Deploy Directus | Pinned, With Admin Credentials You Can Find
Pinned image, admin password in variables instead of the deploy log.
Directus
Just deployed
/directus/uploads
Redis
Just deployed
/data
PostGIS
Just deployed
/var/lib/postgresql/data
Deploy and Host Directus on Railway
Directus, the headless CMS, on Postgres with PostGIS, with Redis caching and a volume for uploads. Every image is pinned, and the admin credentials are in your service variables rather than the deploy log.
Log in at the domain with admin@example.com and the generated ADMIN_PASSWORD.
About Hosting Directus
The existing Directus template is well built: PostGIS and Redis are pinned, files go to S3, caching and websockets are on. Two things are wrong with it.
The Directus image itself is :latest, the only unpinned image in a stack that pins everything else. Two deploys a month apart are not the same CMS, and a redeploy can change the application over a database it has already migrated.
The administrator credentials only exist in the deploy log. Directus creates the first user on bootstrap. With no ADMIN_EMAIL and ADMIN_PASSWORD set, it generates them and prints them, so getting in means scrolling through logs, and once the log rotates or the volume is lost, that password is gone. Here both are template variables: the password is generated, and it sits in your service settings where you can read it and change it.
Common Use Cases
- A content backend for websites and apps, managed in the Directus admin and read over its API.
- Schemas that use PostGIS types, since the database is PostGIS rather than plain Postgres.
- A CMS with no external dependencies to start with: uploads go to a volume, and S3 can be switched on later.
Dependencies for Directus Hosting
Deployment Dependencies
- Directus
directus/directus:12.2.0(public) - PostGIS
postgis/postgis:17-3.5 - Redis
redis:8.6.5-alpine, the cache
Source images and configuration follow the Directus documentation. Directus is by Monospace Inc, under the Directus BSL.
Implementation Details
- Admin credentials are template variables.
ADMIN_EMAILisadmin@example.com;ADMIN_PASSWORDis generated and readable in the service variables. - Uploads are on a volume at
/directus/uploadsrather than S3, so the template has no external dependency and nothing to configure. For larger installations, switchSTORAGE_LOCATIONSto S3 and point it at a bucket; Directus supports both, and the variables are the ones in its own documentation. - Secrets are generated.
KEY,SECRET, the database password and the admin password are all generated, so there is nothing to fill in.KEYandSECRETshould not be changed after first boot: they sign sessions and tokens.
Verification
By using it. Deployed from this template, logged in with the generated password, read the administrator back over the API, and created a collection, which is a schema write rather than a health check. A wrong password returns 401.
Why Deploy Directus on Railway?
Railway is a singular platform to deploy your infrastructure stack. Railway will host your infrastructure so you don't have to deal with configuration, while allowing you to vertically and horizontally scale it.
By deploying Directus on Railway, you are one step closer to supporting a complete full-stack application with minimal burden. Host your servers, databases, AI agents, and more on Railway.
Template Content