Production-shaped RVBox Linux-server Compose deployment
This directory is intentionally separate from the development/toolchain Compose
files. It starts only the Linux server and nginx TLS terminator; Windows clients
connect through nginx at /v1/agent.
Before the first start, create server.toml from the authoritative example:
cp ../../docs/examples/server.toml server.toml
chmod 0640 server.toml
Set RVBOX_SERVER_IMAGE to an immutable image reference, plus absolute paths
for RVBOX_TLS_CERT and RVBOX_TLS_KEY. The TLS key must be readable by Docker
but should remain inaccessible to ordinary host users. Validate before start:
docker compose -f compose.yaml config
docker compose -f compose.yaml up -d
The stack's init container creates the two named volumes with the runtime
ownership required by the non-root server. server-data is the sole persistent
data volume and must be backed up as a whole while the server is stopped;
server-run contains only the ephemeral local control socket. Do not publish,
proxy, or enable JSON-RPC except for intentional loopback debugging.