Sign inSign up

cirruslink/chariot

By cirruslink

•Updated 1 day ago

Chariot is an MQTT server and IoT platform by Cirrus Link Solutions

Image
Internet of things
0

10.0K

cirruslink/chariot repository overview

⁠Chariot

Chariot is an MQTT server and IoT platform by Cirrus Link Solutions⁠. This image provides a fully configurable, production-ready Chariot deployment that can be configured entirely through environment variables on first run.

⁠Quick Start

docker run -d \
  -p 8080:8080 \
  -p 1883:1883 \
  -e ACCEPT_EULA=true \
  -e ADMIN_PASSWORD=mypassword \
  cirruslink/chariot:latest

⁠Docker Compose

services:
  chariot:
    image: cirruslink/chariot:latest
    ports:
      - "8080:8080"
      - "8443:8443"
      - "1883:1883"
      - "8883:8883"
      - "8090:8090"
      - "8091:8091"
    environment:
      ACCEPT_EULA: "true"
      ADMIN_PASSWORD: "mypassword"
    restart: unless-stopped

⁠Exposed Ports

PortProtocolDescription
8080HTTPWeb UI and REST API
8443HTTPSSecure Web UI and REST API
1883MQTTMQTT listener
8883MQTTSSecure MQTT listener
8090WSMQTT over WebSocket
8091WSSMQTT over Secure WebSocket

⁠Environment Variables

⁠General
VariableRequiredDescription
ACCEPT_EULAYesMust be set to true to start configuration. No configuration is applied if unset.
ADMIN_PASSWORDRecommendedSets the admin user password. If unset, the default credentials (admin/password) remain active.
⁠MQTT Users
VariableRequiredDescription
MQTT_USERSNoJSON array of MQTT users to create, or an absolute path to a JSON file mounted into the container.

Inline example:

MQTT_USERS=[{"username":"myuser","password":"mypassword","acl":{"subscribeTopics":["#"],"publishTopics":["#"]}}]

File example:

MQTT_USERS=/config/mqtt-users.json

Mount the file via a volume:

volumes:
  - ./mqtt-users.json:/config/mqtt-users.json:ro

JSON format:

[
  {
    "username": "myuser",
    "password": "mypassword",
    "acl": {
      "subscribeTopics": ["devices/#"],
      "publishTopics": ["devices/#"]
    }
  }
]
⁠Licensing
VariableRequiredDescription
LICENSE_TYPENoOne of online or floating. Leave empty to skip license activation.
LICENSE_KEYIf onlineLicense key for online activation.
LICENSE_SERVERIf floatingLicense server address for floating activation.
LICENSE_PRODUCTIf floatingProduct identifier for floating license.
⁠System Configuration
VariableRequiredDescription
CHARIOT_SERVER_NAMENoDisplay name for the Chariot instance.
HTTP_PORTNoHTTP listener port (default: 8080).
HTTPS_PORTNoHTTPS listener port (default: 8443).
HTTPS_ENABLEDNoEnable HTTPS (true/false).
⁠MQTT Server Configuration
VariableRequiredDescription
SERVER_CONFIGNoJSON object merged onto the default MQTT server config, or an absolute path to a JSON file mounted into the container. Only include fields you want to override.

Available fields:

FieldTypeDescription
portnumberMQTT listener port
securePortnumberMQTT TLS listener port
enableNonSecurebooleanEnable non-secure MQTT listener
enableSecurebooleanEnable secure MQTT listener
allowAnonymousbooleanAllow anonymous MQTT connections
bindAddressstringBind address (e.g. "0.0.0.0")
webSocketEnablebooleanEnable MQTT over WebSocket
webSocketPortnumberWebSocket listener port
webSocketEnableSecurebooleanEnable secure WebSocket
webSocketSecurePortnumberSecure WebSocket listener port
enforceUniqueLwtTopicbooleanEnforce unique LWT topics
uniqueLwtTopicFiltersstringLWT topic filter patterns

Inline example:

SERVER_CONFIG={"port":1883,"securePort":8883,"allowAnonymous":false}

File example:

SERVER_CONFIG=/config/server-config.json

Mount the file via a volume:

volumes:
  - ./server-config.json:/config/server-config.json:ro

Note: If you change MQTT service ports via SERVER_CONFIG, update the container-side port mappings in your compose file to match.

⁠TLS / SSL
VariableRequiredDescription
SETUP_SSLNoSet to true to enable SSL configuration.
TLS_PRIVATE_KEYIf SETUP_SSL=truePath to the private key file inside the container.
TLS_CERTIFICATEIf SETUP_SSL=truePath to the certificate file inside the container.
TLS_CA_CHAINIf SETUP_SSL=truePath to the CA chain file inside the container.

Mount your certificate files and reference them by their container paths:

volumes:
  - ./certs:/certs:ro
environment:
  SETUP_SSL: "true"
  TLS_PRIVATE_KEY: /certs/privkey.pem
  TLS_CERTIFICATE: /certs/cert.pem
  TLS_CA_CHAIN: /certs/chain.pem
⁠Backup Restore
VariableRequiredDescription
BACKUP_FILENoPath to a Chariot backup zip file inside the container. Applied on first run.
volumes:
  - ./my-backup.zip:/backups/backup.zip:ro
environment:
  BACKUP_FILE: /backups/backup.zip

Note: Backups are restored first in the configuration process. Settings provided via environment variables (admin password, license, server config, etc.) will take precedence over anything in the backup.

⁠IBSnow (Snowflake IoT Bridge)
VariableRequiredDescription
IBSNOW_CONFIGNoJSON object merged onto the default IBSnow config, or an absolute path to a JSON file mounted into the container.
IBSNOW_SERVERSNoJSON array of IBSnow server definitions, or an absolute path to a JSON file.
IBSNOW_CERTSNoJSON array of absolute paths to certificate files to upload.

Configuration example (inline):

IBSNOW_CONFIG={"snowflake_application_enabled":true,"ibsnow_instance_name":"prod-1","streaming_profile_account":"xy12345"}

Configuration example (file):

IBSNOW_CONFIG=/config/ibsnow-config.json
volumes:
  - ./ibsnow-config.json:/config/ibsnow-config.json:ro

Servers example (inline):

IBSNOW_SERVERS=[{"url":"tcp://localhost:1883","name":"Server 1","subscriptions":"sub1,sub2","verifyHostname":false,"username":"user1","password":"password","clientId":"my-client"}]

Servers example (file):

IBSNOW_SERVERS=/config/ibsnow-servers.json
volumes:
  - ./ibsnow-servers.json:/config/ibsnow-servers.json:ro

Certificates example:

volumes:
  - ./ibsnow-certs:/certs:ro
environment:
  IBSNOW_CERTS: '["/certs/rsa_key.p8","/certs/cert.pem"]'

⁠Configuration Behavior

All configuration is applied once on first startup by an init script that runs in the background. A sentinel file at /Chariot/config-state/state.json tracks which steps have been completed. On subsequent restarts, completed steps are skipped.

To re-apply a specific configuration step, set its applied value to false in the sentinel file and restart the container.

Configuration order:

  1. Restore backup
  2. Set admin password
  3. Activate license
  4. Apply MQTT server configuration
  5. Upload IBSnow certificates
  6. Create IBSnow servers
  7. Apply IBSnow configuration
  8. Create MQTT users
  9. Setup SSL
  10. Apply system configuration

⁠Health Check

The image includes a built-in health check that polls the REST API every 30 seconds with a 60-second startup grace period. Container orchestrators like Docker Compose and Kubernetes will automatically detect when Chariot is ready to serve traffic.

⁠Architectures

This image is published as a multi-architecture manifest supporting linux/amd64 and linux/arm64.

Tag summary

Content type

Image

Digest

sha256:185cef0ca…

Size

942.6 MB

Last updated

about 2 months ago

docker pull cirruslink/chariot