Self-hosted deployment
Components, network configuration and maintenance responsibilities to understand before deployment.
Self-hosting keeps identity data in your environment and makes you responsible for configuration, security maintenance and backups. This page helps you prepare. Start with Quickstart for a local evaluation.
Components
| Component | Purpose |
|---|---|
| Server (IdP) | Sign-in, identity protocols and token issuance |
| Admin | User, client and audit administration |
| Me | End-user account self-service |
Use installation and orchestration guidance appropriate to your release package. For integration questions, email hello@pandalabs.cc.
Network and integration configuration
- Configure HTTPS and a trusted reverse proxy for production access. Do not expose the database or internal administration ports directly.
- Use network, domain and proxy configuration appropriate to your environment rather than copying another instance’s settings.
- Check the identity domain, client callback URLs and logout URLs. Your instance’s OIDC Discovery document describes protocol endpoints.
Maintenance and data protection
- Updates: pin release versions and read release notes. Prepare backups and a rollback plan before updating, then check sign-in and account functions.
- Database: follow deployment instructions for schema updates and separate everyday runtime permissions from migration permissions.
- Backups: back up regularly and verify restoration. Reverting an application does not restore its database; check recovery plans before schema changes.
- Secrets: protect database passwords, administrator credentials and client secrets. Keep them out of public repositories, images and logs.
The current Community Preview is intended for evaluation and integration assessment, without an SLA. Read the security guidance and assess configuration and maintenance needs before production use.