Production checklist
Teldrive
Deployment

Production checklist

Minimum production hardening for Teldrive.

Pin the image

image: ghcr.io/tgdrive/teldrive:X.Y.Z

HTTPS and proxy

Keep Teldrive private, terminate TLS at a reverse proxy, and configure http.trusted-proxies for that proxy.

See Reverse proxy & HTTPS.

Restrict login

security:
  allowed-users:
    - your_telegram_username

An empty list allows any Telegram user who completes login.

Protect keys

Back up:

security.signing-key
security.data-key
encryption.keys

Keep recovery keys separate from PostgreSQL backups.

Protect PostgreSQL

  • do not expose port 5432 publicly;
  • use a dedicated database/user;
  • require TLS for remote databases;
  • restrict network access;
  • monitor connection limits.

See Backup and restore.

Telegram rate limiting

telegram:
  rate-limit: true

Tune concurrency only after measuring throughput and Telegram errors.

Logs and monitoring

logging:
  log-level: info
  log-format: json

Monitor CPU, memory, PostgreSQL connections, transfer throughput, Telegram errors, and failed jobs.

Upgrade

Follow Upgrading for backups, compatibility checks, and upgrade commands.

Topology

Internet
   │
TLS reverse proxy
   │
Teldrive ───── Telegram
   │
PostgreSQL
   │
Backups