TEA PlatformTEA Docs
Technical DocumentationDeployment

Deployment overview

Choose a deployment layout and configure the services the TEA Platform uses.

Edit on GitHub

The application runs as a Next.js service backed by PostgreSQL. The repository supplies docker-compose.yml for a self-hosted application and database, and .github/workflows/build.yaml deploys the official staging and production builds to Azure App Service. The Docker deployment guide covers the supplied compose layout; the database guide covers migrations and backups.

Deployment layout

The production compose file defines tea_app and postgres. PostgreSQL uses a named volume and has a health check. The application waits for that database health check before starting. Its image entrypoint runs prisma migrate deploy, then starts the Next.js server. The compose file publishes the application on port 3000 by default and stores local uploads in a second named volume.

The compose file names ghcr.io/alan-turing-institute/assuranceplatform:latest, while the Build workflow pushes ghcr.io/alan-turing-institute/assuranceplatform/tea-app; resolve that image-path mismatch before using the compose file to pull a release.

Configuration

Supply secrets through the deployment environment. These variable names come from the compose file and application code, not from an environment example file.

VariableUsed for
DATABASE_URLPostgreSQL connection used by lib/prisma.ts
NEXTAUTH_SECRET, NEXTAUTH_URLSession signing and the public application URL
POSTGRES_DB, POSTGRES_USER, POSTGRES_PASSWORDCompose-managed PostgreSQL; defaults are tea, tea_user and tea_password
TOKEN_ENCRYPTION_KEYBase64 key for stored OAuth tokens; the encryption code requires exactly 32 decoded bytes
GITHUB_APP_CLIENT_ID, GITHUB_APP_CLIENT_SECRETGitHub sign-in and authorised import
GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRETGoogle sign-in and Drive access
USE_LOCAL_STORAGESelects local file storage; compose defaults to true
UPLOADS_DIRLocal upload root when USE_LOCAL_STORAGE is set; defaults to <working directory>/uploads, which the compose file mounts the uploads_data volume onto
AZURE_STORAGE_ACCOUNT_NAME, AZURE_STORAGE_ACCOUNT_KEYAzure Blob storage when configured
ACS_CONNECTION_STRING, ACS_SENDER_ADDRESSEmail through Azure Communication Services
CRON_SECRETAuthenticates scheduled maintenance routes
LOG_LEVELSets the structured logger's threshold
DB_POOL_TIMEOUT_MSDatabase connection wait limit; defaults to 5000 ms

The table covers common settings rather than every application variable. TEA_PLUGINS_DISABLED disables selected compiled plugins; SKIP_ELEMENT_VALIDATION bypasses write-time element validation and must never be set in production. GitHub sign-in also reads GITHUB_APP_CLIENT_ID_STAGING and GITHUB_APP_CLIENT_SECRET_STAGING fallbacks. The compose file exposes only a subset of the application's optional integrations. Set Google, email and cron variables in the hosting environment if you use those features. A deployment should use its own secret values and a database password rather than the compose development defaults. The scheduled jobs page explains the cron routes.

Security and operations

Terminate HTTPS at a proxy or hosting platform and keep PostgreSQL reachable only by the application and administrators who need it. The code implements rate limiting for several sensitive routes and records security audit events; check the rate limiting and audit page for the covered operations. Monitor /api/health as an application endpoint. The supplied compose file health-checks PostgreSQL but does not define an application container health check.

Plan a database backup and restore process before applying a new build. The entrypoint applies pending migrations automatically, but backups and restore tests remain an operator task.

MIT 2026 © Alan Turing InstituteTrustworthy and Ethical Assurance Platform