Operations
This section covers installing, configuring, running, backing up, upgrading and troubleshooting a production installation. For a local development stack see Development setup.
What you are running
Users browse https://<PLATFORM_DOMAIN> (the Hub) and
https://<PLATFORM_DOMAIN>/axis (Axis). New agents and site connectors
connect out to https://<PLATFORM_DOMAIN>/axis, older ones to the
address they enrolled with (Moving Entrosity Hub),
and download from https://<RMM_FILES_DOMAIN>.
All containers are defined in deploy/docker-compose.prod.yml:
| Service | Image | Notes |
|---|---|---|
web | ghcr.io/entrosity/entrosity-web (Caddy + Hub app + Axis portal + documentation) | Ports 80/443 (and 443/udp for HTTP/3); automatic TLS; serves the Hub at /, Axis at /axis/ and the documentation at /docs/; runs as uid 10001. |
backend | ghcr.io/entrosity/axis-backend (distroless, non-root) | Stateless; scale with --scale backend=N. Health check: rmm-server healthcheck. |
migrate | axis-backend | Runs migrate up once, as the database owner, before the backends start. |
platform | ghcr.io/entrosity/hub-backend | Entrosity Hub (platform-server serve): sign-in, users, organizations, roles. Public API on :8080 behind Caddy, internal API on :8081 for the backends only. |
platform-db-init, platform-migrate | postgres:18-alpine, hub-backend | Create the platform database once, then apply the Hub's migrations and enable the platform_app login. |
postgres | postgres:18-alpine | Tuned for a 4 GB host; data in the postgres18-data volume (rmm_postgres18-data in production). |
minio, minio-init | cgr.dev/chainguard/minio (pinned by digest) | Object storage; minio-init creates the bucket and runs the MinIO client for backups. |
Optional: deploy/docker-compose.monitoring.yml adds Prometheus and
Grafana (Monitoring).
The compose network is 172.30.0.0/24; the backend trusts
X-Forwarded-For only from there.
Sizing
Measured with 5,000 simulated agents and 50,000 devices (Performance):
| Fleet | Host |
|---|---|
| Up to 2,000 devices | 2 vCPU, 4 GB RAM, 40 GB SSD, one backend |
| Up to 10,000 devices | 4 vCPU, 8 GB RAM, SSD, two backends; raise PG_SHARED_BUFFERS / PG_EFFECTIVE_CACHE_SIZE |
- About 45 KB of backend memory per connected agent.
- PostgreSQL grows by roughly 1 MB per device per month with the default retention.
Entrosity production
| Entrosity Hub | https://hub.entrosity.com/ (sign-in, product list, administration) |
| Axis | https://hub.entrosity.com/axis/; API https://hub.entrosity.com/axis/api/v1 |
| Agents and connectors | New enrollments: https://hub.entrosity.com/axis. Earlier ones keep https://manage.entrosity.com or https://portal.entrosity.com/manage (old addresses) |
| Documentation | https://hub.entrosity.com/docs/ |
| Host | A VPS (93.123.16.96, since 2026-09-27) with Docker; the stack lives in /opt/entrosity (deploy/ from entrosity-infra). nginx on the same host keeps ports 80/443 for the website, the helpdesk and Vaultwarden and routes the Entrosity names to Caddy (TLS → Behind an existing nginx) |
| DNS | entrosity.com at Cloudflare: hub, manage and portal proxied; files.manage and media DNS only |
| Deploys | Every new main image of a product repository and every change to deploy/ in entrosity-infra (Continuous deployment) |
Sent as [email protected] (Microsoft 365) | |
| ACME / ops contact | [email protected] |