Host
Start with Linux, 2 vCPU, 4 GB RAM, 20 GB persistent storage, Docker Engine and Compose, DNS, and time synchronisation.
Deployment
Choose who operates the broker, portal, database, certificates, updates, and backups without changing the mobile experience.
Side-by-side
In both models, the connector initiates the broker connection. The monitoring interface does not need public exposure.
| Deployment detail | LCW Labs Cloud | Self-hosted broker and portal |
|---|---|---|
| Who operates it | LCW Labs operates the broker, database, portal, updates, backups, certificates, and push delivery. | Your organisation operates the broker, PostgreSQL, portal, reverse proxy, certificates, updates, and backups. |
| Monitoring server exposure | No inbound connection. The connector initiates outbound HTTPS. | No inbound connection. The connector initiates outbound HTTPS to your broker. |
| Broker and portal access | Managed service over public HTTPS. | Reachable by authorised apps and connectors over TCP 443 through your selected access path. |
| Inbound ports | No inbound Server Alerts ports in the monitoring network. | TCP 443 at the broker. TCP 80 is optional for ACME. PostgreSQL 5432 and broker 8080 stay private. |
| Monitoring data | Stored in the managed Server Alerts database. | Snapshots, queues, users, dashboards, alerts, and audit records stay in your PostgreSQL database. |
| Identity | Managed accounts and configured organisation SSO. | Local portal roles, seat controls, administration, and per-organisation OIDC. |
| HTTPS certificates | Provisioned and monitored by LCW Labs. | Automatic public HTTPS or your own public/internal CA certificate. Internal CA trust must also be deployed to every client device. |
Self-hosted requirements
The supported Compose stack includes the broker, PostgreSQL 16, Caddy HTTPS, private networking, readiness checks, volumes, and backups.
Start with Linux, 2 vCPU, 4 GB RAM, 20 GB persistent storage, Docker Engine and Compose, DNS, and time synchronisation.
Inbound TCP 443, optional TCP 80 for ACME, and outbound TCP 443 for identity, licensing, updates, and push relay.
Your organisation manages availability, certificates, backups, disaster recovery, access, and supported updates.
HTTPS certificates
An internally issued certificate works when its CA trust is installed on every mobile device and browser accessing the broker.