Docker Compose
Docker Compose builds and runs TomoriBot and PostgreSQL as containers. It’s the third install path alongside the setup wizard and manual setup: pick it when you’d rather run everything in Docker than install Bun and PostgreSQL on the host. It does not use the setup wizard; the database connection is auto-configured for you.
1. Get the code
Section titled “1. Get the code”git clone https://github.com/Bredrumb/TomoriBot.gitcd TomoriBot2. Required .env values
Section titled “2. Required .env values”Start from the example file:
cp .env.example .envThen set at minimum:
| Variable | Value |
|---|---|
DISCORD_TOKEN | Your Discord bot token (enable the GuildMembers, MessageContent, and GuildPresences privileged intents). |
CRYPTO_SECRET | A 32-character encryption key used to encrypt stored API keys. |
POSTGRES_PASSWORD | The database password. Every other POSTGRES_* value is auto-configured. |
Generate a random 32-character value for CRYPTO_SECRET using Docker, then copy it into .env:
docker run --rm alpine:3.22 sh -c "head -c 24 /dev/urandom | base64"Generate a separate value for POSTGRES_PASSWORD. Optional tuning values can be copied from
.env.optional.example.
On Linux, create the host directories and give the container user (UID 1001) ownership before the first start. Docker creates missing bind-mount directories as root, which prevents the bot from writing backups, logs, or uploaded data.
mkdir -p backups logs datasudo chown 1001:1001 backups logs data3. Build and run
Section titled “3. Build and run”docker compose build # first time, or after code/dependency changesdocker compose up # bot + databaseFor later starts, docker compose up alone is enough unless you changed code or
dependencies. When the bot is online, run /setup in Discord to add your AI
provider key: see the Quickstart for the in-Discord side.
Compose uses RUN_ENV=development so .env secrets and local HTTP endpoints work. The app
healthcheck reports whether its process is running; it does not test Discord connectivity.
RUN_ENV=production loads secrets from a secret manager or mounted JSON file and enforces HTTPS
and private-network URL restrictions. It also changes command registration and enables the health
HTTP server and metrics collector. The Compose configuration pins development mode.
4. Optional local servers (Compose profiles)
Section titled “4. Optional local servers (Compose profiles)”Local servers are opt-in via Compose profiles, so you only run what you need:
# SearXNG (private web search) + Crawl4AI (browser-rendered fetch)docker compose --profile searxng --profile fetch-crawl4ai upSet SEARXNG_BASE_URL=http://searxng:8080/ in .env when enabling the SearXNG profile.
Leave it unset otherwise. Set SEARXNG_SECRET to a separate random value for the SearXNG
signing key.
See SearXNG, Crawl4AI, and Local Monitoring for per-server details.
Maintenance, updating & backups
Section titled “Maintenance, updating & backups”Use bun run update --docker for the backup-first update procedure on a Compose
deployment. Backing up and restoring the Compose database is covered on the
Maintenance & Backups page. Before pulling a
new version, start with Safe Migration.