---
title: "Deploy OpenCTI 7 Threat Intelligence Platform"
description: "Collect, link and share cyber threat intel. Full stack with workers."
category: "Other"
url: https://railway.com/deploy/opencti-7-threat-intelligence-platform
---

# Deploy OpenCTI 7 Threat Intelligence Platform

Collect, link and share cyber threat intel. Full stack with workers.

**[Deploy OpenCTI 7 Threat Intelligence Platform on Railway](https://railway.com/template/opencti-7-threat-intelligence-platform)**

Machine-readable deploy manifest (JSON, validated by TemplateCI): https://railway.com/deploy/opencti-7-threat-intelligence-platform/manifest.json

- **Creator:** bento
- **Category:** Other
- **Total deploys:** 1

## Template content

### OpenCTI Worker https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/png/opencti.png

- **Image:** opencti/worker:7.261008.0

### connector-analysis https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/png/opencti.png

- **Image:** opencti/connector-import-document:7.261008.0

### connector-import-external-reference https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/png/opencti.png

- **Image:** opencti/connector-import-external-reference:7.261008.0

### connector-export-file-csv https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/png/opencti.png

- **Image:** opencti/connector-export-file-csv:7.261008.0

### connector-import-file-yara https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/png/opencti.png

- **Image:** opencti/connector-import-file-yara:7.261008.0

### connector-mitre https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/png/opencti.png

- **Image:** opencti/connector-mitre:7.261008.0

### Redis https://cdn.sanity.io/images/sy1jschh/production/0ce0bfdcfbdbf69662b1116671f97c2dd788b655-157x157.svg

- **Image:** redis:8.2
- **Start command:** `/bin/sh -c "rm -rf $RAILWAY_VOLUME_MOUNT_PATH/lost+found/ && exec docker-entrypoint.sh redis-server --requirepass $REDIS_PASSWORD --save 60 1 --dir $RAILWAY_VOLUME_MOUNT_PATH"`

### RabbitMQ https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/svg/rabbitmq.svg

- **Image:** rabbitmq:4.3.6-management

### connector-import-document https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/png/opencti.png

- **Image:** opencti/connector-import-document:7.261008.0

### OpenCTI https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/png/opencti.png

- **Image:** opencti/platform:7.261008.0
- **Start command:** `/bin/sh -c 'e="${MINIO__ENDPOINT#*://}"; export MINIO__ENDPOINT="${e%%/*}"; exec node build/back.mjs'`
- **Health check:** /health
- **Public domain:** Yes

### connector-export-file-txt https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/png/opencti.png

- **Image:** opencti/connector-export-file-txt:7.261008.0

### connector-export-file-stix https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/png/opencti.png

- **Image:** opencti/connector-export-file-stix:7.261008.0

### Elasticsearch https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/svg/elasticsearch.svg

- **Source:** baranberkay96/opencti-railway

### connector-opencti https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/png/opencti.png

- **Image:** opencti/connector-opencti:7.261008.0

### connector-import-file-stix https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/png/opencti.png

- **Image:** opencti/connector-import-file-stix:7.261008.0

## Buckets

- **Bucket**

## Documentation

# Deploy and Host OpenCTI with Railway

[![Deploy on Railway](https://railway.com/button.svg)](https://railway.com/deploy/opencti-7-threat-intelligence-platform?referralCode=20H68q)

OpenCTI is an open-source platform for structuring, storing and sharing cyber threat intelligence as a STIX 2.1 knowledge graph. This community template deploys the full OpenCTI 7 stack on Railway: the platform, three workers, Elasticsearch, Redis, RabbitMQ, a Railway Bucket for files, and the ten built-in connectors from the official Docker setup.

## About Hosting OpenCTI

OpenCTI's platform serves the web UI and GraphQL API and stores its knowledge graph in Elasticsearch. Redis holds caches and live event streams, RabbitMQ distributes work, and S3-compatible storage keeps uploaded reports and exports. Workers consume the queues and write data through the API, and connectors import or export data. This template follows the official docker-compose service by service, pins every image to the same release, generates all credentials, stores files in a Railway Bucket instead of MinIO, and loads the MITRE ATT&CK and OpenCTI reference datasets on first start.

## Common Use Cases

- Building a central threat intelligence knowledge base for a SOC or CERT team
- Mapping threat actors, campaigns and malware to MITRE ATT&CK techniques
- Importing PDF and HTML threat reports and extracting indicators and observables
- Sharing curated intelligence as STIX 2.1 bundles, CSV or TAXII feeds
- Connecting external feeds and enrichment services through OpenCTI connectors

## Dependencies for OpenCTI Hosting

- OpenCTI platform, worker and connectors 7.261008.0 (official `opencti/*` images)
- Elasticsearch 8.19
- Redis 8.2 (Railway Redis)
- RabbitMQ 4.3 with the management plugin
- S3-compatible object storage (Railway Bucket)

### Deployment Dependencies

- OpenCTI Docker setup (official compose this template follows): https://github.com/OpenCTI-Platform/docker
- OpenCTI documentation, installation and configuration: https://docs.opencti.io/latest/deployment/installation/
- OpenCTI connectors catalog: https://github.com/OpenCTI-Platform/connectors
- Railway Storage Buckets: https://docs.railway.com/storage-buckets

### Implementation Details

| Service | Image | Role |
|---|---|---|
| OpenCTI | `opencti/platform:7.261008.0` | Web UI, GraphQL API, background managers; public domain |
| OpenCTI Worker (3 replicas) | `opencti/worker:7.261008.0` | Processes queued bundles into the knowledge graph |
| connector-export-file-stix / -csv / -txt | `opencti/connector-export-file-*` | Exports to STIX 2.1, CSV and plain text |
| connector-import-file-stix, connector-import-document, connector-import-file-yara | `opencti/connector-import-*` | Imports STIX files, PDF/text/HTML reports and YARA rules |
| connector-analysis | `opencti/connector-import-document` | Content analysis of reports |
| connector-import-external-reference | `opencti/connector-import-external-reference` | Fetches external reference URLs as files |
| connector-opencti, connector-mitre | `opencti/connector-opencti`, `opencti/connector-mitre` | Reference datasets (markings, sectors, countries) and MITRE ATT&CK |
| Elasticsearch | built from `services/elasticsearch` (`elasticsearch:8.19.21`) | Knowledge graph indexes (volume) |
| RabbitMQ | `rabbitmq:4.3.6-management` | Work queues (volume) |
| Redis | `redis:8.2` | Cache, streams, locks (volume) |
| Bucket | Railway Bucket | Uploaded files, imports, exports |

**First login:** wait until the OpenCTI service is healthy, open its public URL and log in with `APP__ADMIN__EMAIL` (default `admin@opencti.io`, change it before the first deploy if you like) and the generated `APP__ADMIN__PASSWORD` from the OpenCTI service variables. Change the password in your profile. MITRE ATT&CK and the OpenCTI datasets start importing immediately; on the very first start these two connectors may restart once or twice while their service accounts are created.

**Adding connectors:** OpenCTI's connector manager normally starts containers through Docker, which Railway does not offer. Add each extra connector as its own Railway service with the image `opencti/connector-{name}:7.261008.0`, `OPENCTI_URL` and `OPENCTI_TOKEN` copied from an existing connector, a new UUIDv4 `CONNECTOR_ID`, and the connector's own settings from the connectors catalog.

**Scaling:** raise the OpenCTI Worker replica count for faster ingestion. Give Elasticsearch more memory together with a larger `ES_JAVA_OPTS` heap, and the platform more memory together with `NODE_OPTIONS`, as your knowledge base grows.

**E-mail:** OpenCTI sends notifications over SMTP only. Add `SMTP__HOSTNAME`, `SMTP__PORT`, `SMTP__USERNAME`, `SMTP__PASSWORD` and `SMTP__USE_SSL` to the OpenCTI service; Railway allows outbound SMTP on the Pro plan.

**Versions:** every OpenCTI image is pinned to `7.261008.0`. Upgrade by changing the tag on the platform, worker and all connectors together; the platform migrates its data on start. OpenCTI also publishes an LTS line if you prefer fewer upgrades.

### Why Deploy OpenCTI on Railway?

OpenCTI needs several cooperating services. Railway runs them all in one project with private networking, persistent volumes, a managed S3 bucket and an HTTPS domain, so the complete stack, with reference data loaded, comes up from one template. You can scale workers and give Elasticsearch more resources from the dashboard as your intelligence grows.


## Similar templates

- [Rocky Linux](https://railway.com/deploy/rocky-linux) — Hosted Rocky Linux 9 workspace with SSH and persistent storage. 🚀
- [Foundry Virtual Tabletop](https://railway.com/deploy/X5tR6G) — A Self-Hosted & Modern Roleplaying Platform
- [Letta Code Remote](https://railway.com/deploy/letta-code-remote) — Run a Letta Code agent 24/7. No inbound ports, just deploy.

Open this page in a browser: https://railway.com/deploy/opencti-7-threat-intelligence-platform
