Self-hosting SigmaPLM
SigmaPLM deploys natively on a single Linux host — no container stack required.
Architecture
| Piece | Technology |
|---|---|
| API | Node 22 + Express 5, managed by PM2 |
| Frontend | Static React SPA served by nginx |
| Database | PostgreSQL 16 |
| Files | Local-filesystem object storage with HMAC-signed URLs |
| TLS | Let's Encrypt via certbot |
| Live updates | WebSocket at /api/ws (nginx Upgrade proxying) |
Environment
Every variable is documented in .env.example at the repo root. Required:
DATABASE_URL, JWT_ACCESS_SECRET, JWT_REFRESH_SECRET, OBJECT_STORAGE_DIR,
OBJECT_URL_SIGNING_SECRET, APP_BASE_URL, PORT. Stripe keys are optional —
billing stays dormant without them.
Deploying
bash deploy.sh # install → build → integration tests → publish → restart
bash deploy.sh --push-db # additionally sync the database schema first
The deploy is gated: the API integration test suite runs against a dedicated test database, and a red suite blocks publication.
Backups & restore
A nightly job dumps the database (pg_dump | gzip) and archives the object-storage
directory, with 30-day rotation. The restore runbook (restore into a fresh database,
swap names, untar the data directory, restart) lives in docs/DEPLOY.md in the
repository.
Hardening
The reference nginx config ships HTTPS-only with HSTS, a Content-Security-Policy,
X-Frame-Options: DENY, per-IP rate limits on the API, and a stricter brute-force
limit on the credential endpoints.