---
title: "Deploy SigNoz | (Just Updated) Datadog Alternative, Admin Locked To You"
description: "Traces, logs and metrics on ClickHouse. Admin seeded, ingest token-locked."
category: "Observability"
url: https://railway.com/deploy/signoz-or-just-updated-datadog-alternati
---

# Deploy SigNoz | (Just Updated) Datadog Alternative, Admin Locked To You

Traces, logs and metrics on ClickHouse. Admin seeded, ingest token-locked.

**[Deploy SigNoz | (Just Updated) Datadog Alternative, Admin Locked To You on Railway](https://railway.com/template/signoz-or-just-updated-datadog-alternati)**

Machine-readable deploy manifest (JSON, validated by TemplateCI): https://railway.com/deploy/signoz-or-just-updated-datadog-alternati/manifest.json

- **Creator:** SuperSlowSloth
- **Category:** Observability

## Template content

### otel-collector

- **Image:** signoz/signoz-otel-collector:v0.144.8
- **Start command:** `/bin/sh -c 'echo cmVjZWl2ZXJzOgogIG90bHA6CiAgICBwcm90b2NvbHM6CiAgICAgIGdycGM6CiAgICAgICAgZW5kcG9pbnQ6IDAuMC4wLjA6NDMxNwogICAgICAgIGF1dGg6CiAgICAgICAgICBhdXRoZW50aWNhdG9yOiBiZWFyZXJ0b2tlbmF1dGgKICAgICAgaHR0cDoKICAgICAgICBlbmRwb2ludDogMC4wLjAuMDoke2VudjpQT1JUfQogICAgICAgIGF1dGg6CiAgICAgICAgICBhdXRoZW50aWNhdG9yOiBiZWFyZXJ0b2tlbmF1dGgKcHJvY2Vzc29yczoKICBiYXRjaDoKICAgIHNlbmRfYmF0Y2hfc2l6ZTogMTAwMAogICAgdGltZW91dDogMTBzCmV4dGVuc2lvbnM6CiAgYmVhcmVydG9rZW5hdXRoOgogICAgc2NoZW1lOiBCZWFyZXIKICAgIHRva2VuOiAke2VudjpJTkdFU1RfVE9LRU59CmV4cG9ydGVyczoKICBjbGlja2hvdXNldHJhY2VzOgogICAgZGF0YXNvdXJjZTogJHtlbnY6Q0xJQ0tIT1VTRV9EU059CiAgICB1c2VfbmV3X3NjaGVtYTogdHJ1ZQogIHNpZ25vemNsaWNraG91c2VtZXRyaWNzOgogICAgZHNuOiAke2VudjpDTElDS0hPVVNFX0RTTn0KICBjbGlja2hvdXNlbG9nc2V4cG9ydGVyOgogICAgZHNuOiAke2VudjpDTElDS0hPVVNFX0RTTn0KICAgIHVzZV9uZXdfc2NoZW1hOiB0cnVlCnNlcnZpY2U6CiAgZXh0ZW5zaW9uczogW2JlYXJlcnRva2VuYXV0aF0KICBwaXBlbGluZXM6CiAgICB0cmFjZXM6CiAgICAgIHJlY2VpdmVyczogW290bHBdCiAgICAgIHByb2Nlc3NvcnM6IFtiYXRjaF0KICAgICAgZXhwb3J0ZXJzOiBbY2xpY2tob3VzZXRyYWNlc10KICAgIG1ldHJpY3M6CiAgICAgIHJlY2VpdmVyczogW290bHBdCiAgICAgIHByb2Nlc3NvcnM6IFtiYXRjaF0KICAgICAgZXhwb3J0ZXJzOiBbc2lnbm96Y2xpY2tob3VzZW1ldHJpY3NdCiAgICBsb2dzOgogICAgICByZWNlaXZlcnM6IFtvdGxwXQogICAgICBwcm9jZXNzb3JzOiBbYmF0Y2hdCiAgICAgIGV4cG9ydGVyczogW2NsaWNraG91c2Vsb2dzZXhwb3J0ZXJdCg== | base64 -d > /tmp/otel.yaml; M="--clickhouse-dsn=$CLICKHOUSE_DSN --clickhouse-replication=false"; i=0; while [ $i -lt 60 ]; do /signoz-otel-collector migrate bootstrap $M && break; echo "[railway] waiting for ClickHouse..."; i=$((i+1)); sleep 5; done; /signoz-otel-collector migrate sync up $M || echo "[railway] sync migrations failed"; /signoz-otel-collector migrate async up $M || echo "[railway] async migrations failed"; exec /signoz-otel-collector --config /tmp/otel.yaml'`
- **Public domain:** Yes

### signoz

- **Image:** signoz/signoz:v0.136.1
- **Start command:** `/bin/sh -c 'export SIGNOZ_SQLSTORE_SQLITE_PATH=/var/lib/signoz/signoz.db; cd /root && ./signoz server & SP=$!; i=0; while [ $i -lt 150 ]; do wget -q -O /dev/null http://127.0.0.1:8080/api/v1/health && break; i=$((i+1)); sleep 2; done; if wget -q -O /dev/null --header="Content-Type: application/json" --post-data="{\"email\":\"$ADMIN_EMAIL\",\"name\":\"Admin\",\"orgName\":\"SigNoz\",\"password\":\"$ADMIN_PASSWORD\"}" http://127.0.0.1:8080/api/v1/register; then echo "[railway] admin account claimed for $ADMIN_EMAIL"; else echo "[railway] admin not seeded (already set up, or ADMIN_PASSWORD rejected: needs 12+ chars with upper, lower, digit and symbol)"; fi; wait $SP'`
- **Health check:** /api/v1/health
- **Public domain:** Yes

### clickhouse

- **Image:** clickhouse/clickhouse-server:25.12.5
- **Start command:** `/bin/sh -c 'mkdir -p /etc/clickhouse-server/config.d && echo PGNsaWNraG91c2U+CiAgPGxpc3Rlbl9ob3N0PjAuMC4wLjA8L2xpc3Rlbl9ob3N0PgogIDx6b29rZWVwZXI+PG5vZGU+PGhvc3Q+MTI3LjAuMC4xPC9ob3N0Pjxwb3J0PjkxODE8L3BvcnQ+PC9ub2RlPjwvem9va2VlcGVyPgogIDxrZWVwZXJfc2VydmVyPgogICAgPHRjcF9wb3J0PjkxODE8L3RjcF9wb3J0PgogICAgPHNlcnZlcl9pZD4xPC9zZXJ2ZXJfaWQ+CiAgICA8bG9nX3N0b3JhZ2VfcGF0aD4vdmFyL2xpYi9jbGlja2hvdXNlL2Nvb3JkaW5hdGlvbi9sb2c8L2xvZ19zdG9yYWdlX3BhdGg+CiAgICA8c25hcHNob3Rfc3RvcmFnZV9wYXRoPi92YXIvbGliL2NsaWNraG91c2UvY29vcmRpbmF0aW9uL3NuYXBzaG90czwvc25hcHNob3Rfc3RvcmFnZV9wYXRoPgogICAgPGNvb3JkaW5hdGlvbl9zZXR0aW5ncz4KICAgICAgPG9wZXJhdGlvbl90aW1lb3V0X21zPjEwMDAwPC9vcGVyYXRpb25fdGltZW91dF9tcz4KICAgICAgPHNlc3Npb25fdGltZW91dF9tcz4zMDAwMDwvc2Vzc2lvbl90aW1lb3V0X21zPgogICAgPC9jb29yZGluYXRpb25fc2V0dGluZ3M+CiAgICA8cmFmdF9jb25maWd1cmF0aW9uPgogICAgICA8c2VydmVyPjxpZD4xPC9pZD48aG9zdG5hbWU+MTI3LjAuMC4xPC9ob3N0bmFtZT48cG9ydD45MjM0PC9wb3J0Pjwvc2VydmVyPgogICAgPC9yYWZ0X2NvbmZpZ3VyYXRpb24+CiAgPC9rZWVwZXJfc2VydmVyPgogIDxyZW1vdGVfc2VydmVycz4KICAgIDxjbHVzdGVyPgogICAgICA8c2hhcmQ+CiAgICAgICAgPGludGVybmFsX3JlcGxpY2F0aW9uPnRydWU8L2ludGVybmFsX3JlcGxpY2F0aW9uPgogICAgICAgIDxyZXBsaWNhPjxob3N0PjEyNy4wLjAuMTwvaG9zdD48cG9ydD45MDAwPC9wb3J0PjwvcmVwbGljYT4KICAgICAgPC9zaGFyZD4KICAgIDwvY2x1c3Rlcj4KICA8L3JlbW90ZV9zZXJ2ZXJzPgogIDxtYWNyb3M+PHNoYXJkPjAxPC9zaGFyZD48cmVwbGljYT4wMTwvcmVwbGljYT48Y2x1c3Rlcj5jbHVzdGVyPC9jbHVzdGVyPjwvbWFjcm9zPgo8L2NsaWNraG91c2U+Cg== | base64 -d > /etc/clickhouse-server/config.d/railway.xml && export CLICKHOUSE_USER=signoz CLICKHOUSE_DB=default && exec /entrypoint.sh'`

## Documentation

# Deploy and Host SigNoz on Railway

SigNoz is an open-source observability platform — distributed traces, metrics and logs in one
application, stored in ClickHouse. It is the self-hosted alternative to Datadog and New Relic,
speaks OpenTelemetry natively, and needs no proprietary agent.

This template deploys SigNoz as **three services**: ClickHouse (with ClickHouse Keeper embedded in
the same process), the SigNoz application, and an OpenTelemetry collector that accepts your
telemetry over OTLP.

## About Hosting SigNoz

SigNoz is not a single container. It needs a ClickHouse cluster, a coordination service for the
replicated-table DDL it issues, a schema migration step that must complete before the application
starts, and a collector to receive OTLP. Getting those four things to agree is most of the work,
and it is where self-hosted SigNoz deployments usually go wrong.

Three things this template does that are easy to get wrong:

- **Coordination state lives on the volume.** ClickHouse Keeper runs embedded in the ClickHouse
  process and writes its log and snapshots under `/var/lib/clickhouse/coordination`, which is
  inside the mounted volume. If coordination state is lost, ClickHouse brings the replicated
  tables back **read-only** — the container still looks healthy, the UI still loads, and ingest
  silently stops. Verified here by destroying the container and bringing it back on the same
  volume: existing spans were still readable and a fresh OTLP push still landed.
- **The schema migrations run before the collector serves.** The collector service runs
  `migrate bootstrap`, `migrate sync up` and `migrate async up` against ClickHouse, retrying
  until ClickHouse accepts connections, and only then starts receiving. Migrations are
  idempotent, so a redeploy is safe.
- **Both stateful services have volumes.** ClickHouse holds your telemetry, and the SigNoz
  application holds its SQLite database — users, dashboards, saved views and alert rules.
  Without a volume on the second one, every redeploy loses your dashboards even though the
  telemetry survives.

## Why Deploy SigNoz on Railway

Railway gives each service a private network address, a managed volume and a public domain, which
is exactly the shape this stack needs — ClickHouse stays private, the application and the ingest
endpoint each get their own URL.

Two problems in the general self-hosted case are closed here by construction:

**The admin account is yours before anyone else can take it.** A stock SigNoz has no users on
first boot, and its `/api/v1/register` endpoint hands out the first account with `isRoot: true`
to whoever calls it. On a public URL that is a race, and losing it means a stranger owns your
observability data. This template registers the first account from your own template variables
during boot, so by the time the URL answers, setup is complete and SigNoz reports
`self-registration is disabled` to everybody else. Verified against the running deployment.

**The ingest endpoint requires a token.** SigNoz Core has no ingest authentication of its own, so
a public OTLP endpoint lets anyone write into your ClickHouse — on a platform that bills for the
storage. The collector here is configured with a bearer-token authenticator, so OTLP pushes
without `Authorization: Bearer $INGEST_TOKEN` are rejected with 401.

All three images are pinned to explicit versions rather than a floating tag, so a redeploy
rebuilds what you already tested. ClickHouse carries one-way schema migrations, which makes an
unpinned tag a genuine risk rather than a stylistic preference.

## Common Use Cases

- Replace Datadog or New Relic for application traces, metrics and logs at a fixed hosting cost
- Give an OpenTelemetry-instrumented service a backend to send to, without signing up for a SaaS
- Debug latency across services with distributed traces and flamegraphs
- Centralise logs from several Railway services and query them alongside the traces
- Run dashboards and alert rules over telemetry you keep on your own infrastructure

## Dependencies for SigNoz

- **ClickHouse** — the telemetry store, with ClickHouse Keeper embedded for cluster coordination
- **OpenTelemetry collector** — the SigNoz distribution, which also runs the schema migrations
- **OpenTelemetry SDK or collector in your own app** — to produce the telemetry

### Deployment Dependencies

- SigNoz: https://signoz.io — source at https://github.com/SigNoz/signoz
- OpenTelemetry OTLP specification: https://opentelemetry.io/docs/specs/otlp/
- ClickHouse: https://clickhouse.com

### After deploying

1. Set **`ADMIN_EMAIL`** on the deploy form. That address becomes the owner account.
2. After the deploy finishes, read **`ADMIN_PASSWORD`** from the SigNoz service's variables and
   sign in with it. Change it from inside the UI once you are in.
3. Point your application at the collector's public URL, with the token:

   ```
   OTEL_EXPORTER_OTLP_ENDPOINT=https://
   OTEL_EXPORTER_OTLP_HEADERS=Authorization=Bearer 
   OTEL_EXPORTER_OTLP_PROTOCOL=http/protobuf
   ```

   `INGEST_TOKEN` is generated for you and lives on the collector service's variables. Services
   running inside the same Railway project can also reach the collector privately on port 4317
   (OTLP gRPC) without going through the public domain.

**A note on plan sizing.** ClickHouse is the memory-hungry part of this stack. It idles at roughly
250 MB and settles near 550 MB once the SigNoz schema is in place, so it fits a 1 GB service, but
it will want considerably more as your telemetry volume grows — ClickHouse trades memory for query
speed by design. Give it Hobby-plan headroom if you intend to keep more than a little data, and
set a retention period in SigNoz's settings early rather than late.


## Similar templates

- [Rootprint](https://railway.com/deploy/rootprint-1) — Open-source logs and traces with full-text search on object-storage.
- [Pyroscope profiling](https://railway.com/deploy/pyroscope-profiling) — Protected continuous profiling with durable Pyroscope storage.
- [SigOnly](https://railway.com/deploy/sigonly) — Deploy SigNoz with a working demo app & config in one click

Open this page in a browser: https://railway.com/deploy/signoz-or-just-updated-datadog-alternati
