Deployment requirements
What you need before installing Workforce Intelligence: a box, open ports, a GitHub token for the image registry, and a public address.
Workforce Intelligence runs as a set of Docker containers on a single Linux box that you control. This article lists what must be in place before you start either install path (AWS CloudFormation or on-premises).
The box#
You need a Linux machine, virtual or physical, that:
- Runs Docker with the Docker Compose plugin.
install.shinstalls Docker for you when it is missing, and the CloudFormation template installs Docker and the Compose plugin during first boot. - Has
sudoaccess for the account you install with, andopensslavailable (used to generate secrets). - Can reach the internet to pull container images from
ghcr.ioand, if you use a domain, to complete certificate issuance. - Has enough room for Postgres, the application, the web server, the Dokku container, and
the per-company Coworker workbench containers that run on the same Docker daemon. The
CloudFormation template defaults to a
t3.large(2 vCPU, 8 GiB) with a 40 GiB root volume as a starting point.
Ports#
| Port | Used for | Notes |
|---|---|---|
| 80 | Web app over HTTP | Also used for the certificate challenge when you configure a domain. |
| 443 | Web app over HTTPS | Used when you set WI_DOMAIN. |
| 22 (default) | Dokku SSH, where Builders push code for deployed Apps | Change it with WI_DOKKU_SSH_PORT. |
Open these to wherever your users and Builders connect from. You can change the published
HTTP and HTTPS ports with WI_HTTP_PORT and WI_HTTPS_PORT (see
Configuration reference).
The Dokku container publishes its SSH port on the host, and the default is port 22. If the
box's own SSH server already listens on 22, set WI_DOKKU_SSH_PORT to a free port before you
start the stack, and open that port to your Builders.
The CloudFormation template opens ports 80 and 443 (to HttpCidr and HttpsCidr) and port 22
only when you set SshCidr. If your Dokku SSH port is something else, add an inbound rule for
it to the stack's security group yourself.
A GitHub token for the image registry#
The application images are private packages on the GitHub Container Registry (ghcr.io):
wi-server and wi-web, published under the image owner radialventures by default.
You need:
- A GitHub account with read access to the
wi-serverandwi-webpackages. Confirm this on the organization's packages page before you start. Membership in a GitHub organization does not by itself grant read access to every private package. - A classic personal access token for that account with the
read:packagesscope and nothing else. Fine-grained personal access tokens do not work with GHCR. This is a limitation of the GitHub registry, not of Workforce Intelligence.
You provide the username and token once, to install.sh, as GHCR_USER and GHCR_TOKEN.
Docker stores the login on the host, and later pulls and in-app updates reuse it. See
Registry credentials for updates for what to do when the
token expires.
An address for the app#
Decide how people will reach the box before you install:
- A domain name that resolves to the box. With it, Caddy obtains and renews a real certificate and serves HTTPS. See Domains and HTTPS.
- A hostname or IP address with plain HTTP. The app is served, but in production the session cookie is marked secure, so browsers do not keep a sign-in made over plain HTTP. Use a domain with HTTPS for anything people will sign in to.
The address you choose becomes WI_ALLOWED_ORIGIN, for example https://wi.example.com.
Where the box must be reachable from#
If you use a domain with automatic HTTPS, ports 80 and 443 must be reachable from the public internet so the certificate authority can verify the domain. A box behind NAT, such as one in a private subnet routed through a NAT gateway, cannot complete that verification.