Choose a deployment mode
| Mode | Use it for | What changes |
|---|---|---|
| demo | Evaluation and product tours | Adds sample data and keeps external actions in dry-run mode. |
| prod | A persistent business deployment | Runs the production stack without sample business data. |
| dev | Contributing to OpenNeko | Uses the source tree and development services. |
Install one deployment
curl -fsSL https://openneko.app/install.sh | shmkdir -p ~/openneko && cd ~/openneko
openneko setup --mode prodRun setup from the directory that should hold the deployment configuration. OpenNeko writes the stack files there and prompts for the required credentials.
Run several customer instances on one VM
Install the CLI once, then give every customer a stable lowercase instance name. Each named instance gets its own Compose project, databases and volumes, encrypted config and secrets, OpenShell state, backup namespace, runtime markers, ports, and Docker subnet.
openneko --instance acme setup --mode prod --port 3101 --openshell-port 18101 --bind-address 127.0.0.1
openneko --instance globex setup --mode prod --port 3102 --openshell-port 18102 --bind-address 127.0.0.1
openneko instancesThe port and subnet flags are optional for a new named instance: setup selects available values and saves them for later commands. Explicit loopback web ports are useful when a host reverse proxy owns public ports 80 and 443.
acme.example.com {
reverse_proxy 127.0.0.1:3101
}
globex.example.com {
reverse_proxy 127.0.0.1:3102
}openneko --instance acme status
openneko --instance acme logs -f
openneko --instance acme backup now
openneko --instance acme upgradeUpgrade
The CLI upgrade command is the normal upgrade path. It checks the release, updates deployment assets, runs database migrations, and brings the stack back up.
cd ~/openneko
openneko upgrade
openneko statusopenneko upgrade --version <version>For a named installation, add --instance <name> to backup, upgrade, status, and every other customer-specific operation.
Ports and services
| Default port | Service | Purpose |
|---|---|---|
| 3000 | Web | Operator interface and setup; the only network-exposed application boundary. |
| 18080 | OpenShell gateway | Sandbox callback endpoint published on host loopback only. |
Postgres, GraphJin, the worker broker, backup API, registry, and demo data services stay on the private Docker network. Configure the web listener during setup with --port and --bind-address; configure the loopback gateway with --openshell-port.