Archflow
Self-Hosting

Self-Hosting Archflow

Run a private, single-organization architecture workspace on your own infrastructure

A self-hosted Archflow installation serves one organization. You control its infrastructure, accounts, architecture data, backups, and upgrade schedule. Members sign in to accounts created by your administrator; they do not need an Archflow SaaS account.

No Call Home

The running application does not require an Archflow cloud account, online license activation, or a connection to an Archflow licensing server. There is no automatic check for new releases.

In single-org mode:

  • Product-event reporting, Vercel analytics, and speed insights are disabled, including before the browser has finished discovering the deployment mode.
  • The supplied Compose configuration disables Next.js telemetry.
  • Fonts and application assets are served from the built application.
  • Account administration and password-based sign-in work without email or an AI provider.

Architecture content is stored in your configured database and object storage. The web application and background worker do not need a vendor service to operate the architecture editor.

Connections You Choose

No call home does not mean that every possible configuration makes zero external connections. You choose where integrations send requests:

Configuration or actionDestination and data involved
AI assistance and automatic AI analysisThe administrator's configured provider receives the context needed for the request. Use an internal model endpoint to keep processing inside your network.
Email deliveryThe configured SMTP server receives recipients and message content. Email is optional.
External object storageYour chosen S3 service stores application files. Bundled SeaweedFS keeps those files within the Compose installation.
Explicitly configured knowledge servicesThe endpoint configured by your operator receives the requests made to that integration.
URL imports, external images, or opening external linksThe application or browser can contact the referenced destination.

For an isolated installation, restrict runtime outbound access to approved internal services. Apply the corresponding network policy to both servers and user browsers. Verify traffic with your actual integrations and content before treating the whole installation as air-gapped.

Downloads And Updates

Installation and upgrades are operator actions using the Compose file and prebuilt images supplied for the release. Download images from the supplied registry or an internal mirror, or load the image archives you received. These transfers are separate from the running application; customers do not build Archflow from source.

Registry credentials are download credentials. Losing registry access does not stop a downloaded version from running, but it can prevent downloading that same version again as well as obtaining newer ones. Retain the images you deploy, or mirror them internally, so reinstalls and disaster recovery do not depend on continued external registry access.

Follow the setup guide with your received Compose file, environment configuration instructions, and images. Use the registry address, credentials, and release versions provided with your installation package.

What Runs

ServicePurposePersistent data
WebBrowser application and APIUses PostgreSQL and object storage
WorkerBackground jobs and analysisUses PostgreSQL, Valkey, and object storage
MigrateApplies database migrations, then exitsUpdates PostgreSQL
PostgreSQLAccounts, projects, architecture, and application statepostgres-data volume
ValkeyJob queuesqueue-data volume
SeaweedFSPrivate S3-compatible file storagestorage-data volume

Web, worker, and migrations use the same Archflow image in separate containers. PostgreSQL, Valkey, and SeaweedFS each use their own image. A successful migration container exits normally; it is not expected to stay running.

Organization And Project Access

One installation contains one organization, with administrator and member accounts. Projects still use explicit ownership, group membership, and sharing. Joining the organization does not make every project visible to every member.

Single-org setup requires a clean application database. It does not convert an existing hosted database into an organization. See configuration for member administration and collaboration for project access.

On this page