Skip to main content
Helicone OSS LLM Observability

Docker

Deploy Helicone using Docker. Quick setup guide for running a containerized instance of the LLM observability platform on your local machine or server.
3 min read

To run all services in a single Docker container, you can use the helicone-all-in-one image.

Quick Start (Local)#

Get Docker and run the container:

Access the dashboard at http://localhost:3000.

Example to test the Jawn service#

Note

Jawn no longer proxies LLM traffic: the /v1/gateway/* routes have been removed. To proxy requests through a self-hosted deployment, run the AI Gateway alongside Jawn.

Production Setup (Remote Server)#

When deploying to a remote server (EC2, VPS, etc.), configure your server's public IP or domain:

Environment Variables#

The container uses these environment variables (with defaults for local development):

VariableDefaultDescription
NEXT_PUBLIC_HELICONE_JAWN_SERVICEhttp://localhost:8585URL browsers use to reach the API. Must be public URL for remote deployments.
S3_ENDPOINThttp://localhost:9080URL browsers use for presigned URLs. Must be public URL for remote deployments.
S3_ACCESS_KEYminioadminMinIO access key
S3_SECRET_KEYminioadminMinIO secret key
S3_BUCKET_NAMErequest-response-storageS3 bucket for request/response bodies
BETTER_AUTH_SECRETchange-me-in-productionAuth secret. Generate a secure value for production.
SITE_URL-Public URL of the web dashboard
BETTER_AUTH_URL-Same as SITE_URL
NEXT_PUBLIC_APP_URL-Same as SITE_URL
NEXT_PUBLIC_IS_ON_PREM-Set to true for non-localhost deployments

Port Requirements#

PortServiceRequired For
3000Web DashboardBrowser access
8585Jawn API + LLM ProxyBrowser API calls, LLM proxying
9080MinIO S3Request/response body storage
5432PostgreSQLInternal (can be restricted)
8123ClickHouseInternal (can be restricted)

Important: Ports 3000, 8585, and 9080 must be accessible from browsers accessing the dashboard.

User Account Setup#

Create Account#

Navigate to http://YOUR_IP:3000/signup and create your account.

Email Verification#

The container doesn't include email services. Manually verify users:

Organization Setup#

Users need an organization. If you see "No organization ID found" errors:

LLM Proxying#

The all-in-one image runs the dashboard and the Jawn API only. Jawn's /v1/gateway/* proxy routes have been removed, so LLM requests must go through the AI Gateway, which you can deploy next to this image.

Important Notes#

Data Persistence#

Container restarts will wipe all data. For production, mount Docker volumes:

Security#

Port 8585 does not require authentication for proxying requests. Anyone with access can proxy LLM requests through your endpoint. Restrict access via firewall rules.

HTTPS#

For HTTPS support, use a reverse proxy (Caddy, nginx, Traefik) in front of the container. See the Cloud Deployment guide for a Caddy example.

Troubleshooting#

API calls fail with connection refused#

The web app tries to connect to localhost:8585 instead of your public IP. Verify the environment variable was set:

Infinite redirect loop#

Missing NEXT_PUBLIC_IS_ON_PREM=true environment variable.

"Invalid origin" error on sign-in#

All URL environment variables must use the same origin (public IP or domain). Don't mix localhost with public IPs.

"No organization ID found" error#

User needs to be added to an organization. See the Organization Setup section above.