Sign inSign up

system4us/salamandr-backend

By system4us

•Updated 26 days ago

Self-hosted support ticket & helpdesk system. Fast, private Zendesk alternative in Go & Postgres.

Image
Security
Web servers
Databases & storage
1

959

system4us/salamandr-backend repository overview

⁠Salamandr — Self-Hosted Support Ticket & Customer Helpdesk

Docker Pulls Docker Image Size License: AGPL-3.0 Artifact Hub Architectures

The modern, privacy-first, self-hosted omnichannel customer support platform you actually own.

Salamandr is a high-performance open-source alternative to Zendesk, Freshdesk, Intercom, and osTicket. It combines a high-throughput Go (Golang) backend, PostgreSQL (with pgvector & Row-Level Security), Redis, and an embedded React web interface in a single container.


⁠⚡ Why Teams Switch to Salamandr

CapabilitySalamandrLegacy SaaS Helpdesks
Data Custody & Privacy100% On-Premises / Self-Hosted (GDPR, HIPAA, SOC 2 compliant)Hosted on third-party multi-tenant clouds
Pricing & Seat EconomyPredictable self-hosted fleet licensing — No per-seat penaltyExpensive per-agent per-month recurring seats
Telemetry & TrackingZero Telemetry Guarantee — Nothing phones home, air-gap readyMandatory telemetry, tracking pixels, and diagnostics
Local AI & Document RAGAir-Gapped Ollama + pgvector (No third-party LLM data leaks)Cloud APIs training on your customer tickets
ArchitectureSingle-binary Web + API in Go (sub-millisecond routing, low RAM)Heavy legacy monoliths or bloated microservices
Omnichannel CoreEmail (IMAP/SMTP), WhatsApp Cloud API, Live Chat, Slack, DiscordPaywalled add-ons per channel

⁠🚀 Quickstart (Docker Compose)

Get a production-grade Salamandr helpdesk running in under 2 minutes:

# docker-compose.yml
services:
  backend:
    image: system4us/salamandr-backend:community
    restart: unless-stopped
    ports:
      - "8080:8080"
    environment:
      - APP_DOMAIN=helpdesk.example.com
      - FRONTEND_URL=http://localhost:8080
      - BACKEND_URL=http://localhost:8080
      - DATABASE_URL=postgres://salamandr_app:AppSecretPass123!@postgres:5432/salamandr?sslmode=disable
      - MIGRATIONS_DATABASE_URL=postgres://salamandr:AdminSecretPass123!@postgres:5432/salamandr?sslmode=disable
      - REDIS_URL=redis://:RedisSecretPass123!@redis:6379/0
      - SESSION_SECRET=0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef
      - ENCRYPTION_KEY=dGhpcy1pcy1hLXNhbXBsZS1lbmNyeXB0aW9uLWtleS0zMndheXM=
      - [email protected]
      - ADMIN_PASSWORD=ChangeThisAdminPassword123!
    volumes:
      - attachments_data:/data/attachments
    depends_on:
      postgres:
        condition: service_healthy
      redis:
        condition: service_healthy

  worker:
    image: system4us/salamandr-worker:community
    restart: unless-stopped
    environment:
      - DATABASE_URL=postgres://salamandr_app:AppSecretPass123!@postgres:5432/salamandr?sslmode=disable
      - MIGRATIONS_DATABASE_URL=postgres://salamandr:AdminSecretPass123!@postgres:5432/salamandr?sslmode=disable
      - REDIS_URL=redis://:RedisSecretPass123!@redis:6379/0
      - ENCRYPTION_KEY=dGhpcy1pcy1hLXNhbXBsZS1lbmNyeXB0aW9uLWtleS0zMndheXM=
    volumes:
      - attachments_data:/data/attachments
    depends_on:
      - backend

  postgres:
    image: pgvector/pgvector:pg16
    restart: unless-stopped
    environment:
      POSTGRES_DB: salamandr
      POSTGRES_USER: salamandr
      POSTGRES_PASSWORD: AdminSecretPass123!
      APP_DB_PASSWORD: AppSecretPass123!
    volumes:
      - postgres_data:/var/lib/postgresql/data
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U salamandr -d salamandr"]
      interval: 5s
      timeout: 5s
      retries: 5

  redis:
    image: redis:7-alpine
    restart: unless-stopped
    command: exec redis-server --appendonly yes --requirepass RedisSecretPass123!
    volumes:
      - redis_data:/data
    healthcheck:
      test: ["CMD", "redis-cli", "-a", "RedisSecretPass123!", "ping"]
      interval: 5s
      timeout: 5s
      retries: 5

volumes:
  attachments_data:
  postgres_data:
  redis_data:
⁠Run and Access
docker compose up -d
docker compose logs -f backend

Open http://localhost:8080 in your browser and sign in with [email protected] / ChangeThisAdminPassword123!.


⁠⚙ Environment Variables Reference

VariableDescriptionRequiredDefault
APP_DOMAINThe public domain name of your instance (e.g. helpdesk.example.com).Yeslocalhost
FRONTEND_URLPublic origin allowed to call the API and base for all links in outbound emails.Yeshttp://localhost:8080
BACKEND_URLPublic base URL used for OAuth callbacks and redirects.Yeshttp://localhost:8080
DATABASE_URLConnection string for the unprivileged application role (salamandr_app).Yes-
MIGRATIONS_DATABASE_URLConnection string with owner privileges to apply database schema migrations.Yes-
REDIS_URLRedis connection URL for sessions, rate-limit windows, and verification tokens.Yesredis://redis:6379/0
SESSION_SECRET64-character hex string used to sign session cookies securely.Yes-
ENCRYPTION_KEY32-byte Base64 key to encrypt stored email passwords, OAuth tokens, and secrets.Yes-
ADMIN_EMAILDefault administrator account created on first startup.Yes[email protected]
ADMIN_PASSWORDInitial administrator password (change in UI after login).Yes-
ATTACHMENTS_DIRLocal directory for file uploads when S3 storage is disabled.No/data/attachments
S3_BUCKETS3/R2/B2/MinIO bucket name for scalable object storage.No""
OLLAMA_HOSTURL to your local Ollama instance for on-premise AI assistance.No""
TRUSTED_PROXY_CIDRSCIDR blocks of upstream reverse proxies (e.g. 172.16.0.0/12).Conditional""

⁠✨ Comprehensive Feature Suite

⁠1. Omnichannel Unified Inbox
  • Two-way Email: IMAP polling + SMTP sending with threading, spam blacklist, and strict DKIM/SPF sender validation.
  • WhatsApp Cloud API: Native integration with 24-hour service window handling and Meta message templates (BYO Meta App).
  • Website Live Chat Widget: Lightweight embeddable widget with real-time Server-Sent Events (SSE), visitor presence, and typing indicators.
  • ChatOps Mirrors: Real-time ticket mirroring into Slack, Mattermost, Discord, and Zulip channels.
⁠2. Air-Gapped Local AI & Document RAG
  • Connect your own local Ollama instance (bge-m3 embeddings + qwen2.5-coder / gemma2).
  • Ingest PDF runbooks, technical documentation, and spreadsheets into PostgreSQL pgvector.
  • Support agents receive instant, cited answer recommendations inside the composer with 100% data privacy.
⁠3. Service Management & SLAs
  • Multi-Metric SLA Engine: Track First Response, Next Response, and Full Resolution deadlines independently.
  • Operational business hours calendars, timezone offsets, holiday schedules, and auto-pause on customer-waiting states.
  • Automated condition-based routing rules and skill-based ticket assignment.
  • Time tracking, billable hours auditing, collision detection, and reply locks.
⁠4. Sandboxed WebAssembly Plugins (WASM)
  • Extend ticket sidebars and trigger automated workflows with sandboxed WASM plugins.
  • Built-in connectors for Jira, GitHub Issues, Linear, Trello, Asana, Redmine, HubSpot, Zabbix, WooCommerce, and Shopify.
⁠5. Config-as-Code CLI (salamandrctl)
  • Manage SLAs, teams, routing rules, canned responses, and webhooks declaratively from JSON files via CI/CD using system4us/salamandrctl⁠.

⁠🏷 Container Images & Architectures

ImageDescriptionArchitectures
system4us/salamandr-backendGo REST API + embedded React Web UI (Port 8080)linux/amd64, linux/arm64
system4us/salamandr-workerBackground task daemon (IMAP polling, SLA timers, webhooks)linux/amd64, linux/arm64
system4us/salamandrctlConfig-as-code administration CLI toollinux/amd64, linux/arm64

⁠🛡 Zero Telemetry Guarantee

Salamandr contains zero tracking pixels, zero analytics beacons, and zero phone-home mechanisms. Your database, conversations, and customer data remain 100% under your custody.


Tag summary

Content type

Image

Digest

sha256:d049bf148…

Size

123.2 MB

Last updated

26 days ago

docker pull system4us/salamandr-backend