Self-hosted Temporal

Self-hosted Temporal An architecture diagram generated by Archify. Workers and APIs · client certificate · Architecture component Workers and APIs client certificate mTLS gateway · Caddy :7233 · Temporal host · Docker network temporal mTLS gateway Caddy :7233 Schema setup · admin-tools, each start · Temporal host · Docker network temporal Schema setup admin-tools, each start Temporal server · all four roles · Temporal host · Docker network temporal Temporal server all four roles PostgreSQL · temporal + visibility · Temporal host · Docker network temporal PostgreSQL temporal + visibility Team browser · HTTPS · Architecture component Team browser HTTPS Reverse proxy · TLS · 32k buffers · Architecture component Reverse proxy TLS · 32k buffers Temporal UI · loopback :8080 · Temporal host · Docker network temporal Temporal UI loopback :8080 OIDC provider · e.g. Keycloak · Architecture component OIDC provider e.g. Keycloak gRPC + mTLS h2c SQL migrations HTTPS HTTP gRPC OIDC Temporal host · Docker network temporal Legend Frontend Backend Database Security External

What is exposed

  • • Only the gateway's :7233, and only to certificate holders
  • • The UI binds to a private address behind the proxy
  • • Temporal and PostgreSQL are never published

Startup order

  • • PostgreSQL healthy, then schema setup runs
  • • Server starts once setup succeeds
  • • Namespaces, UI and gateway follow a healthy server

Gotchas

  • • History shard count is fixed forever at first start
  • • SSO cookies exceed nginx's default header buffer
  • • The UI needs PKCE off and the OIDC issuer reachable