Self-hosting
Run Grounded on your own infrastructure — what you need, how to install it, and how to operate it.
Grounded runs on Kubernetes. The repository ships a generic Kustomize base, optional components and two example overlays; your install keeps its own overlay in its own repository, references the base at a release tag, and pins the image by digest.
Requirements
Kubernetes, Postgres with pgvector, Valkey, S3, OIDC and a model gateway.
Install on Kubernetes
The base and components, secrets, configuration and the first admin.
Configuration reference
Every environment variable, grouped.
OIDC and SSO
Sign-in, allowed domains, the first admin and group claims.
Model gateways
OpenAI-compatible gateways and self-hosted model tips.
OCR sidecar
The optional Tesseract sidecar for scanned documents.
Observability
Metrics, dashboards, alerts and objectives.
Backups and restore
What to back up and how to restore it.
Upgrades
Release by release, pinning digests and verifying images.
Security
Threat model summary, key rotation and
grounded doctor.Before you rely on it
Grounded is pre-1.0 with one maintainer. Its load tests and restore rehearsal ran on single-node test clusters, and the high-availability topology is validated as manifests but hasn't yet been proven by a long-running install. Load-test your own install and rehearse a restore before you depend on it.