systemprompt
Stack
Self-owned AI control plane: governance gateway for Claude, OpenAI, and Gemini with policy checks, audit, rate limits, and MCP orchestration. Bundles Postgres. GitHub: systempromptio/systemprompt-template
Source details
Configuration
TypeComposelinuxPOSTGRES_PASSWORD=''ANTHROPIC_API_KEY=OPENAI_API_KEY=GEMINI_API_KEY=EXTERNAL_URL=HTTP_PORT=8080unless-stoppedNotes
Services
postgres
Configuration
Imagepostgres:18-alpine/var/lib/postgresql : postgres_dataPOSTGRES_USER=systempromptPOSTGRES_PASSWORD=${POSTGRES_PASSWORD:-systemprompt}POSTGRES_DB=systempromptunless-stoppedImage details
app
Configuration
Imageghcr.io/systempromptio/systemprompt-template:0${HTTP_PORT:-8080}:8080/app/web : app_web/app/storage/data : app_storage_data/app/services/profiles/docker : app_profilesDATABASE_URL=postgres://systemprompt:${POSTGRES_PASSWORD:-systemprompt}@postgres:5432/systempromptANTHROPIC_API_KEY=${ANTHROPIC_API_KEY:-}OPENAI_API_KEY=${OPENAI_API_KEY:-}GEMINI_API_KEY=${GEMINI_API_KEY:-}EXTERNAL_URL=${EXTERNAL_URL:-}HOST=${HOST:-0.0.0.0}PORT=8080unless-stoppedImage details
Standalone Install
Select an install method, to see config/commands for deploying systemprompt
Install on Portainer
Import all app templates into your Portainer instance, for easy 1-click deploys
- Ensure both Docker and Portainer are installed, and up-to-date
- Log into your Portainer web UI
- Under Settings → App Templates, paste the below URL
- Head to Home → App Templates, and the list of apps will show up
- Select systemprompt, fill in any config options, and hit Deploy
Template Import URL
https://raw.githubusercontent.com/Lissy93/portainer-templates/main/templates.json
Show Me
Original stackfile
The compose file this template deploys, straight from its repo:
# Canonical one-click catalog compose for the systemprompt gateway.
# This is the artifact marketplace catalogs (Portainer, Dokploy, CasaOS,
# CapRover derivatives) reference by raw URL. It runs the published GHCR
# image; the root docker-compose.yml builds from source. Keep the service
# and volume topology in sync — smoke-tests.yml `compose-drift` enforces it.
services:
postgres:
image: postgres:18-alpine
restart: unless-stopped
environment:
POSTGRES_USER: systemprompt
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-systemprompt}
POSTGRES_DB: systemprompt
volumes:
# postgres:18+ images store data under major-version subdirectories of
# /var/lib/postgresql — mounting the old .../data path aborts startup.
- postgres_data:/var/lib/postgresql
healthcheck:
test: ["CMD-SHELL", "pg_isready -U systemprompt -d systemprompt"]
interval: 5s
timeout: 5s
retries: 10
app:
# Floating major tag: picks up minor/patch releases without a template bump.
image: ghcr.io/systempromptio/systemprompt-template:0
restart: unless-stopped
depends_on:
postgres:
condition: service_healthy
environment:
DATABASE_URL: postgres://systemprompt:${POSTGRES_PASSWORD:-systemprompt}@postgres:5432/systemprompt
ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY:-}
OPENAI_API_KEY: ${OPENAI_API_KEY:-}
GEMINI_API_KEY: ${GEMINI_API_KEY:-}
# Public URL of this deployment (https://gateway.example.com);
# used for api_external_url + CORS. Optional.
EXTERNAL_URL: ${EXTERNAL_URL:-}
HOST: ${HOST:-0.0.0.0}
PORT: 8080
ports:
- "${HTTP_PORT:-8080}:8080"
volumes:
- app_web:/app/web
- app_storage_data:/app/storage/data
- app_profiles:/app/services/profiles/docker
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:8080/api/v1/health"]
interval: 30s
timeout: 10s
start_period: 300s
retries: 3
volumes:
postgres_data:
app_web:
app_storage_data:
app_profiles:
Or deploy it directly from the source:
git clone https://github.com/lissy93/portainer-templates
cd portainer-templates
docker compose -f sources/stacks/systemprompt.yml up -dMore install options in our documentation, or see systempromptio/systemprompt-template for app-specific guidance.
Container Documentation
postgres Documentation
The PostgreSQL object-relational database system provides reliability and data integrity.
Check the logs first
Nine times out of ten the logs tell you exactly what went wrong.
- In Portainer, go to Containers, click the container, then Logs. Or run
docker logs <container> - Exit codes help too:
137means killed, usually out of memory.126or127means the command inside the image is broken.
Image won't pull
Test the pull directly on the host: docker pull postgres:18-alpine
- "manifest unknown" means the tag no longer exists.
- "toomanyrequests" is the Docker Hub rate limit. Log in with
docker loginto raise it. - "no space left on device" means a full disk. Reclaim space with
docker system prune
"exec format error"
This means the image was built for a different CPU architecture than your server.
- Check yours with
uname -m: x86_64 is amd64, aarch64 is arm64. Raspberry Pi and other ARM boards are the usual culprits.
Container keeps restarting
The unless-stopped restart policy relaunches the app after every crash, so the real error can scroll past.
- Check the logs right after a restart, the last few lines before it died are the useful ones.
- Get the exit code with
docker inspect <container> --format '{{.State.ExitCode}}' - Still stuck? Redeploy once with the restart policy set to
noso the failure stays visible.
Stack won't deploy
Compose stacks fail fast on small mistakes, and Portainer shows the reason just above the editor.
- YAML only accepts spaces for indentation, a single tab breaks the whole file.
Raise an issue
Found something which isn't working as it should? Here's how to report it.
- Bug within the app: Open an issue on systempromptio/systemprompt-template
- Template not working: Open an issue within the template's repo
- This website not working: Open an issue on lissy93/portainer-templates
A Compose stack
systemprompt is a Compose stack, a set of containers (2 of them) defined in one file and brought up together by Portainer, then started and stopped as a single app.
The services
This stack is built from 2 containers that run side by side. Here's each one, with the image it runs and anything it waits for first:
postgresrunspostgres:18-alpineapprunsghcr.io/systempromptio/systemprompt-template:0, starts after postgres
Volumes
A volume is where systemprompt keeps its files so they survive an update or a restart. Without one, anything it saves would sit inside the container and vanish the moment it's recreated. This template mounts:
/var/lib/postgresqlkept in thepostgres_datavolume Docker manages/app/webkept in theapp_webvolume Docker manages/app/storage/datakept in theapp_storage_datavolume Docker manages/app/services/profiles/dockerkept in theapp_profilesvolume Docker manages
Environment variables
Environment variables are the settings you hand over when you deploy, things like a password or a timezone. systemprompt takes 10 of them, all with defaults you can leave alone or tweak:
POSTGRES_USER, defaults tosystempromptPOSTGRES_PASSWORD, defaults tosystempromptPOSTGRES_DB, defaults tosystempromptDATABASE_URL, defaults topostgres://systemprompt:systemprompt@postgres:5432/systempromptANTHROPIC_API_KEY, pulled from your own environmentOPENAI_API_KEY, pulled from your own environmentGEMINI_API_KEY, pulled from your own environmentEXTERNAL_URL, pulled from your own environmentHOST, defaults to0.0.0.0PORT, defaults to8080
Restart policy
The restart policy here is unless-stopped, so Docker restarts systemprompt after a crash or reboot, but leaves it off when you stop it on purpose. You can change this on the deploy screen. The choices are no (never restart), on-failure (only after a crash), unless-stopped (restart unless you stop it), and always (bring it back no matter what).
Networking
Portainer puts these services on one shared private network, so they can find each other by name (like postgres) while only the ports above are open to you.
Platform
The platform is linux, the kind of system the container is built to run on. Docker and Portainer handle this on a normal Linux server.
Portainer app templates
Zooming out, this whole page comes from a Portainer app template: a short recipe telling Portainer how to set systemprompt up. Add the template list to Portainer once, then deploying systemprompt is a click rather than a wall of config.