Docker
Routes has two images, ghcr.io/mkittleson/routes-central and ghcr.io/mkittleson/routes-node, for x64 and ARM64,
and a compose file that runs them with PostgreSQL on one host. It is the quickest way to try Routes, and a sound way to run it.
Run it
Section titled “Run it”-
Download
routes-docker-<version>.zipfrom the download page, unzip it, and go to itsroutes-dockerfolder. -
Create the environment file and set its two secrets:
Terminal window cp .env.example .envopenssl rand -base64 24 # use one for POSTGRES_PASSWORD, another for ENROLLMENT_KEY -
Start (the images are pulled the first time):
Terminal window docker compose up -d -
Read the first administrator’s password:
Terminal window docker compose exec central cat /data/initial-admin-password.txt -
Open
https://<host>:5080, sign in asadminwith that password, and choose your own. -
On the Nodes tab, approve
node-1: it enrolls by itself with the key from.env, then waits for an administrator before it gets its configuration.
DICOM senders reach the node at <host>:11112, AE title ROUTES.
What runs
Section titled “What runs”| Service | Image | Port | Volume |
|---|---|---|---|
postgres |
postgres:18 |
(internal) | postgres |
central |
routes-central |
5080 (HTTPS) | central (/data), and central-certificate |
node |
routes-node |
11112 (DICOM) | node (/data) |
- The images run as an unprivileged user (
app); each keeps its data in its/datavolume. - The central service makes a self-signed certificate and writes its public part to the shared
central-certificatevolume; the node trusts it from there (Routes__Node__CentralCertificatePath), so nothing needs copying. - The node may listen on ports below 1024 (DICOM’s 104) if you set them in the console: the compose file allows it.
Settings
Section titled “Settings”Containers take their settings from environment variables, as on Linux. The compose file
sets the database connection, the enrollment key and the node’s central address; add others under environment:.
| Variable | For |
|---|---|
Routes__Central__ConnectionString |
The PostgreSQL connection. |
Routes__Central__InitialEnrollmentKey |
The enrollment key the database starts with, so nodes started at the same time can enroll. |
Routes__Central__CertificatePath (and …KeyPath, …Password) |
A certificate browsers trust, mounted into the container. |
Routes__Node__CentralUrl |
The central service, as the node reaches it. |
Routes__Node__ApiKey |
The enrollment key. |
Routes__Node__CentralCertificatePath |
The central service’s certificate, when it is self-signed. |
More nodes
Section titled “More nodes”Copy the node service under another name, with its own hostname, Routes__Node__NodeName, published port and
volume. Nodes on other hosts use the same image with the central service’s address, the enrollment key and its
certificate’s thumbprint (Routes__Node__CentralCertificateThumbprints).
Versions and upgrades
Section titled “Versions and upgrades”The compose file of a release runs that release’s images. To move to another version, set it in .env:
TAG=1.0.1then docker compose pull and docker compose up -d. The central service updates its database schema when it starts.
Backups
Section titled “Backups”The node volume holds instances in transit and the node’s own key. A node that loses it needs Reset key on the
Nodes tab before it can enroll again (see Adding nodes), and instances not yet delivered are lost
with it.
