Self-Hosting Archflow
Run a private, single-organization architecture workspace on your own infrastructure
A self-hosted Archflow installation serves one organization. You control its infrastructure, accounts, architecture data, backups, and upgrade schedule. Members sign in to accounts created by your administrator; they do not need an Archflow SaaS account.
Install And Set Up
Start the Compose stack and create your organization and first administrator
Configure Your Organization
Manage members, shared AI, email, and object storage
Operate And Upgrade
Check service health, preserve backups, and troubleshoot installation issues
No Call Home
The running application does not require an Archflow cloud account, online license activation, or a connection to an Archflow licensing server. There is no automatic check for new releases.
In single-org mode:
- Product-event reporting, Vercel analytics, and speed insights are disabled, including before the browser has finished discovering the deployment mode.
- The supplied Compose configuration disables Next.js telemetry.
- Fonts and application assets are served from the built application.
- Account administration and password-based sign-in work without email or an AI provider.
Architecture content is stored in your configured database and object storage. The web application and background worker do not need a vendor service to operate the architecture editor.
Connections You Choose
No call home does not mean that every possible configuration makes zero external connections. You choose where integrations send requests:
| Configuration or action | Destination and data involved |
|---|---|
| AI assistance and automatic AI analysis | The administrator's configured provider receives the context needed for the request. Use an internal model endpoint to keep processing inside your network. |
| Email delivery | The configured SMTP server receives recipients and message content. Email is optional. |
| External object storage | Your chosen S3 service stores application files. Bundled SeaweedFS keeps those files within the Compose installation. |
| Explicitly configured knowledge services | The endpoint configured by your operator receives the requests made to that integration. |
| URL imports, external images, or opening external links | The application or browser can contact the referenced destination. |
For an isolated installation, restrict runtime outbound access to approved internal services. Apply the corresponding network policy to both servers and user browsers. Verify traffic with your actual integrations and content before treating the whole installation as air-gapped.
Downloads And Updates
Installation and upgrades are operator actions using the Compose file and prebuilt images supplied for the release. Download images from the supplied registry or an internal mirror, or load the image archives you received. These transfers are separate from the running application; customers do not build Archflow from source.
Registry credentials are download credentials. Losing registry access does not stop a downloaded version from running, but it can prevent downloading that same version again as well as obtaining newer ones. Retain the images you deploy, or mirror them internally, so reinstalls and disaster recovery do not depend on continued external registry access.
Follow the setup guide with your received Compose file, environment configuration instructions, and images. Use the registry address, credentials, and release versions provided with your installation package.
What Runs
| Service | Purpose | Persistent data |
|---|---|---|
| Web | Browser application and API | Uses PostgreSQL and object storage |
| Worker | Background jobs and analysis | Uses PostgreSQL, Valkey, and object storage |
| Migrate | Applies database migrations, then exits | Updates PostgreSQL |
| PostgreSQL | Accounts, projects, architecture, and application state | postgres-data volume |
| Valkey | Job queues | queue-data volume |
| SeaweedFS | Private S3-compatible file storage | storage-data volume |
Web, worker, and migrations use the same Archflow image in separate containers. PostgreSQL, Valkey, and SeaweedFS each use their own image. A successful migration container exits normally; it is not expected to stay running.
Organization And Project Access
One installation contains one organization, with administrator and member accounts. Projects still use explicit ownership, group membership, and sharing. Joining the organization does not make every project visible to every member.
Single-org setup requires a clean application database. It does not convert an existing hosted database into an organization. See configuration for member administration and collaboration for project access.