# How is it deployed and self-hosted?

> Open-source personal assistants — a good answer covers: Runtime dependencies (DB, queues, browsers); Docker/one-click paths; required external accounts.

Canonical page: https://llms-technical-reviews.com/personal-assistants/q/deploy/

## Verdict

Both ship Docker paths, but their required services differ.

[OpenBot](/p/openbot/) needs Postgres (the compose file uses the pgvector image), a model key and a CopilotKit Intelligence project, managed or self-hosted; the server refuses to boot without Intelligence. `scripts/start.sh` brings up Postgres, migrations, Bot computers, the API, the routine worker and the app. Production can use a single published image carrying app, API and Chromium, with optional embedded Postgres, or the Helm chart in `charts/openbot`. A supervisor gives each Bot its own computer container; without it, all Bots share one.

[Rakazo](/p/rakazo/) needs only Postgres 16, Docker and a model key. `install-images.sh` writes `.env` with random secrets and starts `postgres`, `supervisor`, `api`, `worker` and `web` from published `edge` images. There is no Redis: jobs and realtime run on Postgres. Computers can be local Docker or hosted E2B, Daytona, CreateOS or Box. `infra/compose` adds a Caddyfile, host hardening and egress restriction scripts.

Rakazo is the simpler fully self-hosted install with no required third-party service. OpenBot fits organisations that already use CopilotKit or want Kubernetes and SSO-oriented deployment.

More projects in this category are being researched.

## Per-project answers

### CopilotKit/OpenBot (answered)

**Runtime dependencies.** The required infrastructure is: PostgreSQL (specifically `pgvector/pgvector:pg17` from docker-compose), CopilotKit Intelligence (managed or self-hosted), and a model provider API key. Docker Compose (`docker-compose.yml`) brings up `postgres`, `migrate` (Drizzle migrations), `agent-computer` (a Playwright/Chromium container per Bot), and optionally SPIRE for workload identity. A single all-in-one Dockerfile (`Dockerfile:1-60`) packages the full stack — app, API, and Chromium browser — for serverless deployment. The supervisor (`server/src/computer/supervisor.ts:1-76`) manages per-Bot computer containers via Docker on a laptop; absent a supervisor, all Bots share one computer (`AGENT_COMPUTER_URL`).

**Quick start path.** The `.env.example` sets `OPENBOT_SINGLE_USER=true` so a fresh clone works without any OAuth client registration. The startup script (`scripts/start.sh`) handles `.env` generation, `docker compose up` for postgres/computer, `bun run dev` for the API and frontend. A CopilotKit Intelligence project is required — the `setup-learning.ts` script provisions it. The example package ships 13 coworkers under `examples/` (General Assistant, Knowledge, Risk Analyst, and 10 fintech-specific agents).

**One-click Docker.** The `Dockerfile` at root builds a single container (`openbot-server`) with Bun, Playwright/Chromium, and all workspace code. It runs the API server + static file serving + a shared browser. The `SERVER_IMAGE` and `COMPUTER_IMAGE` env vars in docker-compose let you publish named release images via `IMAGE_PULL_POLICY=missing`. `docker-compose.yml` is the primary deployment vehicle — it separates postgres onto an isolated `data` network so Bot containers cannot reach the database directly.

**Required external accounts.** A model provider key (OpenAI, Anthropic, or Google), a CopilotKit Intelligence project (free tier available, can be self-hosted via `INTELLIGENCE_API_URL`), and optionally: Composio API key for 200+ SaaS integrations, Google/Microsoft/Okta OAuth credentials for sign-in, and Google Drive API credentials for the Drive connector.


Citations: [docker-compose.yml:1-45](https://github.com/CopilotKit/OpenBot/blob/f4bc60bf9b12c65eb3d7640173f1b3432f6b2a60/docker-compose.yml#L1-L45) · [docker-compose.yml:100-120](https://github.com/CopilotKit/OpenBot/blob/f4bc60bf9b12c65eb3d7640173f1b3432f6b2a60/docker-compose.yml#L100-L120) · [Dockerfile:1-60](https://github.com/CopilotKit/OpenBot/blob/f4bc60bf9b12c65eb3d7640173f1b3432f6b2a60/Dockerfile#L1-L60) · [server/src/computer/supervisor.ts:1-76](https://github.com/CopilotKit/OpenBot/blob/f4bc60bf9b12c65eb3d7640173f1b3432f6b2a60/server/src/computer/supervisor.ts#L1-L76) · [README.md:32-100](https://github.com/CopilotKit/OpenBot/blob/f4bc60bf9b12c65eb3d7640173f1b3432f6b2a60/README.md#L32-L100)

### elie222/rakazo (answered)

**Runtime dependencies.** Rakazo requires PostgreSQL 16 (primary datastore), Docker Engine (for sandboxed computer containers), and optionally Redis (for the supervisor queue). Three processes run: the **API server** (Hono on port 3100), the **Worker** (Graphile Worker background job runner), and the **Web** server (Vite preview serving the React frontend on port 5173). A **supervisor** service manages Docker-based computer sandboxes, listening on port 7091.

**Docker / one-click paths.** The primary deployment mechanism is Docker Compose (`infra/compose/docker-compose.yml`). Services defined: `postgres` (PostgreSQL 16 with healthcheck), `supervisor` (sandbox manager), `computer` (sandbox computer image builder), `data-init` (permissions fixup), `api`, `worker`, and `web`. All images are built from the monorepo via `infra/compose/Dockerfile`. A bootstrap script `infra/compose/install-images.sh` downloads pre-built images from GitHub Container Registry, creates `.env` with random secrets, and starts everything.

**Published images.** Images are tagged `edge` for main branch builds (multi-arch `linux/amd64` + `linux/arm64`). The installer at `install-images.sh` handles the full workflow: download Compose files, create secrets, pull images, `docker compose up`. For restricted networks, `RAKAZO_DOWNLOAD_BASE` overrides the download base URL and `--local` skips existing files.

**Development setup.** Requires Node.js 22.22.2+/24.x/26+ and pnpm 9. After cloning, copy `.env.example`, start Postgres via Docker Compose, then `pnpm install && pnpm db:generate && pnpm db:migrate && pnpm sandbox:build && pnpm dev`. The `pnpm dev` command runs the API, worker, web, and sandbox supervisor concurrently via Turbo.

**Required external accounts.** Rakazo is designed to work without any hosted vendor. Core functionality (model access) requires at minimum an OpenRouter API key (`OPENROUTER_API_KEY`) or another provider's key. Optional accounts: Composio (`COMPOSIO_API_KEY`) for the curated integration catalog, Pipedream (`PIPEDREAM_CLIENT_ID`/`SECRET`/`PROJECT_ID`) for Pipedream workflows, and TypeSafe (`TYPESAFE_API_KEY`) for AI-powered tool review. For voice, ElevenLabs, OpenAI, Cartesia, or Fish Audio keys are optional. Email notification providers (SMTP) are self-hosted.

**Production hardening.** The `infra/compose/` directory includes a `Caddyfile.prod` for HTTPS termination, `harden-host.sh` for system hardening, `restrict-computer-egress.sh` to sandbox computer egress, and `backup-prod.sh` for database backups. Production Docker Compose overlays (`docker-compose.prod.yml`, `docker-compose.prod.docker.yml`) are provided for deployment.

> **Editor's note.** Correction: Redis is not used anywhere in the stack. Background jobs run on Graphile Worker over Postgres, and the local compose file has no Redis service.

Citations: [infra/compose/install-images.sh:1-10](https://github.com/elie222/rakazo/blob/4cdf3e23315c2633b6b3fde8977f197b986f06fa/infra/compose/install-images.sh#L1-L10) · [package.json:12-35](https://github.com/elie222/rakazo/blob/4cdf3e23315c2633b6b3fde8977f197b986f06fa/package.json#L12-L35) · [apps/worker/src/index.ts:60-100](https://github.com/elie222/rakazo/blob/4cdf3e23315c2633b6b3fde8977f197b986f06fa/apps/worker/src/index.ts#L60-L100)
