Deployment overview
Choose a deployment layout and configure the services the TEA Platform uses.
Edit on GitHubThe application runs as a Next.js service backed by PostgreSQL. The repository supplies docker-compose.yml for a self-hosted application and database, and .github/workflows/build.yaml deploys the official staging and production builds to Azure App Service. The Docker deployment guide covers the supplied compose layout; the database guide covers migrations and backups.
Deployment layout
The production compose file defines tea_app and postgres. PostgreSQL uses a named volume and has a health check. The application waits for that database health check before starting. Its image entrypoint runs prisma migrate deploy, then starts the Next.js server. The compose file publishes the application on port 3000 by default and stores local uploads in a second named volume.
The compose file names ghcr.io/alan-turing-institute/assuranceplatform:latest, while the Build workflow pushes ghcr.io/alan-turing-institute/assuranceplatform/tea-app; resolve that image-path mismatch before using the compose file to pull a release.
Configuration
Supply secrets through the deployment environment. These variable names come from the compose file and application code, not from an environment example file.
| Variable | Used for |
|---|---|
DATABASE_URL | PostgreSQL connection used by lib/prisma.ts |
NEXTAUTH_SECRET, NEXTAUTH_URL | Session signing and the public application URL |
POSTGRES_DB, POSTGRES_USER, POSTGRES_PASSWORD | Compose-managed PostgreSQL; defaults are tea, tea_user and tea_password |
TOKEN_ENCRYPTION_KEY | Base64 key for stored OAuth tokens; the encryption code requires exactly 32 decoded bytes |
GITHUB_APP_CLIENT_ID, GITHUB_APP_CLIENT_SECRET | GitHub sign-in and authorised import |
GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET | Google sign-in and Drive access |
USE_LOCAL_STORAGE | Selects local file storage; compose defaults to true |
UPLOADS_DIR | Local upload root when USE_LOCAL_STORAGE is set; defaults to <working directory>/uploads, which the compose file mounts the uploads_data volume onto |
AZURE_STORAGE_ACCOUNT_NAME, AZURE_STORAGE_ACCOUNT_KEY | Azure Blob storage when configured |
ACS_CONNECTION_STRING, ACS_SENDER_ADDRESS | Email through Azure Communication Services |
CRON_SECRET | Authenticates scheduled maintenance routes |
LOG_LEVEL | Sets the structured logger's threshold |
DB_POOL_TIMEOUT_MS | Database connection wait limit; defaults to 5000 ms |
The table covers common settings rather than every application variable. TEA_PLUGINS_DISABLED disables selected compiled plugins; SKIP_ELEMENT_VALIDATION bypasses write-time element validation and must never be set in production. GitHub sign-in also reads GITHUB_APP_CLIENT_ID_STAGING and GITHUB_APP_CLIENT_SECRET_STAGING fallbacks. The compose file exposes only a subset of the application's optional integrations. Set Google, email and cron variables in the hosting environment if you use those features. A deployment should use its own secret values and a database password rather than the compose development defaults. The scheduled jobs page explains the cron routes.
Security and operations
Terminate HTTPS at a proxy or hosting platform and keep PostgreSQL reachable only by the application and administrators who need it. The code implements rate limiting for several sensitive routes and records security audit events; check the rate limiting and audit page for the covered operations. Monitor /api/health as an application endpoint. The supplied compose file health-checks PostgreSQL but does not define an application container health check.
Plan a database backup and restore process before applying a new build. The entrypoint applies pending migrations automatically, but backups and restore tests remain an operator task.