boundary
  • Docker, Kubernetes (Helm) or Windows / IIS
Talk to sales

Architecture

Two moving parts

A stateless app you scale horizontally, and a PostgreSQL database that holds all state. The image is app-only — you run your own Postgres, so your data stays yours.

Your customers' apps activate · validate (offline between) You & your team admin API · dashboard · portal Load balancer / TLS health check · /health · no sticky sessions Keyright app node stateless · port 8080 Keyright app node add replicas for HA PostgreSQL (yours) all state · auto-migrated on start

Install

Deploy your way

Pull one public image and run it next to a PostgreSQL. The app creates its own schema on first start — no SQL to import.

Docker Compose Single node

Brings up the app and a PostgreSQL together — one command.

cp deploy/.env.example deploy/.env      # set KEYRIGHT_ADMIN_TOKEN + KEYRIGHT_KEK
docker compose -f deploy/docker-compose.yml --env-file deploy/.env up -d
curl -fsS http://localhost:8080/health  # {"status":"ok","service":"keyright-issuing","version":"2.0.1"}

Kubernetes Helm chart

Run 2+ replicas behind your ingress; point it at your managed PostgreSQL for production.

helm upgrade --install keyright deploy/helm/keyright \
  --set image.repository=ghcr.io/delta1-labs/keyright \
  --set-string secrets.adminToken=$KEYRIGHT_ADMIN_TOKEN \
  --set-string secrets.kek=$KEYRIGHT_KEK \
  --set replicaCount=2

Windows / IIS No containers

A self-contained bundle for the ASP.NET Core Module (in-process), pointed at your PostgreSQL.

pwsh deploy/windows/build-win-bundle.ps1   # -SelfContained if the server has no .NET 8
# unzip into an IIS site, set the KEYRIGHT_* machine env vars, start the site

Full instructions — database setup, sizing by scale, load balancing, TLS, backups, upgrades, air-gapped — are in the self-hosting guide.

No phone-home

Your instance verifies its own licence offline against an embedded public key. Nothing calls out at runtime — it works in a fully disconnected network.

Your customers are never affected

Activation, validation and metering always work. Licensing on our side only ever gates new provisioning, and only after a generous grace window.

Your keys stay yours

Signing keys are generated in your database and encrypted at rest with a key only you hold. We never see your data or your customers' keys.

Who self-hosts

Built for the toughest environments

Air-gapped & classified networks

Defense, industrial and OT environments with no outbound internet. Keyright verifies its own licence and yours offline, and meters disconnected machines with signed credit blocks.

Regulated industries

Finance, healthcare and government teams that must keep licence data and customer PII inside their own compliance boundary and audit trail.

Data residency

Keep all licensing data in a specific region or sovereign cloud. You choose where the app and PostgreSQL run — a VM, your Kubernetes cluster, or a private datacenter.

On-prem enterprise

Vendors whose own customers require the licensing backend to live inside their infrastructure — behind their firewall, on their SSO, under their change control.

Bring Keyright in-house

Talk to us about a self-hosted licence, or start free on the managed cloud today.