Running Kombine on your own infrastructure
The same build installs on your own servers against a licence key. Not a reduced edition and not a fork: the same containers the hosted service runs, updated the same way. For some buyers that is the only acceptable answer, so it is supported properly rather than tolerated.
Your data never reaches us in that arrangement. We receive no telemetry about your workspace and no copy of your records. What we provide is the software, the updates and support. What you keep is everything else, including the backups and the decision about who can reach it.
It ships as containers, so the host distribution matters only as far as Docker does. You do not need a copy of the source: the application is in the images, and the deploy bundle is a handful of files.
Minimum
2 vCPU, 4 GB RAM, 40 GB SSD. The container budgets total around 2 GB, which leaves room for the host and Docker itself.
Recommended
4 vCPU, 8 GB RAM, 80 GB SSD. Go here for sites running large imports, and for the disk in any case.
Why 80 GB of disk
Every in-place update leaves the previous image behind, on purpose, because that is what a rollback falls back to. Budget for roughly two versions and do not prune images on a schedule.
Operating system
Ubuntu Server 24.04 LTS is the recommended default and is what the hosted platform runs. Ubuntu 26.04 LTS, Debian 12 and 13, RHEL 9 and 10 using Docker's own repository, Rocky and AlmaLinux 9, and SLES 15 SP6 and later are all fine.
Not supported
CentOS Stream, because it is rolling, and Windows Server with Docker Desktop.
Runtime
Docker Engine with Docker Compose v2. Nothing else to install.
Inbound ports
443 for the application and for any collector agents, 80 so the proxy can redirect to it, and 22 from your own admin network or bastion only. Port 22 should never face the internet, and none of the three are for us.
Outbound
Access to the container registry to pull images, or a registry you mirror yourself. Everything beyond that is per integration and only if you enable it: your Microsoft tenant, your scanners, your own mail relay.
Also needed
A DNS name for the machine, which can be internal, and a certificate. Two secrets are generated at install and are the only ones the product hard-requires.
Updates
An update agent on the box pulls and applies new versions, and a rollback is a redeploy of the previous image. Shell access is permanent rather than install-day only, because upgrades and backups both run there.