Endpoint
GET /health. Answers with a status, the product name and the running version. A deployment can be confirmed, not assumed.
System requirements
What the container needs before anybody deploys it: the runtime inside it, the one port it publishes, the volume it must keep, and the host we recommend you give it.
Two language runtimes in one container, and the second one has a specific cause behind it, not a preference.
| What it is | Why, and where to check | |
|---|---|---|
| Base image | python:3.13-slim | The same base in both build stages. What is compiled is what runs. Dockerfile:13 |
| Python | 3.13 or later | Tested on 3.13 in continuous integration. pyproject.toml:9, .github/workflows/tests.yml:91 |
| .NET | 8.0 runtime | The runtime only, not the SDK. Migrate wraps Tableau’s own .NET Migration SDK. The runtime travels inside the image with it. Dockerfile:101 |
| Runs as | uid 10001, user ttc | Root is used once, to take ownership of a mounted volume, and dropped before the application starts. Dockerfile:188 |
| Processor architecture | amd64 | An arm64 build loads cleanly on an x86 host and then fails to start. The architecture is worth asserting before a deployment, not after one. |
The governed applications answer on loopback inside the container. The gateway reaches them and nothing else does.
All 14 governed applications bind to the local interface inside the container and are never published. One port carries every request in, and the gateway routes each to the application that owns it, holding a single Tableau session on your behalf.
That is a property you can check rather than a promise you have to accept. List the published ports of the running container and you will find one, whatever the roster inside it happens to be that release.
The container serves plain traffic and never holds a certificate. Transport security stays where you already run it.
| What it is | Why, and where to check | |
|---|---|---|
| Published port | 8865 by default | Set by the PORT environment variable. A deployment behind a proxy usually maps it instead of changing it. Dockerfile:236 |
| Application ports | 8851 to 8869, on loopback | Every governed application binds 127.0.0.1 inside the container and is never published. The gateway reaches them and the network does not. |
| Inbound rules | 80 and 443 to the world, administrative access from your own addresses | The application port itself stays unpublished. |
| Transport security | Terminated ahead of the container | The container always serves plain HTTP and never holds a certificate. Your load balancer or reverse proxy owns transport security, which is where it already is for everything else you run. |
| Forwarded headers | Trusted only when you say so | Header trust defaults off. A directly reachable container ignores a forwarded address. |
One volume holds everything a rebuild must not lose. This page names what is inside it, because an instruction to back up a path does not tell you what you would be losing.
| What it is | Value | Why, and where to check |
|---|---|---|
| Data volume | /app/data | The user directory, the change ledger, the administrative audit log, the semantic layer profiles and the encrypted connection records. Dockerfile:215 |
| Artefact volume | /app/artifacts | Where Offboard writes the deliverables an audit asks for. |
| Volume size | Within the 500 GB recommendation | The stores are JSON and JSON Lines files, not a database, and observability logs rotate at 5 MB keeping five files. |
| Ownership | Corrected at every start | The entry point takes ownership of the volume before dropping privileges. A volume created by an earlier version stays readable and is never silently emptied. |
| Secret-adjacent files | Written 0600, atomically | A partial write leaves the previous file intact, not a truncated one. |
One container on a Docker host, with room to work. These are the figures Boreon recommends you provision against.
| What it is | Value | What bears on it |
|---|---|---|
| Host | A Docker host | One self-contained container on any Docker host you already run. No orchestrator is required. |
| Memory | 8 GB RAM | Two language runtimes and a headless browser share one container. |
| Available disk | 500 GB | Covers the image, the persistent volumes and room for the artefacts an audit asks for. |
Ask the container and it answers with the version it is running, which is a better source for that number than any page including this one.
GET /health. Answers with a status, the product name and the running version. A deployment can be confirmed, not assumed.
Every 30 seconds
4 seconds
60 seconds. The gateway waits for every governed application to answer before it reports ready. A cold start is slower than a restart.
5