{
  "manifest_version": "1.0.0",
  "template": {
    "id": "9c6f903b-4002-4bb2-9197-d21a2e344bcf",
    "slug": "dependency-track",
    "name": "Dependency-Track 5 | OWASP SBOM and Vulnerability Tracking",
    "description": "OWASP Dependency-Track 5: SBOM analysis, known vulnerabilities, one URL",
    "url": "https://railway.com/deploy/dependency-track",
    "upstream": {
      "repo_url": "https://github.com/nomideusz/dependency-track-railway"
    }
  },
  "services": [
    {
      "name": "API",
      "source": {
        "repo": "https://github.com/nomideusz/dependency-track-railway"
      },
      "needs_volume": true,
      "volume_mount_path": "/data",
      "http": false
    },
    {
      "name": "Postgres",
      "source": {
        "image": "ghcr.io/railwayapp-templates/postgres-ssl:17"
      },
      "needs_volume": true,
      "volume_mount_path": "/var/lib/postgresql/data",
      "http": false
    },
    {
      "name": "Dependency-Track",
      "source": {
        "repo": "https://github.com/nomideusz/dependency-track-railway"
      },
      "needs_volume": false,
      "http": true
    }
  ],
  "required_inputs": [
    {
      "key": "PORT",
      "service": "API",
      "description": "Port the API server listens on - leave as is",
      "secret": false,
      "strategy": "default",
      "default": "8080"
    },
    {
      "key": "DT_DATASOURCE_URL",
      "service": "API",
      "description": "Postgres JDBC URL - private network, leave as is",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "DTRACK_ADMIN_PASSWORD",
      "service": "API",
      "description": "Admin password, read on first boot - set it on the Dependency-Track service",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DT_DATASOURCE_PASSWORD",
      "service": "API",
      "description": "Postgres password - leave as is",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DT_DATASOURCE_USERNAME",
      "service": "API",
      "description": "Postgres user - leave as is",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "RAILWAY_DEPLOYMENT_DRAINING_SECONDS",
      "service": "API",
      "description": "Time for running analyses to stop cleanly on redeploy",
      "secret": false,
      "strategy": "default",
      "default": "30"
    },
    {
      "key": "PGDATA",
      "service": "Postgres",
      "description": "Data subdirectory - keeps Postgres happy on Railway volumes",
      "secret": false,
      "strategy": "default",
      "default": "/var/lib/postgresql/data/pgdata"
    },
    {
      "key": "POSTGRES_DB",
      "service": "Postgres",
      "description": "Database name",
      "secret": false,
      "strategy": "default",
      "default": "dtrack"
    },
    {
      "key": "POSTGRES_USER",
      "service": "Postgres",
      "description": "Database user",
      "secret": false,
      "strategy": "default",
      "default": "dtrack"
    },
    {
      "key": "POSTGRES_PASSWORD",
      "service": "Postgres",
      "description": "Auto-generated database password",
      "secret": true,
      "strategy": "generate",
      "generate": "strong_password"
    },
    {
      "key": "RAILWAY_DEPLOYMENT_DRAINING_SECONDS",
      "service": "Postgres",
      "description": "Time for Postgres to shut down cleanly on redeploy",
      "secret": false,
      "strategy": "default",
      "default": "60"
    },
    {
      "key": "PORT",
      "service": "Dependency-Track",
      "description": "Port nginx listens on - leave as is",
      "secret": false,
      "strategy": "default",
      "default": "8080"
    },
    {
      "key": "DTRACK_API_URL",
      "service": "Dependency-Track",
      "description": "API server on the private network - /api is proxied there, leave as is",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "DTRACK_ADMIN_PASSWORD",
      "service": "Dependency-Track",
      "description": "Password for the admin login, set on first boot only - copy it from here to log in, then change it in Dependency-Track",
      "secret": true,
      "strategy": "generate",
      "generate": "strong_password"
    }
  ],
  "deploy": {
    "mcp": {
      "server": "railway",
      "tool": "deploy_template",
      "args": {
        "template_code": "dependency-track"
      }
    },
    "cli": "railway deploy --template dependency-track",
    "api": {
      "method": "POST",
      "path": "/graphql/v2",
      "body": {
        "query": "mutation templateDeploy($input: TemplateDeployV2Input!) { templateDeployV2(input: $input) { projectId workflowId } }",
        "variables": {
          "input": {
            "templateId": "9c6f903b-4002-4bb2-9197-d21a2e344bcf",
            "serializedConfig": {
              "services": {
                "04e62795-c400-44c2-9f62-5eb1d4beec8d": {
                  "icon": "https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/svg/dependency-track.svg",
                  "name": "API",
                  "build": {},
                  "deploy": {
                    "startCommand": null,
                    "healthcheckPath": "/api/version",
                    "restartPolicyType": "ON_FAILURE",
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "repo": "https://github.com/nomideusz/dependency-track-railway",
                    "rootDirectory": "/apiserver"
                  },
                  "variables": {
                    "PORT": {
                      "isOptional": false,
                      "description": "Port the API server listens on - leave as is",
                      "defaultValue": "8080"
                    },
                    "DT_DATASOURCE_URL": {
                      "isOptional": false,
                      "description": "Postgres JDBC URL - private network, leave as is",
                      "defaultValue": "jdbc:postgresql://${{Postgres.RAILWAY_PRIVATE_DOMAIN}}:5432/${{Postgres.POSTGRES_DB}}"
                    },
                    "DTRACK_ADMIN_PASSWORD": {
                      "isOptional": false,
                      "description": "Admin password, read on first boot - set it on the Dependency-Track service",
                      "defaultValue": "${{Dependency-Track.DTRACK_ADMIN_PASSWORD}}"
                    },
                    "DT_DATASOURCE_PASSWORD": {
                      "isOptional": false,
                      "description": "Postgres password - leave as is",
                      "defaultValue": "${{Postgres.POSTGRES_PASSWORD}}"
                    },
                    "DT_DATASOURCE_USERNAME": {
                      "isOptional": false,
                      "description": "Postgres user - leave as is",
                      "defaultValue": "${{Postgres.POSTGRES_USER}}"
                    },
                    "RAILWAY_DEPLOYMENT_DRAINING_SECONDS": {
                      "isOptional": false,
                      "description": "Time for running analyses to stop cleanly on redeploy",
                      "defaultValue": "30"
                    }
                  },
                  "networking": {
                    "serviceDomains": {}
                  },
                  "volumeMounts": {
                    "04e62795-c400-44c2-9f62-5eb1d4beec8d": {
                      "mountPath": "/data"
                    }
                  }
                },
                "29ed8029-a9a7-4fa8-9e80-e2cab655878b": {
                  "icon": "https://devicons.railway.app/i/postgresql.svg",
                  "name": "Postgres",
                  "build": {},
                  "deploy": {
                    "startCommand": null,
                    "limitOverride": {
                      "containers": {
                        "memoryBytes": 1000000000
                      }
                    },
                    "healthcheckPath": null,
                    "restartPolicyType": "ON_FAILURE",
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "ghcr.io/railwayapp-templates/postgres-ssl:17"
                  },
                  "variables": {
                    "PGDATA": {
                      "isOptional": false,
                      "description": "Data subdirectory - keeps Postgres happy on Railway volumes",
                      "defaultValue": "/var/lib/postgresql/data/pgdata"
                    },
                    "POSTGRES_DB": {
                      "isOptional": false,
                      "description": "Database name",
                      "defaultValue": "dtrack"
                    },
                    "POSTGRES_USER": {
                      "isOptional": false,
                      "description": "Database user",
                      "defaultValue": "dtrack"
                    },
                    "POSTGRES_PASSWORD": {
                      "isOptional": false,
                      "description": "Auto-generated database password",
                      "defaultValue": "{{POSTGRES_PASSWORD}}"
                    },
                    "RAILWAY_DEPLOYMENT_DRAINING_SECONDS": {
                      "isOptional": false,
                      "description": "Time for Postgres to shut down cleanly on redeploy",
                      "defaultValue": "60"
                    }
                  },
                  "networking": {
                    "serviceDomains": {}
                  },
                  "volumeMounts": {
                    "29ed8029-a9a7-4fa8-9e80-e2cab655878b": {
                      "mountPath": "/var/lib/postgresql/data"
                    }
                  }
                },
                "a0c22c71-58a6-4563-b40f-62a172f35991": {
                  "icon": "https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/svg/dependency-track.svg",
                  "name": "Dependency-Track",
                  "build": {},
                  "deploy": {
                    "startCommand": null,
                    "healthcheckPath": "/",
                    "restartPolicyType": "ON_FAILURE",
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "repo": "https://github.com/nomideusz/dependency-track-railway",
                    "rootDirectory": "/frontend"
                  },
                  "variables": {
                    "PORT": {
                      "isOptional": false,
                      "description": "Port nginx listens on - leave as is",
                      "defaultValue": "8080"
                    },
                    "DTRACK_API_URL": {
                      "isOptional": false,
                      "description": "API server on the private network - /api is proxied there, leave as is",
                      "defaultValue": "http://${{API.RAILWAY_PRIVATE_DOMAIN}}:8080"
                    },
                    "DTRACK_ADMIN_PASSWORD": {
                      "isOptional": false,
                      "description": "Password for the admin login, set on first boot only - copy it from here to log in, then change it in Dependency-Track",
                      "defaultValue": "{{DTRACK_ADMIN_PASSWORD}}"
                    }
                  },
                  "networking": {
                    "serviceDomains": {
                      "<hasDomain>": {}
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "post_deploy": {
    "healthcheck": {
      "service": "Dependency-Track",
      "method": "GET",
      "path": "/",
      "expect_status": 200
    }
  },
  "resources": {
    "expected_services": 3,
    "needs_volume": true
  },
  "generated_at": "2026-10-06T04:14:42.626Z",
  "generator_version": "0.1.0",
  "status": "validated",
  "validated_at": "2026-10-05T18:28:05.516Z",
  "success_rate_30d": 1,
  "validation": {
    "last_run_id": "run_c419397af47543f2ab9f",
    "checks": [
      {
        "name": "workflow_completed",
        "passed": true
      },
      {
        "name": "all_services_deployed",
        "passed": true
      },
      {
        "name": "healthcheck",
        "passed": true
      },
      {
        "name": "stays_up",
        "passed": true
      }
    ],
    "typical_ready_seconds": 101,
    "typical_build_seconds": 21,
    "typical_start_seconds": 30,
    "slowest_service": "API"
  }
}
