Deployment
Production checklist
Minimum production hardening for Teldrive.
Pin the image
image: ghcr.io/tgdrive/teldrive:X.Y.ZHTTPS and proxy
Keep Teldrive private, terminate TLS at a reverse proxy, and configure http.trusted-proxies for that proxy.
Restrict login
security:
allowed-users:
- your_telegram_usernameAn empty list allows any Telegram user who completes login.
Protect keys
Back up:
security.signing-key
security.data-key
encryption.keysKeep recovery keys separate from PostgreSQL backups.
Protect PostgreSQL
- do not expose port
5432publicly; - use a dedicated database/user;
- require TLS for remote databases;
- restrict network access;
- monitor connection limits.
See Backup and restore.
Telegram rate limiting
telegram:
rate-limit: trueTune concurrency only after measuring throughput and Telegram errors.
Logs and monitoring
logging:
log-level: info
log-format: jsonMonitor CPU, memory, PostgreSQL connections, transfer throughput, Telegram errors, and failed jobs.
Upgrade
Follow Upgrading for backups, compatibility checks, and upgrade commands.
Topology
Internet
│
TLS reverse proxy
│
Teldrive ───── Telegram
│
PostgreSQL
│
Backups