Kiket docs
Self host

Self-host

Run Kiket in your own environment or air-gapped deployment.

Enterprise customers can run Kiket alongside managed SaaS or replace it entirely. Same product, your data, your network, your compliance boundary.

Kiket architecture stack — client, API, engine, workspace repo, trust layer

What you get

  • The full platform (API, web app, background workers, scheduler).
  • Every integration extension as an optional deployable.
  • A production-grade primary datastore with the search extensions the platform expects.
  • A durable queue and cache tier for jobs and sessions.
  • Your choice of blockchain anchor (public network, a private chain, or skip anchoring).
  • Interactive sign-in via OAuth (Google and GitHub). SAML and SCIM on the enterprise roadmap.

Requirements

  • A container platform you operate (managed or self-run) meeting the chart’s supported version window.
  • A supported relational database with vector-search extensions enabled, sized for your tenant count.
  • A supported cache and job-queue service (minimum version in the operator guide) for jobs and session backing where required.
  • Object storage (S3-compatible): attachments, evidence exports, bundled backups.
  • TLS: automated certificates from a public CA or your internal PKI.
  • Ingress / load balancing in front of the app and API (any controller you already standardize on).

Minimum resources per node:

ComponentCPURAM
API (2 replicas)500m512Mi
Workers (2 replicas)500m1Gi
Web (2 replicas)200m256Mi
Primary database2 vCPU4Gi
Cache / queue200m512Mi

A mid-size cloud VM profile handles a team of ~200 users comfortably when sized as above.

Deploy flow

Get the install bundle

Private OCI registry; contact sales for access. The bundle ships with a production-grade values.yaml covering secrets, ingress, storage, and the blockchain anchor.

Provision infra

Kiket ships OpenTofu modules for common cloud providers. Each module stands up:

  • A managed container cluster
  • Object storage bucket
  • DNS records for the app, API, and webhook subdomains
  • TLS certificates (via your platform’s cert automation)

For air-gapped: bring your own cluster; we provide a values-only path.

Configure secrets

  • API signing key (generated on first boot if unset)
  • Platform OAuth (optional): Google and/or GitHub for user sign-in.
    • Register redirect URIs https://<api-host>/api/v1/auth/oauth/google/callback and https://<api-host>/api/v1/auth/oauth/github/callback on each provider.
    • Set APP_URL (web app origin), PUBLIC_API_URL or API_URL (public API base), GOOGLE_AUTH_LOGIN_CLIENT_ID / GOOGLE_AUTH_LOGIN_CLIENT_SECRET (or GOOGLE_OAUTH_CLIENT_ID / GOOGLE_OAUTH_CLIENT_SECRET), and optionally dedicated GITHUB_AUTH_LOGIN_* (otherwise GITHUB_CLIENT_* can be reused with an extra callback URL on the same GitHub OAuth app).
    • See Platform OAuth login in the deploy/README.md supplied with your bundle, and the production secrets template in the deploy tree; local API development uses apps/api/.env in the source repo.
    • OAuth login state is API memory–backed — with multiple API replicas and no sticky sessions, use one replica for authorize/callback or shared session/state storage.
  • Primary database URL
  • Cache / queue URL
  • Object storage credentials
  • Blockchain anchor private key (or leave blank to skip)
  • Mailjet credentials for notification email and password reset mail:
    • MAILJET_API_KEY, MAILJET_SECRET_KEY, MAILJET_FROM_EMAIL, optional MAILJET_FROM_NAME
    • APP_URL must match your web app origin so links in email resolve correctly

Use SOPS or your platform’s native secret store. The chart doesn’t prescribe one.

Run migrations

One-time:

helm upgrade kiket ./chart -f values.yaml --set migrate.run=true

The migrate job applies the current schema to your database, then exits.

Open the app

Visit the app hostname. First-user-wins creates the org; invite your team from there.

Backups

  • The reference data stack streams write-ahead logs to object storage for point-in-time recovery; this is tested on every release.
  • Optional: periodic evidence-export jobs for long-term regulatory retention.

Upgrades

Monthly stable releases. Rolling upgrade procedure:

  1. Upgrade the install bundle to the new chart version.
  2. Wait for the migrate job to finish (backward-compatible migrations are the rule).
  3. API rolls; old instances drain gracefully.

Breaking releases ship a version-jump runbook in the release notes — rare.

Air-gapped mode

  • Disable the blockchain anchor (or anchor to a private chain inside your network).
  • Disable outbound extension callbacks if the extensions would cross the boundary.
  • Kiket itself needs no outbound calls to function.

Cost

On a typical small managed cluster plus the database and cache sizes above, total cost for ~200 users is usually modest before extension and external-service usage. See the deploy module README for current numbers.

What's next?

On this page