Browse documentation
CROWDB / DOCUMENTATION

Single-node container

One local deployment option for evaluating the Iceberg and S3 interfaces.

DEVELOPMENT PREVIEW · OCTOBER 2, 2026

Choose an Iceberg or S3 entry point. Both images contain the same single-node CROWDB runtime: storage services, one Access Server with separate protocol listeners, and the Console. A second container is unnecessary when you need both interfaces.

This is one deployment option, not the definition of either access model. Iceberg and S3 document interface capabilities independently of deployment.

Images and ports

  • Iceberg users: crowdb/crowdb-iceberg; catalog and native FileIO on 9092.
  • S3 users: crowdb/crowdb-s3; object endpoint on 9091.
  • Optional Console: 9090. Dataset port 9093 is reserved; Dataset is not available yet.

Examples target the updated 909x release configuration. Verify the tags exist before pulling them; older images use different ports. latest moves with publication. Version tags can also be replaced by republication; pin a digest for exact image identity.

Start one container

Requires Docker with Linux amd64 support and disposable evaluation data. Publish only the interface you need:

docker run -d --name crowdb-iceberg \
  -p 127.0.0.1:9092:9092 \
  -v crowdb-iceberg-data:/opt/crowdb/data \
  --stop-timeout 120 \
  crowdb/crowdb-iceberg:latest

Or start the S3 entry point:

docker run -d --name crowdb-s3 \
  -p 127.0.0.1:9091:9091 \
  -v crowdb-s3-data:/opt/crowdb/data \
  --stop-timeout 120 \
  crowdb/crowdb-s3:latest

For both interfaces in one container, add both port mappings to either command. To use the Console, also add -p 127.0.0.1:9090:9090 and open http://localhost:9090. Table storage and S3 buckets remain separate namespaces.

Health and credentials

Use the name of the container you started:

docker inspect --format '{{.State.Health.Status}}' crowdb-iceberg
docker exec crowdb-iceberg crowdb-monitor credentials show --format env

Wait for healthy. Set the printed client values in your environment: ICEBERG_URI/ICEBERG_TOKEN for Iceberg; AWS_ENDPOINT_URL, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and AWS_DEFAULT_REGION for S3. Keep credentials private. Follow Iceberg tables or S3 objects for supported operations and client examples.

The defaults advertise http://localhost:9092 for Iceberg and http://localhost:9091 for S3. A different host or Iceberg port requires reachable advertised FileIO URLs as well as the client catalog URI. Port mapping alone does not rewrite those URLs.

Stop, resume, and inspect

docker stop --time 120 crowdb-iceberg
docker start crowdb-iceberg
docker logs --tail 100 crowdb-iceberg
docker exec crowdb-iceberg crowdb-monitor liveness
docker exec crowdb-iceberg crowdb-monitor readiness

The monitor recovers failed child services within its restart budget. An unhealthy Docker health check does not restart the container; --restart unless-stopped handles container exits. Docker logs can be bounded with --log-driver json-file --log-opt max-size=30m --log-opt max-file=5. CROWDB service logs live under /opt/crowdb/data/log.

Data and limits

  • Named volumes retain storage, metadata, credentials, and logs across recreation. Never attach one volume to two running containers. Bind mounts must be writable by UID/GID 10001.
  • Stop before backing up the whole volume; preserve ownership, private permissions, and sparse files. Restore using the same image digest. Cross-version volume upgrades are not supported.
  • One host, one voting replica, and one stored copy provide no redundancy. Four sparse 16 GiB disk images are configured; monitor real filesystem capacity.
  • Iceberg physical reclamation is disabled in this profile. Deleting logical content does not guarantee immediate reclaimed space.
  • This is development/test software, not a production deployment or broad client certification.

Troubleshooting

For an exited or unhealthy container, inspect logs and readiness before restarting. For port conflicts, check the selected 909x host port. Do not edit bootstrap manifests or secrets to bypass a rejected volume. Core dump collection follows the host policy; see the crash debugging guide.