Skip to main content
View as Markdown

Deploy Sovrium on Scalingo

You want a git-push deploy on a European PaaS, with a managed database and no server to run yourself.

Configure the app

Scalingo builds with buildpacks, not with your Dockerfile, so the repository needs three files. .buildpacks selects the Sovrium buildpack, which downloads the released, checksum-verified binary into bin/. .sovrium-version pins which release to fetch. The Procfile boots it.

code
# .buildpacks
https://github.com/sovrium/scalingo-buildpack
code
# .sovrium-version — the release to download; bump it to upgrade
0.22.2

Pin whichever release you want from the releases page; the buildpack verifies the checksum before installing it. A version that does not exist fails the build rather than deploying something unexpected.

code
# Procfile
web: bin/sovrium start app.ts

The bin/ prefix matters: the buildpack installs the binary into the app tree, not onto the system PATH.

Then add a managed PostgreSQL database so the app runs on Postgres instead of the SQLite default, and set the environment:

>_ terminal
scalingo --app my-app addons-add postgresql postgresql-starter-1024
scalingo --app my-app env-set \
  SOVRIUM_ENCRYPTION_KEY="$(openssl rand -hex 32)" \
  BASE_URL=https://my-app.osc-fr1.scalingo.io \
  NODE_ENV=production \
  TRUSTED_PROXY_HOPS=1

Pick the add-on plan that fits your data; run scalingo addons-plans postgresql to see the current list. NODE_ENV=production is not cosmetic — it switches Sovrium to immutable caching for content-hashed assets. Without it every asset is re-fetched on each page view.

SOVRIUM_ENCRYPTION_KEY is the only secret in that list, and it is set here for a reason worth knowing. Sovrium generates its own key when none is given, but Scalingo rebuilds the container filesystem on every deploy and restart, while the managed database keeps everything that key encrypted. Generated, the key would be new each time and the stored credentials would stop opening. Setting it once removes the problem. The session-signing secret derives from it, so there is no second value to set — see Secrets.

TRUSTED_PROXY_HOPS=1 accounts for Scalingo's own router, which is what stands between the internet and your container. It lets Sovrium believe the client address the router forwards, so rate limits count per visitor instead of lumping every request onto the router's address. Raise it only if you put your own CDN in front of Scalingo, and never above the number of proxies actually in the path — see Running behind a reverse proxy.

Scalingo injects DATABASE_URL and PORT automatically — Sovrium reads both, so no extra wiring is needed.

Deploy and verify

Scalingo deploys from master, so push your branch to that ref explicitly:

>_ terminal
git push scalingo HEAD:refs/heads/master
curl -fsS https://my-app.osc-fr1.scalingo.io/ >/dev/null && echo "up"

Next

Last updated September 1, 2026

This documentation was written with AI, so errors or outdated content are possible. Sovrium is in beta. Contributions and corrections are welcome.

Built with Sovrium