The marketing website serves public product pages and documentation. The Ralti application requires a Node 24 runtime, persistent private files, a configured database, Clerk, and supervised workers. Publishing the website does not provision the application server or distribute the native app. A useful domain layout is your-domain.example for the public site and app.your-domain.example for the product.
Build and start#
Prepare .env.production.local from .env.production.example, place credentials in the host’s private secret system, and apply database migrations with a separate administrator environment. Prepare the persistent data directory deliberately, with ownership compatible with the image’s unprivileged node user. Preserve existing uploads and encryption keys when moving a live installation.
docker compose --env-file .env.production.local config --quiet
docker compose --env-file .env.production.local build web
docker compose --env-file .env.production.local up -d web
curl --fail http://127.0.0.1:3000/api/health
# After reviewing imported queues and outbound settings:
docker compose --env-file .env.production.local up -d workerThe host port binds to loopback. Put an HTTPS reverse proxy or managed TLS ingress in front of it, preserve host and forwarded protocol, support streaming, and avoid caching authenticated HTML or API responses. The Clerk publishable key is compiled into the web bundle; moving to another Clerk application requires a rebuild. The Docker build receives its Clerk secret through a BuildKit secret mount.
Connect the purchased domain#
- Add the public site and app hostnames to their respective hosts; use the exact DNS records those hosts return.
- Choose a canonical apex or www website host and permanently redirect the alternative. Preserve existing mail DNS.
- Update ATLAS_PUBLIC_ORIGIN, Clerk authorized origins, and exact registered email OAuth callbacks.
- Update the website’s canonical, sitemap, structured-data, social-image, and app-link origins.
- Verify TLS, sign-in, record persistence, files, worker outcomes, device access, and a restored backup.