Production setup
A default install is a local demo: well-known passwords, no TLS and chat switched off. Anything that other people can reach needs item 1. Anything on the internet needs all of the items below. Each one says what to change, where, and how to apply it. Work in the folder where you ran the install.
Warning
Rotating the demo passwords (item 1) is the minimum before anyone but you can reach the instance.
Checklist
1. Rotate the demo passwords
Install creates two accounts, demo (administrator) and user (regular), with passwords that are published in the repository.
- Sign in to SEEK and choose My Account, then Edit profile, then Change password, for both accounts.
- To close sign-ups, set Server Admin, then Configure instance, then Allow registration to No.
2. Lock down Django
In docker/nextseek.env, leave DJANGO_DEBUG unset, set DJANGO_ALLOWED_HOSTS to your host name only, and set DJANGO_CSRF_TRUSTED_ORIGINS to your https:// address. Examples and the apply command: NExtSTEPS 1b and 1c.
3. Set the public SEEK address
SEEK is served on its own host name. Set it once, at the first install, with ./startup.sh install --seek-public-url https://seek.example.org (host only, no path; leave it out on a laptop), so that NExtSEEK's links and SEEK's own identifiers agree. Do this before items 2, 4 and 6: running install again writes the config files again from their templates, which undoes those edits. Details: NExtSTEPS 1d.
4. Rotate credentials
- MySQL. Change the passwords inside the running database, then in
docker/db.env, and recreate the services that read it. Leave user names and database names alone, and do not usereset --keep-configfor this: it writes the demo passwords back. Commands: NExtSTEPS 2a. - Neo4j. The password lives in the Neo4j volume after the first start, so editing files alone does nothing. Steps: NExtSTEPS 2b.
- Django secret key. Install generates one. If it was ever logged or shared, replace it; everyone is signed out and old password-reset links stop working. Steps: NExtSTEPS 3.
5. Add TLS
The built-in nginx serves plain HTTP. Put a TLS-terminating reverse proxy (Caddy, nginx with certbot, or a Cloudflare Tunnel) in front of http://localhost:8000, and set DJANGO_CSRF_TRUSTED_ORIGINS to the https:// address (item 2). Options: NExtSTEPS 5.
6. Add LLM keys for Nessie
The chat assistant stays off until you add at least one key in docker/nextseek.env.
GCP_API_KEYfor Google Gemini,AWS_BEARER_TOKEN_BEDROCKfor AWS Bedrock,FDH_APIfor the FAIRDOMHub API.- For AWS Bedrock, put the same token in
NessieAI/docker/bedrock-proxy/proxy-secret.envtoo: the assistant's sandboxed side reads only that file. If you exportAWS_BEARER_TOKEN_BEDROCKbefore you run install, install writes it there for you. Apply that file withdocker compose up -d --no-deps --force-recreate bedrock-proxy.
Apply: docker compose up -d --no-deps --force-recreate nextseek. See Nessie.
7. Set up backups
Back up three things on a schedule: the MySQL databases dmac and seek_production, the Neo4j graph, and the SEEK file store (uploads and blobs). The commands, including the -T flag that keeps a MySQL dump from being corrupted: NExtSTEPS 6.
8. Update safely
- Pull the new code, then run
./startup.sh rebuild. It keeps your data. - If CSS or JavaScript changed, also run
docker compose exec nextseek uv run manage.py collectstatic --noinput. - Check the instance with
./startup.sh doctor.
Note
A rebuild empties the app's media folder, which holds batch-upload jobs in progress. Do not rebuild while an upload is running.
Where each setting lives
| Setting | File | Apply with |
|---|---|---|
| Demo user passwords | SEEK web interface | Immediate |
| MySQL passwords | docker/db.env, plus ALTER USER in the database |
Recreate nextseek, seek and seek_workers |
| Neo4j password | docker/nextseek.env, plus Cypher in the database |
Recreate nextseek |
| Django secret, allowed hosts, CSRF origins | docker/nextseek.env |
Recreate nextseek |
| LLM keys | docker/nextseek.env |
Recreate nextseek |