Skip to content
Alpha: Odal Node is in active development. APIs, schemas and docs will change before 1.0.

Self-hosting

Self-hosting is the standard way to run Odal Node. You run the engine on infrastructure you control, with your own keys. There are no licence keys, no passport caps, and no features held back for payment. Production self-hosting for your own organisation is free under the engine’s licence.

Docker, a clone of the engine repository, and the odal CLI, which you build once from that clone. The node and resolver are built from the same source the first time you start them. Ready-made container images are not public yet; until they are, a node runs from a clone.

  1. Configure your secrets. The node fails closed without them. Database credentials, a key-store passphrase and your admin login go in a local environment file you create.
  2. Bring it up. Running odal walks you through it: it starts the node, then onboards you and mints your first API key. The first start builds the node from source, which takes a few minutes.
  3. Check its health. odal status confirms the node is up and serving, and shows which of its services are real and which are stand-ins.
  4. Go live carefully. Production deployment covers TLS, the two public addresses and the checks to run first, and Backup, restore and key custody covers what to protect.

The Quick Start is the short version of these steps.

Your signing key is generated and held on your own infrastructure, encrypted at rest, and never leaves it. Everything the node stores stays there too, including the signed passport (the full product data you published, its history and the metadata needed to serve it), drafts, and a record of what each import found, row by row. This holds whoever operates the node; see What Odal can and cannot see.

The engine and the product-group rules change as the regulation does. To update, bring your clone to the new release first (for example, check out its tag), then run odal update: it rebuilds the node and resolver from that source, with the new product-group schemas and fixes, and restarts them. A new signed plugin can be installed on a running node with odal plugin install. A node you never update keeps working, but falls behind the regulation over time.