Skip to content

System Requirements

Hardware, software, and infrastructure requirements for self-hosting Quackback.

Minimum Requirements

ResourceMinimumRecommended
CPU1 core2+ cores
RAM1 GB2+ GB
Storage10 GB20+ GB
PostgreSQL14+17 or 18

Software Requirements

PostgreSQL

PostgreSQL is the only datastore Quackback needs. It holds your data, the background job queue, caches, rate limits, and realtime events.

RequirementDetails
VersionPostgreSQL 14 or newer
vector extensionpgvector 0.5.0 or newer (HNSW indexes)
pg_trgm extensionShips with the PostgreSQL contrib package
TEMPORARY privilegeThe app's database user needs it. PostgreSQL grants it by default.
Connection modeA direct or session-mode connection. Not a transaction-mode pooler.

Quackback creates both extensions on startup. If the database user can't create extensions, ask a superuser to run CREATE EXTENSION IF NOT EXISTS vector; and CREATE EXTENSION IF NOT EXISTS pg_trgm; once.

Realtime updates use PostgreSQL LISTEN/NOTIFY, which doesn't work through a transaction-mode pooler (for example PgBouncer in transaction mode, or a hosted pooler on port 6543). Point DATABASE_URL at the database directly or at a session-mode pooler.

Before it runs migrations, Quackback checks the server version, both extensions, and the TEMPORARY privilege. If anything is missing it stops without changing the database and names what to fix.

Object storage

File uploads need S3-compatible storage: AWS S3, Cloudflare R2, Backblaze B2, a Railway bucket, or the bundled PGSTY Silo (a maintained MinIO fork) in the Docker Compose stack. Without storage, uploads are disabled.

ComponentVersion
Docker Engine20.10+
Docker Composev2+

The published image is multi-arch (linux/amd64 and linux/arm64), so it runs natively on both x86-64 and ARM hosts (Apple Silicon, AWS Graviton, Ampere, Raspberry Pi).

Bun (Alternative)

If running without Docker:

ComponentVersion
Bun1.4.0+

Network Requirements

Ports

PortPurposeRequired
3000Application (default)Yes
5432PostgreSQLInternal only
9000Bundled object storageInternal only
443HTTPS (via proxy)Production
80HTTP redirectOptional

Domains

You need:

  • A domain or subdomain (e.g., feedback.yourcompany.com)
  • SSL certificate (Let's Encrypt works great)

Outbound Connections

Quackback needs to reach:

  • Email provider (SMTP, Amazon SES, or Resend)
  • OAuth providers (GitHub, Google, etc.)
  • Integration services (Slack, etc.)

Database Requirements

PostgreSQL Configuration

Recommended settings for production:

# Memory
shared_buffers = 256MB
work_mem = 16MB
maintenance_work_mem = 128MB
 
# Connections
max_connections = 100
 
# WAL
wal_level = replica

Storage

Estimate storage needs:

DataSize Estimate
1,000 posts~50 MB
10,000 posts~500 MB
100,000 posts~5 GB

Add headroom for:

  • Attachments (if enabled)
  • Vector embeddings (for AI features)
  • Logs and backups

Backups

Plan for regular backups to prevent data loss. Point-in-time recovery is recommended for production deployments.

  • Daily full backups
  • Point-in-time recovery (recommended)
  • Off-site backup storage

Cloud Provider Options

AWS

ServiceUse
EC2Application server
RDSManaged PostgreSQL
S3File uploads
ALBLoad balancing

Minimum instance: t3.small

Google Cloud

ServiceUse
Compute EngineApplication server
Cloud SQLManaged PostgreSQL
Cloud Load BalancingLoad balancing

Minimum machine: e2-small

DigitalOcean

ServiceUse
DropletApplication server
Managed DatabasePostgreSQL
Load BalancerOptional

Minimum droplet: 2GB RAM

Railway / Render / Fly.io

All support Quackback with managed databases.

VPS Providers

Budget-friendly options:

ProviderMinimum Plan
HetznerCX21 (2GB RAM)
Vultr2GB plan
LinodeNanode 2GB
DigitalOceanBasic 2GB

Security Requirements

TLS/SSL

  • Required for production
  • Use Let's Encrypt (free) or commercial cert
  • Minimum TLS 1.2

Firewall

Allow only:

  • 443 (HTTPS)
  • 80 (HTTP, redirect to HTTPS)
  • 22 (SSH, restricted IPs)

Block:

  • Direct database access
  • Application port from public

Secrets

SECRET_KEY is required and must be at least 32 characters. Generate one with openssl rand -base64 32 and keep it the same across upgrades: it signs sessions and encrypts stored credentials.

Securely manage all secrets including SECRET_KEY, database credentials, OAuth client secrets, and integration tokens. Use environment variables or a secrets management solution.

Plan for scaling

Single Server

Suitable for:

  • Up to 10,000 users
  • Moderate traffic

Scale horizontally

For higher loads, split HTTP serving from background processing across replicas. See Scale with multiple replicas.

Scale the database

Options:

  • Vertical scaling (bigger instance)
  • Read replicas (for read-heavy loads)
  • Connection pooling in session mode (PgBouncer pool_mode = session)

Set up monitoring

Application

  • Health check endpoint
  • Error tracking (Sentry, etc.)
  • Request latency

Database

  • Connection count
  • Query performance
  • Disk usage

Infrastructure

  • CPU utilization
  • Memory usage
  • Disk I/O
  • Network throughput

Next Steps