Self-host
Run Kiket in your own environment or air-gapped deployment.
Enterprise customers can run Kiket alongside managed SaaS or replace it entirely. Same product, your data, your network, your compliance boundary.
What you get
- The full platform (API, web app, background workers, scheduler).
- Every integration extension as an optional deployable.
- A production-grade primary datastore with the search extensions the platform expects.
- A durable queue and cache tier for jobs and sessions.
- Your choice of blockchain anchor (public network, a private chain, or skip anchoring).
- Interactive sign-in via OAuth (Google and GitHub). SAML and SCIM on the enterprise roadmap.
Requirements
- A container platform you operate (managed or self-run) meeting the chart’s supported version window.
- A supported relational database with vector-search extensions enabled, sized for your tenant count.
- A supported cache and job-queue service (minimum version in the operator guide) for jobs and session backing where required.
- Object storage (S3-compatible): attachments, evidence exports, bundled backups.
- TLS: automated certificates from a public CA or your internal PKI.
- Ingress / load balancing in front of the app and API (any controller you already standardize on).
Minimum resources per node:
| Component | CPU | RAM |
|---|---|---|
| API (2 replicas) | 500m | 512Mi |
| Workers (2 replicas) | 500m | 1Gi |
| Web (2 replicas) | 200m | 256Mi |
| Primary database | 2 vCPU | 4Gi |
| Cache / queue | 200m | 512Mi |
A mid-size cloud VM profile handles a team of ~200 users comfortably when sized as above.
Deploy flow
Get the install bundle
Private OCI registry; contact sales for access. The bundle ships with a production-grade values.yaml covering secrets, ingress, storage, and the blockchain anchor.
Provision infra
Kiket ships OpenTofu modules for common cloud providers. Each module stands up:
- A managed container cluster
- Object storage bucket
- DNS records for the app, API, and webhook subdomains
- TLS certificates (via your platform’s cert automation)
For air-gapped: bring your own cluster; we provide a values-only path.
Configure secrets
- API signing key (generated on first boot if unset)
- Platform OAuth (optional): Google and/or GitHub for user sign-in.
- Register redirect URIs
https://<api-host>/api/v1/auth/oauth/google/callbackandhttps://<api-host>/api/v1/auth/oauth/github/callbackon each provider. - Set
APP_URL(web app origin),PUBLIC_API_URLorAPI_URL(public API base),GOOGLE_AUTH_LOGIN_CLIENT_ID/GOOGLE_AUTH_LOGIN_CLIENT_SECRET(orGOOGLE_OAUTH_CLIENT_ID/GOOGLE_OAUTH_CLIENT_SECRET), and optionally dedicatedGITHUB_AUTH_LOGIN_*(otherwiseGITHUB_CLIENT_*can be reused with an extra callback URL on the same GitHub OAuth app). - See Platform OAuth login in the
deploy/README.mdsupplied with your bundle, and the production secrets template in the deploy tree; local API development usesapps/api/.envin the source repo. - OAuth login
stateis API memory–backed — with multiple API replicas and no sticky sessions, use one replica for authorize/callback or shared session/state storage.
- Register redirect URIs
- Primary database URL
- Cache / queue URL
- Object storage credentials
- Blockchain anchor private key (or leave blank to skip)
- Mailjet credentials for notification email and password reset mail:
MAILJET_API_KEY,MAILJET_SECRET_KEY,MAILJET_FROM_EMAIL, optionalMAILJET_FROM_NAMEAPP_URLmust match your web app origin so links in email resolve correctly
Use SOPS or your platform’s native secret store. The chart doesn’t prescribe one.
Run migrations
One-time:
helm upgrade kiket ./chart -f values.yaml --set migrate.run=trueThe migrate job applies the current schema to your database, then exits.
Open the app
Visit the app hostname. First-user-wins creates the org; invite your team from there.
Backups
- The reference data stack streams write-ahead logs to object storage for point-in-time recovery; this is tested on every release.
- Optional: periodic evidence-export jobs for long-term regulatory retention.
Upgrades
Monthly stable releases. Rolling upgrade procedure:
- Upgrade the install bundle to the new chart version.
- Wait for the migrate job to finish (backward-compatible migrations are the rule).
- API rolls; old instances drain gracefully.
Breaking releases ship a version-jump runbook in the release notes — rare.
Air-gapped mode
- Disable the blockchain anchor (or anchor to a private chain inside your network).
- Disable outbound extension callbacks if the extensions would cross the boundary.
- Kiket itself needs no outbound calls to function.
Cost
On a typical small managed cluster plus the database and cache sizes above, total cost for ~200 users is usually modest before extension and external-service usage. See the deploy module README for current numbers.