---
title: "Deploy Infisical v0.166 Secrets Manager"
description: "Store, sync and rotate secrets for your apps and teams. Self-hosted."
category: "Other"
url: https://railway.com/deploy/infisical-v0166-secrets-manager
---

# Deploy Infisical v0.166 Secrets Manager

Store, sync and rotate secrets for your apps and teams. Self-hosted.

**[Deploy Infisical v0.166 Secrets Manager on Railway](https://railway.com/template/infisical-v0166-secrets-manager)**

Machine-readable deploy manifest (JSON, validated by TemplateCI): https://railway.com/deploy/infisical-v0166-secrets-manager/manifest.json

- **Creator:** bento
- **Category:** Other
- **Total deploys:** 1

## Template content

### Postgres https://devicons.railway.app/i/postgresql.svg

- **Image:** ghcr.io/railwayapp-templates/postgres-ssl:18

### Infisical Bootstrap https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/svg/infisical.svg

- **Source:** baranberkay96/infisical-railway

### Redis https://cdn.sanity.io/images/sy1jschh/production/0ce0bfdcfbdbf69662b1116671f97c2dd788b655-157x157.svg

- **Image:** redis:8.2
- **Start command:** `/bin/sh -c "rm -rf $RAILWAY_VOLUME_MOUNT_PATH/lost+found/ && exec docker-entrypoint.sh redis-server --requirepass $REDIS_PASSWORD --save 60 1 --dir $RAILWAY_VOLUME_MOUNT_PATH --maxmemory-policy noeviction"`

### Infisical https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/svg/infisical.svg

- **Image:** infisical/infisical:v0.166.3
- **Health check:** /api/status
- **Public domain:** Yes

## Documentation

# Deploy and Host Infisical with Railway

Infisical is an open-source secrets manager: store environment variables, API keys and certificates per project and environment, sync them to your apps and CI/CD, and keep an audit trail of every access. This community template runs Infisical on Railway with Postgres and Redis, generated keys, and an admin account created for you.

## About Hosting Infisical

Infisical is a single Node.js service that serves the web UI and the API used by its CLI, SDKs and Kubernetes operator. It needs Postgres for encrypted secrets and audit logs, Redis for caching and job queues, a root encryption key, and a JWT signing secret. This template pins a current release, generates both keys in the formats upstream documents, runs database migrations as a pre-deploy step, binds the server dual-stack on Railway's private network, and runs a one-shot job that claims the instance with your admin e-mail, so nobody else can register as super-admin before you open the URL.

## Common Use Cases

- Replacing `.env` files shared over chat with per-environment secrets and access control
- Injecting secrets into Railway services, Docker builds and CI pipelines with the Infisical CLI
- Syncing secrets to cloud providers and Kubernetes through Infisical integrations
- Auditing who read or changed which secret, and rotating credentials on a schedule

## Dependencies for Infisical Hosting

- Infisical (`infisical/infisical:v0.166.3`)
- PostgreSQL (Railway Postgres 18)
- Redis (cache and queues)
- Optional: an SMTP server for invitation and MFA e-mails (Railway Pro)

### Deployment Dependencies

- Infisical self-hosting overview: https://infisical.com/docs/self-hosting/overview
- Environment variable reference: https://infisical.com/docs/self-hosting/configuration/envars
- Instance bootstrap API: https://infisical.com/docs/self-hosting/guides/automated-bootstrapping
- Infisical source and releases: https://github.com/Infisical/infisical

### Implementation Details

| Service | Image / source | Role |
|---|---|---|
| Infisical | `infisical/infisical:v0.166.3` | Web UI and API on the public domain; migrations in pre-deploy |
| Postgres | `ghcr.io/railwayapp-templates/postgres-ssl:18` | Encrypted secrets, audit logs (volume) |
| Redis | `redis:8.2` | Cache and job queues (volume, `noeviction`) |
| Infisical Bootstrap | `services/bootstrap` (curl) | One-shot job: creates the super-admin and first organization |

**First login:** enter your e-mail in `INFISICAL_ADMIN_EMAIL` when deploying. When the Infisical Bootstrap service logs "Instance bootstrapped", sign in at `https://{your-domain}` with that e-mail and the `INFISICAL_ADMIN_PASSWORD` value from the Infisical Bootstrap variables, then change the password and enable MFA. Public sign-up is closed after bootstrap; invite your team from the organization settings.

**Back up the encryption key:** copy `ENCRYPTION_KEY` from the Infisical service variables to a safe place outside Railway. Without it, a database backup cannot be decrypted.

**E-mail:** Infisical sends mail over SMTP only. Railway allows outbound SMTP on the Pro plan; on other plans, share the invitation links shown in the UI.

**Scaling:** Infisical keeps no local state, so you can add replicas for API-heavy workloads such as many CI jobs. Scale Postgres vertically.

**Versions:** change the image tag on the Infisical service and redeploy; migrations run in the pre-deploy step, and a failed migration leaves the running version untouched. Back up Postgres before upgrading.

### Why Deploy Infisical on Railway?

Railway runs Infisical, its database and cache on a private network with managed volumes and usage-based billing, and your Railway services can pull secrets from it over that network. You get a self-hosted secrets manager under your own control without operating servers.


## Similar templates

- [Rocky Linux](https://railway.com/deploy/rocky-linux) — Hosted Rocky Linux 9 workspace with SSH and persistent storage. 🚀
- [Foundry Virtual Tabletop](https://railway.com/deploy/X5tR6G) — A Self-Hosted & Modern Roleplaying Platform
- [Letta Code Remote](https://railway.com/deploy/letta-code-remote) — Run a Letta Code agent 24/7. No inbound ports, just deploy.

Open this page in a browser: https://railway.com/deploy/infisical-v0166-secrets-manager
