Skip to content
RehearsalDocs

Install with Docker ComposeSelf-hosted only

Start the API, the console and the workers on one machine, create the first admin key and your sign-in, and check that a build can start.

Time
30 minutes
Needs:
a Linux machine with Docker, a PostgreSQL database or the local one, and a model provider key

At the end of this page the console opens, you are signed in, and a worker is running, so a build can start.

The repository has one Compose file for a full server on one machine: infra/compose.full.yaml. It starts the API with the console, and the workers. By default it uses a database that you give it. With one option it starts a database too.

Before you start

  • Read the Requirements.
  • Install Docker Engine with the Compose plugin, and git.
  • Have a model provider key, for example a Nebius key.

Steps

Get the code

git clone https://github.com/MitudruDutta/rehearsal
cd rehearsal

Run every command on this page from this folder.

Create the settings file

cp infra/deploy.env.example infra/deploy.env

Open infra/deploy.env and set the values below. Never commit this file.

SettingValue
REHEARSAL_SESSION_SECRETA random value. Make one with openssl rand -hex 32
REHEARSAL_DATABASE_URLYour database: see the next step
NEBIUS_API_KEY, or another provider's keyYour model provider key
REHEARSAL_DOMAINYour server's host name. For a test on your own machine, leave the example value

Put comments on their own lines

Compose reads KEY= # text as the value # text. In this file, a comment must be on a line of its own.

Choose the database

Set REHEARSAL_DATABASE_URL to your database. Give Rehearsal its own role and its own schema, not public.

REHEARSAL_DATABASE_URL=postgresql+psycopg://rehearsal:<password>@<host>:5432/postgres?sslmode=verify-full&sslrootcert=/srv/rehearsal/infra/certs/supabase-prod-ca-2021.crt
REHEARSAL_DB_POOL_SIZE=2
REHEARSAL_DB_MAX_OVERFLOW=3

The address above is the form for Supabase. The image contains Supabase's public root certificate at that path, so verify-full checks the server. For another provider, use its own address and certificate settings.

The pool settings keep the server under your database's connection limit. Each process, the API and every worker, can open up to pool size plus overflow connections.

Start the server

docker compose -f infra/compose.full.yaml --env-file infra/deploy.env up -d

With the local database:

docker compose -f infra/compose.full.yaml --env-file infra/deploy.env --profile localdb up -d

The first start builds the image, which takes several minutes. Then Compose applies the database migrations, and starts the API and one worker.

Check that the API answers:

curl http://127.0.0.1:7800/v1/health
You see
{"status":"ok","signup":"closed","google_client_id":null,"client_wheel":null}

The API listens on this machine only, at 127.0.0.1:7800.

Create the first project and admin key

docker compose -f infra/compose.full.yaml --env-file infra/deploy.env exec api rehearsal bootstrap --org Acme
You see
project: prj_7f4a9532b99af3d2
admin API key (shown once): rh_1a2b3c4d_...
export REHEARSAL_API_KEY=rh_1a2b3c4d_...

Save the key now: it is shown once. Keep the project id for the next step.

Create your sign-in

The console needs a person's account. Create yours in the project, so the console shows what your key makes. An account made on the sign-in page would start a new organisation instead:

docker compose -f infra/compose.full.yaml --env-file infra/deploy.env exec api \
  rehearsal users add you@example.com --project <project_id>

The command asks for a password of 10 characters or more, twice.

You see
you@example.com can sign in to the console as owner of project prj_7f4a9532b99af3d2.

Sign in

Open http://localhost:7800 in a browser on the machine and sign in with the email address and password.

To use the server from a terminal:

rehearsal login --url http://localhost:7800

Check that a build can start

In the console, open Applications, choose Load sample applications, then Build world beside one of them. The build view opens, and its first phase starts within a few seconds.

If the build stays "queued", no worker is running: see Troubleshooting.

More workers

One worker does one piece of work at a time. An evaluation run is cut into parts, up to REHEARSAL_RUN_PARALLEL of them, and each part needs a free worker. To run more at once, start more workers:

docker compose -f infra/compose.full.yaml --env-file infra/deploy.env up -d --scale worker=6

Each part of a run also needs a sandbox, which uses 0.3 to 1.5 GB of memory.

A public address with HTTPS

Set REHEARSAL_DOMAIN to your host name, point its DNS record at the machine, and add the public profile:

docker compose -f infra/compose.full.yaml --env-file infra/deploy.env --profile public up -d

A Caddy container then serves https://<your_domain> on ports 80 and 443, with a certificate that it obtains and renews itself.

Settings worth a decision

SettingDefaultDecide
REHEARSAL_SIGNUPopenAny visitor can create an account and an organisation. Set closed on a private server
REHEARSAL_MAX_ACTIVE_BUILDS, REHEARSAL_MAX_ACTIVE_RUNS2 each in the Compose fileHow many builds and runs one workspace may have in progress
REHEARSAL_MONTHLY_ALLOWANCE_USDOffA model spend limit for the whole server, for a calendar month
REHEARSAL_PLANSoffLeave it off on a private server
GOOGLE_CLIENT_IDEmptySet it to offer "Sign in with Google"

After a restart

The API and the workers start again by themselves after a restart of Docker or the machine. The local database container does not: it has no restart rule. If you use --profile localdb, run the up -d command again after a restart.

Update the server

git pull
docker compose -f infra/compose.full.yaml --env-file infra/deploy.env up -d --build

Compose builds the new image, applies the new database migrations, and replaces the containers. Read the changelog in the repository before you update.

Stop the server

docker compose -f infra/compose.full.yaml --env-file infra/deploy.env down

Your data stays: in your database, and in /var/lib/rehearsal on the machine.

Next

Checked against rehearsal-kit 0.1.2 on 11 October 2026.

Was this page helpful?

Edit this page

On this page

Was this page helpful?

Edit this page