Skip to main content
Version: 2.x (Latest)

Docker

Run Authorizer using Docker with the v2 CLI-only configuration model.


Quick Start​

docker run -p 8080:8080 quay.io/authorizer/authorizer:latest \
--database-type=sqlite \
--database-url=test.db \
--url=http://localhost:8080 \
--jwt-type=HS256 \
--jwt-secret=test \
--encryption-key=test-encryption-key \
--admin-secret=admin \
--client-id=123456 \
--client-secret=secret

Persisting data across restarts​

The command above writes test.db inside the container, so every restart starts from an empty database. Mount a named volume and put SQLite on it:

docker run -p 8080:8080 -u root \
-v authorizer_data:/authorizer/data \
quay.io/authorizer/authorizer \
--database-type=sqlite \
--database-url=/authorizer/data/data.db \
--url=http://localhost:8080 \
--client-id=123456 \
--client-secret=secret \
--admin-secret=admin \
--jwt-type=HS256 \
--jwt-secret=test \
--encryption-key=test-encryption-key

-u root is needed because the image runs as uid 1000 (authorizer), and a named volume mounted at a path the image does not already own is created root-owned — without it the process cannot create the database file. Drop it once you chown the volume, or use a managed database instead.

Then open http://localhost:8080/app for the built-in login UI.


Ports: EXPOSE, publishing, and metrics​

The image EXPOSEs 8080, 8081, and 9091. That only documents which ports the application may listen on; it does not open them on the Docker host. You choose what to publish with -p or Compose ports:.

PortRoleTypical use
8080Main HTTP (API, UI, /healthz, /readyz)Yes — map to the host or front with a reverse proxy / load balancer.
8081Prometheus /metrics (separate listener)Depends — see below.
9091gRPC API (AuthorizerService + AuthorizerAdminService)Optional — publish only if external gRPC clients connect; see gRPC API.

Recommended defaults

  • docker run (single container, no in-Docker Prometheus): publish only 8080 (e.g. -p 8080:8080). Metrics stay on 127.0.0.1:8081 inside the container; that is enough if you scrape from an agent on the same host using the container’s network namespace, or you do not need metrics yet.
  • Docker Compose / Swarm with Prometheus as another service: add --metrics-host=0.0.0.0 so 8081 accepts connections on the internal compose network. Prefer not adding "8081:8081" under ports: (avoids exposing metrics on the host). Prometheus should use a service DNS name like http://authorizer:8081/metrics on the internal network only.
  • gRPC clients: the gRPC server binds to --host (default 0.0.0.0) on 9091. For server-to-server calls on the same Docker/Compose network, dial the service name (e.g. authorizer:9091) — no host publishing needed. Only add -p 9091:9091 (or "9091:9091" under ports:) when a client outside Docker must reach it. gRPC is served as plaintext h2c by default — terminate TLS at an ingress/proxy (or set --grpc-tls-cert / --grpc-tls-key) before exposing it publicly.
  • Public internet: never publish 8081 to a public address. Keep metrics on loopback or an internal network; use auth/network policy at the edge if you must expose a scrape path.

Health checks: the image HEALTHCHECK calls http://127.0.0.1:8080/healthz on the main server only, so liveness works even when metrics are loopback-only.


Using with PostgreSQL​

docker run -p 8080:8080 quay.io/authorizer/authorizer:latest \
--database-type=postgres \
--database-url="postgres://user:pass@host:5432/authorizer" \
--url=http://localhost:8080 \
--jwt-type=HS256 \
--jwt-secret=your-jwt-secret \
--encryption-key=test-encryption-key \
--admin-secret=your-admin-secret \
--client-id=123456 \
--client-secret=secret

Docker Compose​

Create a docker-compose.yml:

version: "3.8"
services:
authorizer:
image: quay.io/authorizer/authorizer:latest
ports:
- "8080:8080"
command:
- "--database-type=sqlite"
- "--database-url=/data/test.db"
- "--url=http://localhost:8080"
- "--jwt-type=HS256"
- "--jwt-secret=test"
- "--encryption-key=test-encryption-key"
- "--admin-secret=admin"
- "--client-id=123456"
- "--client-secret=secret"
volumes:
- authorizer_data:/data

volumes:
authorizer_data:

Start with:

docker compose up -d

Docker Compose with PostgreSQL and Redis​

version: "3.8"
services:
postgres:
image: postgres:15
environment:
POSTGRES_USER: authorizer
POSTGRES_PASSWORD: secret
POSTGRES_DB: authorizer
volumes:
- pg_data:/var/lib/postgresql/data

redis:
image: redis:7-alpine
ports:
- "6379:6379"

authorizer:
image: quay.io/authorizer/authorizer:latest
ports:
- "8080:8080"
depends_on:
- postgres
- redis
command:
- "--database-type=postgres"
- "--database-url=postgres://authorizer:secret@postgres:5432/authorizer"
- "--url=http://localhost:8080"
- "--redis-url=redis://redis:6379"
- "--jwt-type=HS256"
- "--jwt-secret=test"
- "--encryption-key=test-encryption-key"
- "--admin-secret=admin"
- "--client-id=123456"
- "--client-secret=secret"
- "--env=production"

volumes:
pg_data:

Using Environment Variables with v2​

The v2 server does not read from .env files or OS env vars directly. To use env vars in your deployment, map them into CLI flags:

docker run -p 8080:8080 \
-e DATABASE_TYPE=sqlite \
-e DATABASE_URL=test.db \
-e JWT_SECRET=test \
-e ENCRYPTION_KEY=test-encryption-key \
-e ADMIN_SECRET=admin \
-e CLIENT_ID=123456 \
-e CLIENT_SECRET=secret \
quay.io/authorizer/authorizer:latest \
--database-type="$DATABASE_TYPE" \
--database-url="$DATABASE_URL" \
--url=http://localhost:8080 \
--jwt-type=HS256 \
--jwt-secret="$JWT_SECRET" \
--encryption-key="$ENCRYPTION_KEY" \
--admin-secret="$ADMIN_SECRET" \
--client-id="$CLIENT_ID" \
--client-secret="$CLIENT_SECRET"

Required Variables​

FlagDescriptionExample
--database-typeDatabase typesqlite, postgres, mysql
--database-urlDatabase connection stringtest.db
--urlThis server's own public base URL (required)https://auth.example.com
--jwt-typeJWT signing algorithmHS256, RS256
--jwt-secretJWT signing secret (for HS256)test
--admin-secretAdmin secret for admin operationsadmin
--client-idClient identifier (required)123456
--client-secretClient secret (required)secret

For all available flags, see Server Configuration.