CasePack Self-Hosted Connected.

A private design-partner preview for MSPs that want the incident workflow on infrastructure they control. The first supported profile is a single-server Docker Compose or Podman deployment.

Prerequisites
Private design-partner preview
Docker Compose / Podman

A supported Linux server, Compose-compatible runtime, DNS, TLS, and durable encrypted backups

Sales-assisted enrollment through a protected prompt or fileUnlimited tenants/users; two deployment identities

Deployment Stack

  • Docker Compose / Podman reference profile
  • One supported API replica
  • PostgreSQL + SeaweedFS included
  • Connected licensing with durable local identity

Get CasePack Self-Hosted

Request subscription and installation instructions for your deployment.

Architecture Overview

The private preview uses one tested Docker Compose / Podman profile with one CasePack API replica.

Browser
MSP users
CasePack Web
UI (React)
CasePack API
Spring Boot
Postgres
Database
Object Storage
S3-compatible
Keycloak
OIDC

Users access the CasePack Web UI, which communicates with the Spring Boot API. Authentication flows through the bundled Keycloak realm (OIDC). PostgreSQL stores incident metadata, users, audit entries, and workflow state. Evidence artifacts and exports go to the bundled SeaweedFS S3 gateway or another configured S3-compatible backend.

Security Model

Built for MSP multi-tenancy with security controls that support audit-ready documentation.

Tenant isolation

Tenant isolation enforced server-side on every query. No cross-tenant data leakage.

Evidence integrity

Evidence operations are recorded in the audit trail and included in evidence pack outputs.

SSO via Keycloak

OIDC-based authentication through Keycloak, aligned with the current CasePack app stack.

S3-compatible storage

Use bundled SeaweedFS or an external backend, with separate internal and browser-facing endpoints.

Audit log export

Full activity logs exportable for compliance reviews and incident timelines.

Production hardening

Ingress TLS, exact CORS origins, durable storage, resource limits, and network policies are configurable.

Reference Deployment

The private preview supports the included single-server Docker Compose / Podman profile with one API replica. Other profiles remain demand-gated.

Docker Compose

Single node

Best for: Fast start, VPS, small teams
  • Single-repository Compose stack
  • PostgreSQL + SeaweedFS + Keycloak bundled
  • CasePack API and web app included
  • First-run account and admin bootstrap
Accepted design partners receive a pinned compatibility set, private onboarding instructions, and a guided enrollment session after the deployment canary and launch gates pass.

What you get when deployed

  • Incident management and response timeline
  • S3-backed evidence vault
  • NIS2 milestones and incident reports
  • PDF/ZIP evidence packs with audit history
  • ConnectWise, HaloPSA, Autotask, and generic webhook intake
  • Multi-tenant workspaces and role-based access

Licensing

Connected licensing separates the commercial entitlement from durable deployment identities.

Self-Hosted Connected

An operator runs licensectl enroll through the API image and supplies a short-lived code through a protected prompt or file. The API creates and preserves its installation key and signed credential in a dedicated state volume.

Only licensing metadata leaves the deployment. Incident, evidence, tenant, user, identity-provider, storage, and workflow data are outside the Connected protocol.

30-day credential continuity

The API refreshes about every 24 hours with jitter. A vendor outage does not immediately stop an already enrolled deployment.

Customer data custody

Licensing failure preserves authenticated read and recovery/export paths when customer data exists.

Air-Gapped and Broker modes are roadmap options and are not available in the MVP.

Integrations Roadmap

Start PSA-first. SIEM/EDR connectors come later.

IntegrationStatus
PSA webhook intakeAvailable
SIEM ingestRoadmap
Evidence PortalComing soon

Start with signed PSA webhooks for incident intake. SIEM ingestion and the Evidence Portal are on the roadmap for future releases.

Self-hosted FAQ

Quick answers for deployment and operations.

Not in the MVP. The available private preview uses Connected licensing. Air-Gapped and Broker modes are roadmap options, not currently sold or supported.

Evidence artifacts and exports are stored in your configured S3-compatible object storage. Postgres stores case metadata, users, audit entries, and workflow state.

CasePack uses S3-compatible object storage for evidence and exports. We recommend SeaweedFS as the default self-hosted option. Enterprise environments may also use other compatible backends depending on requirements.

Pull the compatible application image versions and use Docker Compose or Podman to apply the upgrade. Keep PostgreSQL, object storage, and the API-owned licensing-state volume backed up together, review release notes, and pin versions.

The supported reference stack includes Keycloak for OIDC login and API-managed user provisioning. Alternative identity-provider configurations are not part of the first preview support boundary.

Ready for CasePack Self-Hosted?

Request CasePack Self-Hosted and receive subscription and installation instructions.