Chariot is an MQTT server and IoT platform by Cirrus Link Solutions
10.0K
Chariot is an MQTT server and IoT platform by Cirrus Link Solutions. This image provides a fully configurable, production-ready Chariot deployment that can be configured entirely through environment variables on first run.
docker run -d \
-p 8080:8080 \
-p 1883:1883 \
-e ACCEPT_EULA=true \
-e ADMIN_PASSWORD=mypassword \
cirruslink/chariot:latest
services:
chariot:
image: cirruslink/chariot:latest
ports:
- "8080:8080"
- "8443:8443"
- "1883:1883"
- "8883:8883"
- "8090:8090"
- "8091:8091"
environment:
ACCEPT_EULA: "true"
ADMIN_PASSWORD: "mypassword"
restart: unless-stopped
| Port | Protocol | Description |
|---|---|---|
| 8080 | HTTP | Web UI and REST API |
| 8443 | HTTPS | Secure Web UI and REST API |
| 1883 | MQTT | MQTT listener |
| 8883 | MQTTS | Secure MQTT listener |
| 8090 | WS | MQTT over WebSocket |
| 8091 | WSS | MQTT over Secure WebSocket |
| Variable | Required | Description |
|---|---|---|
ACCEPT_EULA | Yes | Must be set to true to start configuration. No configuration is applied if unset. |
ADMIN_PASSWORD | Recommended | Sets the admin user password. If unset, the default credentials (admin/password) remain active. |
| Variable | Required | Description |
|---|---|---|
MQTT_USERS | No | JSON array of MQTT users to create, or an absolute path to a JSON file mounted into the container. |
Inline example:
MQTT_USERS=[{"username":"myuser","password":"mypassword","acl":{"subscribeTopics":["#"],"publishTopics":["#"]}}]
File example:
MQTT_USERS=/config/mqtt-users.json
Mount the file via a volume:
volumes:
- ./mqtt-users.json:/config/mqtt-users.json:ro
JSON format:
[
{
"username": "myuser",
"password": "mypassword",
"acl": {
"subscribeTopics": ["devices/#"],
"publishTopics": ["devices/#"]
}
}
]
| Variable | Required | Description |
|---|---|---|
LICENSE_TYPE | No | One of online or floating. Leave empty to skip license activation. |
LICENSE_KEY | If online | License key for online activation. |
LICENSE_SERVER | If floating | License server address for floating activation. |
LICENSE_PRODUCT | If floating | Product identifier for floating license. |
| Variable | Required | Description |
|---|---|---|
CHARIOT_SERVER_NAME | No | Display name for the Chariot instance. |
HTTP_PORT | No | HTTP listener port (default: 8080). |
HTTPS_PORT | No | HTTPS listener port (default: 8443). |
HTTPS_ENABLED | No | Enable HTTPS (true/false). |
| Variable | Required | Description |
|---|---|---|
SERVER_CONFIG | No | JSON object merged onto the default MQTT server config, or an absolute path to a JSON file mounted into the container. Only include fields you want to override. |
Available fields:
| Field | Type | Description |
|---|---|---|
port | number | MQTT listener port |
securePort | number | MQTT TLS listener port |
enableNonSecure | boolean | Enable non-secure MQTT listener |
enableSecure | boolean | Enable secure MQTT listener |
allowAnonymous | boolean | Allow anonymous MQTT connections |
bindAddress | string | Bind address (e.g. "0.0.0.0") |
webSocketEnable | boolean | Enable MQTT over WebSocket |
webSocketPort | number | WebSocket listener port |
webSocketEnableSecure | boolean | Enable secure WebSocket |
webSocketSecurePort | number | Secure WebSocket listener port |
enforceUniqueLwtTopic | boolean | Enforce unique LWT topics |
uniqueLwtTopicFilters | string | LWT topic filter patterns |
Inline example:
SERVER_CONFIG={"port":1883,"securePort":8883,"allowAnonymous":false}
File example:
SERVER_CONFIG=/config/server-config.json
Mount the file via a volume:
volumes:
- ./server-config.json:/config/server-config.json:ro
Note: If you change MQTT service ports via
SERVER_CONFIG, update the container-side port mappings in your compose file to match.
| Variable | Required | Description |
|---|---|---|
SETUP_SSL | No | Set to true to enable SSL configuration. |
TLS_PRIVATE_KEY | If SETUP_SSL=true | Path to the private key file inside the container. |
TLS_CERTIFICATE | If SETUP_SSL=true | Path to the certificate file inside the container. |
TLS_CA_CHAIN | If SETUP_SSL=true | Path to the CA chain file inside the container. |
Mount your certificate files and reference them by their container paths:
volumes:
- ./certs:/certs:ro
environment:
SETUP_SSL: "true"
TLS_PRIVATE_KEY: /certs/privkey.pem
TLS_CERTIFICATE: /certs/cert.pem
TLS_CA_CHAIN: /certs/chain.pem
| Variable | Required | Description |
|---|---|---|
BACKUP_FILE | No | Path to a Chariot backup zip file inside the container. Applied on first run. |
volumes:
- ./my-backup.zip:/backups/backup.zip:ro
environment:
BACKUP_FILE: /backups/backup.zip
Note: Backups are restored first in the configuration process. Settings provided via environment variables (admin password, license, server config, etc.) will take precedence over anything in the backup.
| Variable | Required | Description |
|---|---|---|
IBSNOW_CONFIG | No | JSON object merged onto the default IBSnow config, or an absolute path to a JSON file mounted into the container. |
IBSNOW_SERVERS | No | JSON array of IBSnow server definitions, or an absolute path to a JSON file. |
IBSNOW_CERTS | No | JSON array of absolute paths to certificate files to upload. |
Configuration example (inline):
IBSNOW_CONFIG={"snowflake_application_enabled":true,"ibsnow_instance_name":"prod-1","streaming_profile_account":"xy12345"}
Configuration example (file):
IBSNOW_CONFIG=/config/ibsnow-config.json
volumes:
- ./ibsnow-config.json:/config/ibsnow-config.json:ro
Servers example (inline):
IBSNOW_SERVERS=[{"url":"tcp://localhost:1883","name":"Server 1","subscriptions":"sub1,sub2","verifyHostname":false,"username":"user1","password":"password","clientId":"my-client"}]
Servers example (file):
IBSNOW_SERVERS=/config/ibsnow-servers.json
volumes:
- ./ibsnow-servers.json:/config/ibsnow-servers.json:ro
Certificates example:
volumes:
- ./ibsnow-certs:/certs:ro
environment:
IBSNOW_CERTS: '["/certs/rsa_key.p8","/certs/cert.pem"]'
All configuration is applied once on first startup by an init script that runs in the background. A sentinel file at /Chariot/config-state/state.json tracks which steps have been completed. On subsequent restarts, completed steps are skipped.
To re-apply a specific configuration step, set its applied value to false in the sentinel file and restart the container.
Configuration order:
The image includes a built-in health check that polls the REST API every 30 seconds with a 60-second startup grace period. Container orchestrators like Docker Compose and Kubernetes will automatically detect when Chariot is ready to serve traffic.
This image is published as a multi-architecture manifest supporting linux/amd64 and linux/arm64.
Content type
Image
Digest
sha256:185cef0ca…
Size
942.6 MB
Last updated
about 2 months ago
docker pull cirruslink/chariot