SELF-HOSTING · SECURITY BOUNDARIES

Run the workspace in your environment

MIAO runs as one Go process with PocketBase, UI and migrations embedded. One server-side API handles identity, permissions, Agents and background jobs. This page describes only capabilities documented in the source and operations guide.

Implemented in codeNeeds real-environment verificationNot provided: multi-node HA, cloud SLA, SOC compliance

Architecture in the real product

MIAO self-hosting architectureThe browser reaches one Go process through an HTTPS reverse proxy. The process contains the API, Agent, background jobs, UI, migrations and PocketBase. The server connects separately to the AI Gateway and Typesafe Jev; the operator keeps the data directory and backups.BrowserUsers / public read-onlySingle Go process (PM2)API + permissionsAgent + background jobsEmbedded UI / migrationsPocketBase / SQLiteAI GatewayKeys stay server-sideTypesafe JevOfficial endpointData directory / backupsOperator-owned

PM2 only manages the process; the reverse proxy owns public HTTPS, domain and port boundaries. Raw PocketBase admin interfaces, file tokens and backup APIs are not exposed publicly.

Shortest installation path

  1. On a supported Linux or macOS x64/ARM64 environment, install PM2, curl and openssl, then get the release package from GitHub Releases.
  2. Run the installer and confirm the data directory, listen address, encryption key and first platform admin email. After signing in, configure registration, mail, AI, Jev and backup policies in the admin console.
  3. Configure HTTPS at the reverse proxy, then verify the loopback health endpoint, public entry point and one authenticated business flow separately. A 200 health response does not validate models, mail or the production domain.

How requests cross permission boundaries

Workspace / App

Browser requests enter the MIAO API, which rechecks the user, workspace membership, app permissions and field authorization. Knowing a URL grants no data access.

Implemented in code

Agent / background jobs

Agents and background jobs use server-side authorization context, budgets and run receipts; they do not retain browser login tokens for long-running work. Real model accounts and long-running execution still require field verification.

Needs real-environment verification

Public read-only publishing

Public pages return only explicitly authorized record fields and images. They do not expose a workspace or bypass the app publication scope.

Implemented in code

Operations links

The production domain, real mail, AI Gateway, Jev, backup and restore, and reverse proxy all require target-environment verification. This page does not promise multi-node HA, cloud SLA, certification or paid inference quotas.