Skip to content

Docker

Routes has two images, ghcr.io/mkittleson/routes-central and ghcr.io/mkittleson/routes-node, for x64 and ARM64, and a compose file that runs them with PostgreSQL on one host. It is the quickest way to try Routes, and a sound way to run it.

  1. Download routes-docker-<version>.zip from the download page, unzip it, and go to its routes-docker folder.

  2. Create the environment file and set its two secrets:

    Terminal window
    cp .env.example .env
    openssl rand -base64 24 # use one for POSTGRES_PASSWORD, another for ENROLLMENT_KEY
  3. Start (the images are pulled the first time):

    Terminal window
    docker compose up -d
  4. Read the first administrator’s password:

    Terminal window
    docker compose exec central cat /data/initial-admin-password.txt
  5. Open https://<host>:5080, sign in as admin with that password, and choose your own.

  6. On the Nodes tab, approve node-1: it enrolls by itself with the key from .env, then waits for an administrator before it gets its configuration.

DICOM senders reach the node at <host>:11112, AE title ROUTES.

Service Image Port Volume
postgres postgres:18 (internal) postgres
central routes-central 5080 (HTTPS) central (/data), and central-certificate
node routes-node 11112 (DICOM) node (/data)
  • The images run as an unprivileged user (app); each keeps its data in its /data volume.
  • The central service makes a self-signed certificate and writes its public part to the shared central-certificate volume; the node trusts it from there (Routes__Node__CentralCertificatePath), so nothing needs copying.
  • The node may listen on ports below 1024 (DICOM’s 104) if you set them in the console: the compose file allows it.

Containers take their settings from environment variables, as on Linux. The compose file sets the database connection, the enrollment key and the node’s central address; add others under environment:.

Variable For
Routes__Central__ConnectionString The PostgreSQL connection.
Routes__Central__InitialEnrollmentKey The enrollment key the database starts with, so nodes started at the same time can enroll.
Routes__Central__CertificatePath (and …KeyPath, …Password) A certificate browsers trust, mounted into the container.
Routes__Node__CentralUrl The central service, as the node reaches it.
Routes__Node__ApiKey The enrollment key.
Routes__Node__CentralCertificatePath The central service’s certificate, when it is self-signed.

Copy the node service under another name, with its own hostname, Routes__Node__NodeName, published port and volume. Nodes on other hosts use the same image with the central service’s address, the enrollment key and its certificate’s thumbprint (Routes__Node__CentralCertificateThumbprints).

The compose file of a release runs that release’s images. To move to another version, set it in .env:

TAG=1.0.1

then docker compose pull and docker compose up -d. The central service updates its database schema when it starts.

The node volume holds instances in transit and the node’s own key. A node that loses it needs Reset key on the Nodes tab before it can enroll again (see Adding nodes), and instances not yet delivered are lost with it.