Before you start
- Explicit ReadWriteMany storage class for uploaded media; bundled PostgreSQL storage or an existing PostgreSQL database
- Stable HTTPS origin; complete the first administrator setup before sharing the URL
- Back up PostgreSQL, media and the stable signing key together
Configuration that needs your attention
Only the HTTP proxy is public. It serves media from a read-only shared mount and forwards the verified HTTPS origin to the private backend.
The backend uses upstream migrations and WhiteNoise static serving, one worker and a stable scoped signing key. All services run as non-root users.
Media files follow upstream public URL behavior. Possession of an uploaded media URL permits downloading that object; use an appropriate storage policy for sensitive files.
Choose bundled PostgreSQL 17 or an existing database. The existing database is not provisioned, upgraded or deleted by Hakopod; startup applies Mathesar migrations to the database you supply.
Required secrets
Configure these scoped secrets during deployment review in your Hakopod installation. Secret values stay out of the application TOML.
-
database-password -
secret-key
This preset needs a public site URL. Set the correct origin before starting the application.
Use this preset
- Open the Catalog in your own Hakopod dashboard and select Mathesar.
- Choose the project, environment, and application name. Set the required values and secret references.
- Review the generated configuration, resource requests, networking, and storage plan.
- Deploy, then inspect readiness and logs. Configure backups for persistent data before relying on the service.
Read the upstream setup documentation ↗
View native TOML and setup notes ↗
Pinned container image
mathesar/mathesar:0.12.0@sha256:091757cb01fec9718d627aa672fdd565d76a2da6b53cdab6264e9fbc031472a4
The catalog pins this image for reproducibility. Review upstream updates and compatibility before changing it.