Keyright · Self-hosted
Run Keyright in your own infrastructure
The same licensing backend that powers our managed cloud — deployed inside your network, on your database, under your control. Fully air-gapped capable. Also available fully managed if you'd rather we run it.
Pull the image
docker pull ghcr.io/delta1-labs/keyright:2.0.1 One product, your choice
Managed or self-hosted
Identical build and features either way — the only difference is who runs it. Move between them without changing your integration.
Managed (SaaS)
We host it. Start free.
- We run the issuing service, database and portal
- Zero ops — automatic upgrades and backups
- Global uptime and scaling handled for you
- Start free in minutes, no infrastructure
Self-hosted
You host it. Air-gapped capable.
- Runs entirely inside your infrastructure
- Works fully air-gapped — no phone-home
- Your data never leaves your compliance boundary
- Docker, Kubernetes (Helm) or Windows / IIS
Architecture
Two moving parts
A stateless app you scale horizontally, and a PostgreSQL database that holds all state. The image is app-only — you run your own Postgres, so your data stays yours.
Install
Deploy your way
Pull one public image and run it next to a PostgreSQL. The app creates its own schema on first start — no SQL to import.
Docker Compose Single node
Brings up the app and a PostgreSQL together — one command.
cp deploy/.env.example deploy/.env # set KEYRIGHT_ADMIN_TOKEN + KEYRIGHT_KEK
docker compose -f deploy/docker-compose.yml --env-file deploy/.env up -d
curl -fsS http://localhost:8080/health # {"status":"ok","service":"keyright-issuing","version":"2.0.1"} Kubernetes Helm chart
Run 2+ replicas behind your ingress; point it at your managed PostgreSQL for production.
helm upgrade --install keyright deploy/helm/keyright \
--set image.repository=ghcr.io/delta1-labs/keyright \
--set-string secrets.adminToken=$KEYRIGHT_ADMIN_TOKEN \
--set-string secrets.kek=$KEYRIGHT_KEK \
--set replicaCount=2 Windows / IIS No containers
A self-contained bundle for the ASP.NET Core Module (in-process), pointed at your PostgreSQL.
pwsh deploy/windows/build-win-bundle.ps1 # -SelfContained if the server has no .NET 8
# unzip into an IIS site, set the KEYRIGHT_* machine env vars, start the site Full instructions — database setup, sizing by scale, load balancing, TLS, backups, upgrades, air-gapped — are in the self-hosting guide.
No phone-home
Your instance verifies its own licence offline against an embedded public key. Nothing calls out at runtime — it works in a fully disconnected network.
Your customers are never affected
Activation, validation and metering always work. Licensing on our side only ever gates new provisioning, and only after a generous grace window.
Your keys stay yours
Signing keys are generated in your database and encrypted at rest with a key only you hold. We never see your data or your customers' keys.
Who self-hosts
Built for the toughest environments
Air-gapped & classified networks
Defense, industrial and OT environments with no outbound internet. Keyright verifies its own licence and yours offline, and meters disconnected machines with signed credit blocks.
Regulated industries
Finance, healthcare and government teams that must keep licence data and customer PII inside their own compliance boundary and audit trail.
Data residency
Keep all licensing data in a specific region or sovereign cloud. You choose where the app and PostgreSQL run — a VM, your Kubernetes cluster, or a private datacenter.
On-prem enterprise
Vendors whose own customers require the licensing backend to live inside their infrastructure — behind their firewall, on their SSO, under their change control.
Bring Keyright in-house
Talk to us about a self-hosted licence, or start free on the managed cloud today.