---
title: "Deploy jevbox"
description: "Permission-aware document library with search, chat, and a browser UI"
category: "Storage"
url: https://railway.com/deploy/jevbox
---

# Deploy jevbox

Permission-aware document library with search, chat, and a browser UI

**[Deploy jevbox on Railway](https://railway.com/template/jevbox)**

Machine-readable deploy manifest (JSON, validated by TemplateCI): https://railway.com/deploy/jevbox/manifest.json

- **Creator:** kmaki's Projects
- **Category:** Storage

## Template content

### app

- **Image:** xiaosong233/jevbox-railway:latest
- **Public domain:** Yes

### Postgres https://devicons.railway.app/i/postgresql.svg

- **Image:** ghcr.io/railwayapp-templates/postgres-ssl:18

### Postgres-Hl7_ https://devicons.railway.app/i/postgresql.svg

- **Image:** ghcr.io/railwayapp-templates/postgres-ssl:18

### worker

- **Image:** xiaosong233/jevbox-railway:latest
- **Start command:** `node --import tsx server/worker.ts`

### spicedb

- **Image:** xiaosong233/jevbox-spicedb-railway:latest

## Documentation

# Deploy and Host Jevbox on Railway

Jevbox is a full-stack, permission-aware document library for browsing, organizing, previewing, and searching files through a polished browser UI. It stores document metadata and content in PostgreSQL, evaluates permissions with SpiceDB, and runs durable background jobs for parsing, indexing, thumbnails, email, and source-grounded AI chat.

[![Deploy on Railway](https://railway.com/button.svg)](https://railway.com/deploy/jevbox)

## About Hosting Jevbox on Railway

Railway runs the Jevbox web UI, background worker, SpiceDB authorization service, and two private PostgreSQL databases as Docker-image services. Railway provides HTTPS networking, private service discovery, persistent database volumes, generated secrets, and one-click environment provisioning.

## Tech Stack

- Node.js 24, TypeScript, Express, and Vite
- React 19 with Extend document viewers and PDFium
- PostgreSQL 17-compatible Railway databases
- SpiceDB v1.48.0 for permission checks
- pg-boss for durable background jobs
- Playwright Chromium and Sharp for previews and thumbnails
- Better Auth for email/password authentication

## Why Deploy Jevbox on Railway

Railway makes the multi-service topology reproducible with Docker images, private service-to-service networking, managed PostgreSQL volumes, generated secrets, and an automatically provisioned HTTPS domain. The web service and worker share the same pinned application image while SpiceDB and its dedicated datastore remain private.

## Common Use Cases

- Private team document libraries with nested categories
- Source-grounded search and AI chat over uploaded files
- Organization sharing, invitations, and document permissions
- PDF, Office, image, code, Markdown, JSON, CSV, audio, and video previews
- REST API, API keys, MCP integrations, and public read-only links

## Deployment Notes

- The browser-facing service listens on port `4310`; Railway exposes it through the generated domain and sets `PORT=4310`.
- The worker is private and has no public domain. It uses the same image with `node --import tsx server/worker.ts`.
- SpiceDB listens privately on port `8443` and runs its PostgreSQL migrations at startup.
- The web and worker use PostgreSQL file storage by default, so no application volume is required; both PostgreSQL services use persistent mounts at `/var/lib/postgresql/data`.
- Railway generates `ENCRYPTION_KEY`, `BETTER_AUTH_SECRET`, `BOOTSTRAP_TOKEN`, and the SpiceDB preshared key. Keep them stable across redeployments.
- Set `APP_ORIGIN` to the generated app domain reference. Configure a real TLS SMTP relay, `SMTP_HOST`, `SMTP_PORT`, `SMTP_SECURE`, optional `SMTP_USER` and `SMTP_PASSWORD`, and a verified `AUTH_EMAIL_FROM` before sending verification or invitation email.
- Create the first account with the deployment setup token exposed as `BOOTSTRAP_TOKEN`; signup is disabled by default after bootstrap.
- Configure TypeSafe or Cloudflare decision credentials and chat-provider credentials in Jevbox Organization settings after signing in.

## Dependencies for Jevbox on Railway

Jevbox depends on an application PostgreSQL database for accounts, document metadata, queues, and file bytes; a dedicated PostgreSQL database for SpiceDB; and a private SpiceDB service for authorization. The web and worker services share the application image and configuration.

### Deployment Dependencies

| Service | Image | Port | Volume |
|---------|-------|------|--------|
| app | xiaosong233/jevbox-railway:latest | 4310 | - |
| worker | xiaosong233/jevbox-railway:latest | - | - |
| spicedb | xiaosong233/jevbox-spicedb-railway:latest | 8443 | - |
| Postgres | ghcr.io/railwayapp-templates/postgres-ssl:18 | 5432 | /var/lib/postgresql/data |
| Postgres-Hl7_ | ghcr.io/railwayapp-templates/postgres-ssl:18 | 5432 | /var/lib/postgresql/data |


## Similar templates

- [Garage S3 Storage](https://railway.com/deploy/garage-s3-storage) — Ultra-light S3 server: fast, open-source, plug-and-play.
- [Redis](https://railway.com/deploy/redis-1) — Self Host Latest Redis with Railway
- [EasyImg](https://railway.com/deploy/easyimg) — Simple self-hostable Nuxt.js personal image hosting system.

Open this page in a browser: https://railway.com/deploy/jevbox
