◆docpipe
Product
Docs
GitHubPyPI v0.7.0
All documentation

Docker / Production

Run Docpipe in a containerized environment.

Docker / Production

Use the maintained GHCR profile images and Compose examples as a starting point. Production operators remain responsible for ingress, secret management, storage, and capacity planning.

Source: Production deployment guidanceSource: Published image workflowSource: Compose examples

The current Docker workflow publishes `:slim`, `:balanced` (default), `:quality`, `:agents`, and `:mcp` profiles from the Python 3.13 image. `profile-gpu` exists as a pip extra but is not currently in the published image matrix.

Pull & run API
# Profile-tagged images (GHCR)
docker pull ghcr.io/thesunnysinha/docpipe:balanced
docker pull ghcr.io/thesunnysinha/docpipe:slim
docker pull ghcr.io/thesunnysinha/docpipe:quality
docker pull ghcr.io/thesunnysinha/docpipe:agents
docker pull ghcr.io/thesunnysinha/docpipe:mcp

# API server — .env: OPENAI_API_KEY, DOCPIPE_PASSWORD, etc.
docker run -p 8000:8000 --env-file .env -v ./data:/data \
  ghcr.io/thesunnysinha/docpipe:balanced

# curl -u admin:password http://localhost:8000/health
# curl -u admin:password http://localhost:8000/admin
# curl http://localhost:8000/metrics

# One-off parse / ingest
docker run -v ./data:/data ghcr.io/thesunnysinha/docpipe:balanced \
  parse /data/invoice.pdf
Internal shared stack (no bundled Postgres)
# Shared internal API — each app passes its own connection_string
# See: github.com/thesunnysinha/docpipe/tree/main/examples/internal-shared
services:
  docpipe:
    image: ghcr.io/thesunnysinha/docpipe:balanced
    ports:
      - "8000:8000"
    env_file: .env
    environment:
      DOCPIPE_CONTROL_DB_ENABLED: "true"
      DOCPIPE_CONTROL_DB_PATH: /data/docpipe.db
      DOCPIPE_PERSIST_AUDIT_EVENTS: "true"
      DOCPIPE_ALLOW_PRIVATE_URLS: "true"
    volumes:
      - ./data:/data
    restart: unless-stopped

# cp .env.example .env && docker compose up -d
Standalone pgvector example
# docpipe + pgvector — local dev
# Full examples: github.com/thesunnysinha/docpipe/tree/main/examples
services:
  docpipe:
    image: ghcr.io/thesunnysinha/docpipe:balanced
    ports:
      - "8000:8000"
    env_file: .env
    environment:
      DOCPIPE_DB_CONNECTION_STRING: postgresql://docpipe:docpipe@db:5432/docpipe
      DOCPIPE_CONTROL_DB_ENABLED: "true"
      DOCPIPE_CONTROL_DB_PATH: /data/docpipe.db
    volumes:
      - ./data:/data
    depends_on:
      db:
        condition: service_healthy
    restart: unless-stopped

  db:
    image: pgvector/pgvector:pg16
    environment:
      POSTGRES_USER: docpipe
      POSTGRES_PASSWORD: docpipe
      POSTGRES_DB: docpipe
    ports:
      - "5432:5432"
    volumes:
      - pgdata:/var/lib/postgresql/data
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U docpipe"]
      interval: 5s
      timeout: 5s
      retries: 5
    restart: unless-stopped

volumes:
  pgdata:

# cp .env.example .env && docker compose up -d
VariableExample / defaultPurpose
OPENAI_API_KEYsk-...Embedding / LLM when using OpenAI
DOCPIPE_DB_CONNECTION_STRINGpostgresql://docpipe:docpipe@db:5432/docpipeDefault pgvector URL (health + examples)
DOCPIPE_DB_TABLE_NAMEdocumentsDefault collection name
DOCPIPE_EMBEDDING_PROVIDERopenaiEmbedding vendor
DOCPIPE_EMBEDDING_MODELtext-embedding-3-smallEmbedding model id
DOCPIPE_PROFILEbalancedInstall profile: slim, balanced, quality, agents, mcp
DOCPIPE_DEFAULT_RUNTIME_PRESETbalancedDefault API preset when omitted
DOCPIPE_CONTROL_DB_ENABLEDfalseSQLite/Postgres for admin + optional audit
DOCPIPE_PERSIST_AUDIT_EVENTSfalseStore plugin policy audit rows
DOCPIPE_AUTH_ENABLEDtrueHTTP Basic Auth on API + /admin
DOCPIPE_USERNAMEadminBasic Auth user
DOCPIPE_PASSWORDdocpipeBasic Auth password — change in prod
DOCPIPE_ALLOW_PRIVATE_URLSfalseAllow private-network HTTP source URLs (trusted networks only)
DOCPIPE_OTEL_ENABLEDfalseOpenTelemetry traces
DOCPIPE_RATE_LIMIT_ENABLEDtruePer-preset POST rate limits
  • Images: ghcr.io/thesunnysinha/docpipe — current profile tags :slim, :balanced (default), :quality, :agents, and :mcp, plus release tags.
  • Shared internal API: use examples/internal-shared — no bundled Postgres; each app passes connection_string per request.
  • Vector/RAG data lives in each project's Postgres. Control-plane SQLite (optional) stores admin + opt-in audit only.
  • Runtime presets on API: preset=fast|balanced|quality|agents on /ingest and /rag/query. Discover via GET /profiles.
  • Sidecar: run docpipe on app Docker network; callers use http://docpipe:8000 with Basic Auth.
  • Private-network HTTP source URLs: DOCPIPE_ALLOW_PRIVATE_URLS=true only when the service and network are trusted.
  • Admin panel: GET /admin when DOCPIPE_CONTROL_DB_ENABLED=true.
  • Full Docker examples + env reference: github.com/thesunnysinha/docpipe/tree/main/examples
  • Scrape GET /metrics (no auth) for Prometheus; optional DOCPIPE_OTEL_* for traces.