Skip to main content

Self-hosting SigmaPLM

SigmaPLM deploys natively on a single Linux host — no container stack required.

Architecture​

PieceTechnology
APINode 22 + Express 5, managed by PM2
FrontendStatic React SPA served by nginx
DatabasePostgreSQL 16
FilesLocal-filesystem object storage with HMAC-signed URLs
TLSLet's Encrypt via certbot
Live updatesWebSocket at /api/ws (nginx Upgrade proxying)

Environment​

Every variable is documented in .env.example at the repo root. Required: DATABASE_URL, JWT_ACCESS_SECRET, JWT_REFRESH_SECRET, OBJECT_STORAGE_DIR, OBJECT_URL_SIGNING_SECRET, APP_BASE_URL, PORT. Stripe keys are optional — billing stays dormant without them.

Deploying​

bash deploy.sh # install → build → integration tests → publish → restart
bash deploy.sh --push-db # additionally sync the database schema first

The deploy is gated: the API integration test suite runs against a dedicated test database, and a red suite blocks publication.

Backups & restore​

A nightly job dumps the database (pg_dump | gzip) and archives the object-storage directory, with 30-day rotation. The restore runbook (restore into a fresh database, swap names, untar the data directory, restart) lives in docs/DEPLOY.md in the repository.

Hardening​

The reference nginx config ships HTTPS-only with HSTS, a Content-Security-Policy, X-Frame-Options: DENY, per-IP rate limits on the API, and a stricter brute-force limit on the credential endpoints.