Skip to content

Docker deployment reference

Silo is in active development before 1.0. These guides are updated frequently.

For a new server, follow Install Silo Server. This reference explains the default stack and where to make later changes.

The image is ghcr.io/silo-server/silo-server, built for Linux x86-64 and arm64. Each published build gets three tags:

TagMeaning
latestMoves to each new build from main
build-NOrdered build number; a larger number is newer
Short commit SHAThe exact source the build came from

Set SILO_IMAGE in .env to a build-N tag, commit tag, or image digest when the server must not move with latest. Run docker compose images silo to see what you are running.

ServiceRole
siloWeb app, API, scanning, and playback
postgresPostgreSQL 18 with pgvector
redisShared coordination and cache state

Each service has a health status in docker compose ps. For what Silo’s health and readiness checks mean, see Check server health.

Change a host port in .env when it conflicts with another service. The container ports stay fixed.

VariableDefaultServes
PORT8090Silo web app, API, and native apps
JF_PORT8096Jellyfin-compatible apps
ABS_PORT13378Audiobookshelf-compatible apps (Beta)
POSTGRES_PORT5432PostgreSQL, on the host’s loopback address only
REDIS_PORT6379Redis, on the host’s loopback address only

The three Silo ports listen on every host interface without TLS. The Jellyfin and Audiobookshelf listeners are on from the first start. If you don’t use those apps, turn off Allow Jellyfin apps to connect and Allow Audiobookshelf apps to connect in Admin > Settings > Compatibility. See third-party access. Before allowing access from outside your network, put Silo behind HTTPS.

The media mount is read-only. Silo’s writable directories live below SILO_DATA_ROOT, which defaults to /opt/silo:

DirectoryContents
postgresPostgreSQL files
redisRedis persistence
pluginsInstalled plugin files
artworkLocal artwork, uploads, and downloaded subtitles
compatCompatibility assets
transcodeTemporary transcode output
catalog-seedsCatalog seed inputs, mounted read-only
meilisearchOptional search index

Backups lists which of these to keep.

Search uses PostgreSQL unless you switch it. To add Meilisearch:

  1. Generate a key with openssl rand -hex 32 and set MEILI_MASTER_KEY in .env. Keep it private.
  2. Start the optional service with docker compose --profile search up -d.
  3. Open Admin > Settings > Library & Metadata. Under Search, set Search engine to Meilisearch, enter http://meilisearch:7700 as the Meilisearch URL, and use the same key as the Meilisearch API key.
  4. Select Check Connection, save, and restart Silo.
  5. Silo builds the search index in the background. Test a known title once it finishes.

Starting the container alone does not switch Silo’s search engine. Port 7700 is published on the host’s loopback address; keep it off the public internet.

The Compose file pins the Meilisearch version, because Meilisearch cannot open data written by a different version. To upgrade, change MEILISEARCH_IMAGE and set MEILI_UPGRADE_DB=true in .env for one start, then remove it. You can also empty the meilisearch directory and let Silo rebuild the index.

The default stack uses the CPU only. For a GPU, add the matching overlay:

  • docker-compose.vaapi.yml passes /dev/dri into the container for Intel Quick Sync and Intel or AMD VA-API. The host needs a working device and driver.
  • docker-compose.nvidia.yml requests a GPU through the NVIDIA container runtime. Install the host driver and NVIDIA Container Toolkit first.

The full procedure is in Set up transcoding.

The Compose file includes commented examples for separate proxy and transcode workers. Leave them off on a single host; see Transcode nodes.

For external PostgreSQL or Redis and PostgreSQL tuning, see Server configuration.