Deploy OpenCTI 7 Threat Intelligence Platform
Collect, link and share cyber threat intel. Full stack with workers.
OpenCTI Worker
Just deployed
connector-analysis
Just deployed
connector-import-external-reference
Just deployed
connector-export-file-csv
Just deployed
connector-import-file-yara
Just deployed
connector-mitre
Just deployed
Redis
Just deployed
RabbitMQ
Just deployed
connector-import-document
Just deployed
OpenCTI
Just deployed
connector-export-file-txt
Just deployed
connector-export-file-stix
Just deployed
Elasticsearch
Just deployed
connector-opencti
Just deployed
connector-import-file-stix
Just deployed
Bucket
Bucket
Just deployed
Deploy and Host OpenCTI with Railway
OpenCTI is an open-source platform for structuring, storing and sharing cyber threat intelligence as a STIX 2.1 knowledge graph. This community template deploys the full OpenCTI 7 stack on Railway: the platform, three workers, Elasticsearch, Redis, RabbitMQ, a Railway Bucket for files, and the ten built-in connectors from the official Docker setup.
About Hosting OpenCTI
OpenCTI's platform serves the web UI and GraphQL API and stores its knowledge graph in Elasticsearch. Redis holds caches and live event streams, RabbitMQ distributes work, and S3-compatible storage keeps uploaded reports and exports. Workers consume the queues and write data through the API, and connectors import or export data. This template follows the official docker-compose service by service, pins every image to the same release, generates all credentials, stores files in a Railway Bucket instead of MinIO, and loads the MITRE ATT&CK and OpenCTI reference datasets on first start.
Common Use Cases
- Building a central threat intelligence knowledge base for a SOC or CERT team
- Mapping threat actors, campaigns and malware to MITRE ATT&CK techniques
- Importing PDF and HTML threat reports and extracting indicators and observables
- Sharing curated intelligence as STIX 2.1 bundles, CSV or TAXII feeds
- Connecting external feeds and enrichment services through OpenCTI connectors
Dependencies for OpenCTI Hosting
- OpenCTI platform, worker and connectors 7.261008.0 (official
opencti/*images) - Elasticsearch 8.19
- Redis 8.2 (Railway Redis)
- RabbitMQ 4.3 with the management plugin
- S3-compatible object storage (Railway Bucket)
Deployment Dependencies
- OpenCTI Docker setup (official compose this template follows): https://github.com/OpenCTI-Platform/docker
- OpenCTI documentation, installation and configuration: https://docs.opencti.io/latest/deployment/installation/
- OpenCTI connectors catalog: https://github.com/OpenCTI-Platform/connectors
- Railway Storage Buckets: https://docs.railway.com/storage-buckets
Implementation Details
| Service | Image | Role |
|---|---|---|
| OpenCTI | opencti/platform:7.261008.0 | Web UI, GraphQL API, background managers; public domain |
| OpenCTI Worker (3 replicas) | opencti/worker:7.261008.0 | Processes queued bundles into the knowledge graph |
| connector-export-file-stix / -csv / -txt | opencti/connector-export-file-* | Exports to STIX 2.1, CSV and plain text |
| connector-import-file-stix, connector-import-document, connector-import-file-yara | opencti/connector-import-* | Imports STIX files, PDF/text/HTML reports and YARA rules |
| connector-analysis | opencti/connector-import-document | Content analysis of reports |
| connector-import-external-reference | opencti/connector-import-external-reference | Fetches external reference URLs as files |
| connector-opencti, connector-mitre | opencti/connector-opencti, opencti/connector-mitre | Reference datasets (markings, sectors, countries) and MITRE ATT&CK |
| Elasticsearch | built from services/elasticsearch (elasticsearch:8.19.21) | Knowledge graph indexes (volume) |
| RabbitMQ | rabbitmq:4.3.6-management | Work queues (volume) |
| Redis | redis:8.2 | Cache, streams, locks (volume) |
| Bucket | Railway Bucket | Uploaded files, imports, exports |
First login: wait until the OpenCTI service is healthy, open its public URL and log in with APP__ADMIN__EMAIL (default admin@opencti.io, change it before the first deploy if you like) and the generated APP__ADMIN__PASSWORD from the OpenCTI service variables. Change the password in your profile. MITRE ATT&CK and the OpenCTI datasets start importing immediately; on the very first start these two connectors may restart once or twice while their service accounts are created.
Adding connectors: OpenCTI's connector manager normally starts containers through Docker, which Railway does not offer. Add each extra connector as its own Railway service with the image opencti/connector-{name}:7.261008.0, OPENCTI_URL and OPENCTI_TOKEN copied from an existing connector, a new UUIDv4 CONNECTOR_ID, and the connector's own settings from the connectors catalog.
Scaling: raise the OpenCTI Worker replica count for faster ingestion. Give Elasticsearch more memory together with a larger ES_JAVA_OPTS heap, and the platform more memory together with NODE_OPTIONS, as your knowledge base grows.
E-mail: OpenCTI sends notifications over SMTP only. Add SMTP__HOSTNAME, SMTP__PORT, SMTP__USERNAME, SMTP__PASSWORD and SMTP__USE_SSL to the OpenCTI service; Railway allows outbound SMTP on the Pro plan.
Versions: every OpenCTI image is pinned to 7.261008.0. Upgrade by changing the tag on the platform, worker and all connectors together; the platform migrates its data on start. OpenCTI also publishes an LTS line if you prefer fewer upgrades.
Why Deploy OpenCTI on Railway?
OpenCTI needs several cooperating services. Railway runs them all in one project with private networking, persistent volumes, a managed S3 bucket and an HTTPS domain, so the complete stack, with reference data loaded, comes up from one template. You can scale workers and give Elasticsearch more resources from the dashboard as your intelligence grows.
Template Content
OpenCTI Worker
opencti/worker:7.261008.0connector-analysis
opencti/connector-import-document:7.261008.0connector-import-external-reference
opencti/connector-import-external-reference:7.261008.0connector-export-file-csv
opencti/connector-export-file-csv:7.261008.0connector-import-file-yara
opencti/connector-import-file-yara:7.261008.0connector-mitre
opencti/connector-mitre:7.261008.0Redis
redis:8.2RabbitMQ
rabbitmq:4.3.6-managementconnector-import-document
opencti/connector-import-document:7.261008.0OpenCTI
opencti/platform:7.261008.0connector-export-file-txt
opencti/connector-export-file-txt:7.261008.0connector-export-file-stix
opencti/connector-export-file-stix:7.261008.0Elasticsearch
baranberkay96/opencti-railwayconnector-opencti
opencti/connector-opencti:7.261008.0connector-import-file-stix
opencti/connector-import-file-stix:7.261008.0Bucket
Bucket
