Skip to content

System requirements

One container, and a short list of things it needs

What the container needs before anybody deploys it: the runtime inside it, the one port it publishes, the volume it must keep, and the host we recommend you give it.

The runtime inside the image

Two language runtimes in one container, and the second one has a specific cause behind it, not a preference.

The runtime requirements of the TabTotal container, with the file each was read from
What it isWhy, and where to check
Base imagepython:3.13-slimThe same base in both build stages. What is compiled is what runs. Dockerfile:13
Python3.13 or laterTested on 3.13 in continuous integration. pyproject.toml:9, .github/workflows/tests.yml:91
.NET8.0 runtimeThe runtime only, not the SDK. Migrate wraps Tableau’s own .NET Migration SDK. The runtime travels inside the image with it. Dockerfile:101
Runs asuid 10001, user ttcRoot is used once, to take ownership of a mounted volume, and dropped before the application starts. Dockerfile:188
Processor architectureamd64An arm64 build loads cleanly on an x86 host and then fails to start. The architecture is worth asserting before a deployment, not after one.

One listener reaches the network

The governed applications answer on loopback inside the container. The gateway reaches them and nothing else does.

All 14 governed applications bind to the local interface inside the container and are never published. One port carries every request in, and the gateway routes each to the application that owns it, holding a single Tableau session on your behalf.

That is a property you can check rather than a promise you have to accept. List the published ports of the running container and you will find one, whatever the roster inside it happens to be that release.

Ports, and what sits in front

The container serves plain traffic and never holds a certificate. Transport security stays where you already run it.

The network requirements of the container, with the file each was read from
What it isWhy, and where to check
Published port8865 by defaultSet by the PORT environment variable. A deployment behind a proxy usually maps it instead of changing it. Dockerfile:236
Application ports8851 to 8869, on loopbackEvery governed application binds 127.0.0.1 inside the container and is never published. The gateway reaches them and the network does not.
Inbound rules80 and 443 to the world, administrative access from your own addressesThe application port itself stays unpublished.
Transport securityTerminated ahead of the containerThe container always serves plain HTTP and never holds a certificate. Your load balancer or reverse proxy owns transport security, which is where it already is for everything else you run.
Forwarded headersTrusted only when you say soHeader trust defaults off. A directly reachable container ignores a forwarded address.

What has to persist

One volume holds everything a rebuild must not lose. This page names what is inside it, because an instruction to back up a path does not tell you what you would be losing.

The persistent storage the container needs, and what each volume holds
What it isValueWhy, and where to check
Data volume/app/dataThe user directory, the change ledger, the administrative audit log, the semantic layer profiles and the encrypted connection records. Dockerfile:215
Artefact volume/app/artifactsWhere Offboard writes the deliverables an audit asks for.
Volume sizeWithin the 500 GB recommendationThe stores are JSON and JSON Lines files, not a database, and observability logs rotate at 5 MB keeping five files.
OwnershipCorrected at every startThe entry point takes ownership of the volume before dropping privileges. A volume created by an earlier version stays readable and is never silently emptied.
Secret-adjacent filesWritten 0600, atomicallyA partial write leaves the previous file intact, not a truncated one.

What we recommend you give it

One container on a Docker host, with room to work. These are the figures Boreon recommends you provision against.

The recommended host for one TabTotal container
What it isValueWhat bears on it
HostA Docker hostOne self-contained container on any Docker host you already run. No orchestrator is required.
Memory8 GB RAMTwo language runtimes and a headless browser share one container.
Available disk500 GBCovers the image, the persistent volumes and room for the artefacts an audit asks for.

How a deployment reports itself

Ask the container and it answers with the version it is running, which is a better source for that number than any page including this one.

Endpoint

GET /health. Answers with a status, the product name and the running version. A deployment can be confirmed, not assumed.

Interval

Every 30 seconds

Timeout

4 seconds

Grace on start

60 seconds. The gateway waits for every governed application to answer before it reports ready. A cold start is slower than a restart.

Retries

5