CasePack Self-Hosted Connected.
A private design-partner preview for MSPs that want the incident workflow on infrastructure they control. The first supported profile is a single-server Docker Compose or Podman deployment.
A supported Linux server, Compose-compatible runtime, DNS, TLS, and durable encrypted backups
Deployment Stack
- Docker Compose / Podman reference profile
- One supported API replica
- PostgreSQL + SeaweedFS included
- Connected licensing with durable local identity
Get CasePack Self-Hosted
Request subscription and installation instructions for your deployment.
Architecture Overview
The private preview uses one tested Docker Compose / Podman profile with one CasePack API replica.
Users access the CasePack Web UI, which communicates with the Spring Boot API. Authentication flows through the bundled Keycloak realm (OIDC). PostgreSQL stores incident metadata, users, audit entries, and workflow state. Evidence artifacts and exports go to the bundled SeaweedFS S3 gateway or another configured S3-compatible backend.
Security Model
Built for MSP multi-tenancy with security controls that support audit-ready documentation.
Tenant isolation
Tenant isolation enforced server-side on every query. No cross-tenant data leakage.
Evidence integrity
Evidence operations are recorded in the audit trail and included in evidence pack outputs.
SSO via Keycloak
OIDC-based authentication through Keycloak, aligned with the current CasePack app stack.
S3-compatible storage
Use bundled SeaweedFS or an external backend, with separate internal and browser-facing endpoints.
Audit log export
Full activity logs exportable for compliance reviews and incident timelines.
Production hardening
Ingress TLS, exact CORS origins, durable storage, resource limits, and network policies are configurable.
Reference Deployment
The private preview supports the included single-server Docker Compose / Podman profile with one API replica. Other profiles remain demand-gated.
Docker Compose
Single node
- Single-repository Compose stack
- PostgreSQL + SeaweedFS + Keycloak bundled
- CasePack API and web app included
- First-run account and admin bootstrap
What you get when deployed
- Incident management and response timeline
- S3-backed evidence vault
- NIS2 milestones and incident reports
- PDF/ZIP evidence packs with audit history
- ConnectWise, HaloPSA, Autotask, and generic webhook intake
- Multi-tenant workspaces and role-based access
Licensing
Connected licensing separates the commercial entitlement from durable deployment identities.
Self-Hosted Connected
An operator runs licensectl enroll through the API image and supplies a short-lived code through a protected prompt or file. The API creates and preserves its installation key and signed credential in a dedicated state volume.
Only licensing metadata leaves the deployment. Incident, evidence, tenant, user, identity-provider, storage, and workflow data are outside the Connected protocol.
The API refreshes about every 24 hours with jitter. A vendor outage does not immediately stop an already enrolled deployment.
Licensing failure preserves authenticated read and recovery/export paths when customer data exists.
Air-Gapped and Broker modes are roadmap options and are not available in the MVP.
Integrations Roadmap
Start PSA-first. SIEM/EDR connectors come later.
| Integration | Status |
|---|---|
| PSA webhook intake | Available |
| SIEM ingest | Roadmap |
| Evidence Portal | Coming soon |
Start with signed PSA webhooks for incident intake. SIEM ingestion and the Evidence Portal are on the roadmap for future releases.
Self-hosted FAQ
Quick answers for deployment and operations.
Ready for CasePack Self-Hosted?
Request CasePack Self-Hosted and receive subscription and installation instructions.