Installation
HridaOne ships as a single Docker image — a Spring Boot process that serves the REST API and the built React frontend from one port.
Prerequisites
- Docker and Docker Compose
- A PostgreSQL instance. The bundled compose file expects an existing
hrida-postgrescontainer on an externalhridaai-network(shared with Hrida AI Studio, separate database); pointSPRING_DATASOURCE_URLat your own if you prefer.
Deploy
cp .env.example .env # fill in the required values
docker compose up -d --buildThe app binds 127.0.0.1:8081 by default (put a reverse proxy in front for TLS). Uploads persist in the uploads_data volume.
Required values
The app refuses to start without these:
| Variable | Notes |
|---|---|
SPRING_DATASOURCE_URL / DB_USERNAME / DB_PASSWORD | The tenant database (JDBC URL plus credentials). |
JWT_SECRET | openssl rand -hex 64 — 64+ chars, never reused across environments. |
GLOBAL_ADMIN_SECRET | openssl rand -hex 32. Guards Global Admin bootstrap. Must differ from JWT_SECRET. |
SECURITY_KEYWORD_ENC_KEY | openssl rand -hex 32. AES key for the encrypted security keyword. Must differ from the others. |
ADMIN_EMAIL / MAIL_FROM / MAIL_USERNAME / MAIL_PASSWORD | SMTP for transactional mail. Gmail needs an App Password with 2-Step Verification on. |
SPRING_JPA_HIBERNATE_DDL_AUTO | update for first deploy / local dev; validate in production — never update on a live database. |
Optional integrations
Leave any of these empty to disable the feature:
| Integration | Variables | Adds |
|---|---|---|
| Cloudinary | CLOUDINARY_NAME / KEY / SECRET | Cloud media uploads instead of the local volume |
| OpenAI OCR | OPENAI_API_KEY, OPENAI_OCR_MODEL | AI extraction of fields from uploaded employee documents |
| Razorpay | RAZORPAY_KEY_ID / KEY_SECRET / WEBHOOK_SECRET | Payment collection and webhooks |
| Keycloak SSO | KEYCLOAK_* | Browser SSO; leave blank for native email / password auth (Authentication) |
| Shared LDAP | LDAP_PROVISIONING_ENABLED, LDAP_URL, LDAP_BASE_DN, LDAP_ADMIN_DN, LDAP_ADMIN_PASSWORD | Auto-provisions ou=<Company> on registration (Authentication) |
Full reference in Configuration.
First run
- Bootstrap the first Global Admin using
GLOBAL_ADMIN_SECRET. - Create a plan (or use the seeded catalog) and the feature catalog.
- Register the first company — this creates its tenant, its Super Admin, and (if LDAP provisioning is on) its directory OU.
- The Super Admin adds admins and employees, sets the security keyword, and configures branded email if wanted.
Deployment mode
Set the platform to SaaS or Enterprise — the latter hides demo requests, the plan catalog, and subscription billing for a dedicated single-customer install. See Administration.