Self-hosted support ticket & helpdesk system. Fast, private Zendesk alternative in Go & Postgres.
959
The modern, privacy-first, self-hosted omnichannel customer support platform you actually own.
Salamandr is a high-performance open-source alternative to Zendesk, Freshdesk, Intercom, and osTicket. It combines a high-throughput Go (Golang) backend, PostgreSQL (with pgvector & Row-Level Security), Redis, and an embedded React web interface in a single container.
| Capability | Salamandr | Legacy SaaS Helpdesks |
|---|---|---|
| Data Custody & Privacy | 100% On-Premises / Self-Hosted (GDPR, HIPAA, SOC 2 compliant) | Hosted on third-party multi-tenant clouds |
| Pricing & Seat Economy | Predictable self-hosted fleet licensing — No per-seat penalty | Expensive per-agent per-month recurring seats |
| Telemetry & Tracking | Zero Telemetry Guarantee — Nothing phones home, air-gap ready | Mandatory telemetry, tracking pixels, and diagnostics |
| Local AI & Document RAG | Air-Gapped Ollama + pgvector (No third-party LLM data leaks) | Cloud APIs training on your customer tickets |
| Architecture | Single-binary Web + API in Go (sub-millisecond routing, low RAM) | Heavy legacy monoliths or bloated microservices |
| Omnichannel Core | Email (IMAP/SMTP), WhatsApp Cloud API, Live Chat, Slack, Discord | Paywalled add-ons per channel |
Get a production-grade Salamandr helpdesk running in under 2 minutes:
# docker-compose.yml
services:
backend:
image: system4us/salamandr-backend:community
restart: unless-stopped
ports:
- "8080:8080"
environment:
- APP_DOMAIN=helpdesk.example.com
- FRONTEND_URL=http://localhost:8080
- BACKEND_URL=http://localhost:8080
- DATABASE_URL=postgres://salamandr_app:AppSecretPass123!@postgres:5432/salamandr?sslmode=disable
- MIGRATIONS_DATABASE_URL=postgres://salamandr:AdminSecretPass123!@postgres:5432/salamandr?sslmode=disable
- REDIS_URL=redis://:RedisSecretPass123!@redis:6379/0
- SESSION_SECRET=0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef
- ENCRYPTION_KEY=dGhpcy1pcy1hLXNhbXBsZS1lbmNyeXB0aW9uLWtleS0zMndheXM=
- [email protected]
- ADMIN_PASSWORD=ChangeThisAdminPassword123!
volumes:
- attachments_data:/data/attachments
depends_on:
postgres:
condition: service_healthy
redis:
condition: service_healthy
worker:
image: system4us/salamandr-worker:community
restart: unless-stopped
environment:
- DATABASE_URL=postgres://salamandr_app:AppSecretPass123!@postgres:5432/salamandr?sslmode=disable
- MIGRATIONS_DATABASE_URL=postgres://salamandr:AdminSecretPass123!@postgres:5432/salamandr?sslmode=disable
- REDIS_URL=redis://:RedisSecretPass123!@redis:6379/0
- ENCRYPTION_KEY=dGhpcy1pcy1hLXNhbXBsZS1lbmNyeXB0aW9uLWtleS0zMndheXM=
volumes:
- attachments_data:/data/attachments
depends_on:
- backend
postgres:
image: pgvector/pgvector:pg16
restart: unless-stopped
environment:
POSTGRES_DB: salamandr
POSTGRES_USER: salamandr
POSTGRES_PASSWORD: AdminSecretPass123!
APP_DB_PASSWORD: AppSecretPass123!
volumes:
- postgres_data:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U salamandr -d salamandr"]
interval: 5s
timeout: 5s
retries: 5
redis:
image: redis:7-alpine
restart: unless-stopped
command: exec redis-server --appendonly yes --requirepass RedisSecretPass123!
volumes:
- redis_data:/data
healthcheck:
test: ["CMD", "redis-cli", "-a", "RedisSecretPass123!", "ping"]
interval: 5s
timeout: 5s
retries: 5
volumes:
attachments_data:
postgres_data:
redis_data:
docker compose up -d
docker compose logs -f backend
Open http://localhost:8080 in your browser and sign in with [email protected] / ChangeThisAdminPassword123!.
| Variable | Description | Required | Default |
|---|---|---|---|
APP_DOMAIN | The public domain name of your instance (e.g. helpdesk.example.com). | Yes | localhost |
FRONTEND_URL | Public origin allowed to call the API and base for all links in outbound emails. | Yes | http://localhost:8080 |
BACKEND_URL | Public base URL used for OAuth callbacks and redirects. | Yes | http://localhost:8080 |
DATABASE_URL | Connection string for the unprivileged application role (salamandr_app). | Yes | - |
MIGRATIONS_DATABASE_URL | Connection string with owner privileges to apply database schema migrations. | Yes | - |
REDIS_URL | Redis connection URL for sessions, rate-limit windows, and verification tokens. | Yes | redis://redis:6379/0 |
SESSION_SECRET | 64-character hex string used to sign session cookies securely. | Yes | - |
ENCRYPTION_KEY | 32-byte Base64 key to encrypt stored email passwords, OAuth tokens, and secrets. | Yes | - |
ADMIN_EMAIL | Default administrator account created on first startup. | Yes | [email protected] |
ADMIN_PASSWORD | Initial administrator password (change in UI after login). | Yes | - |
ATTACHMENTS_DIR | Local directory for file uploads when S3 storage is disabled. | No | /data/attachments |
S3_BUCKET | S3/R2/B2/MinIO bucket name for scalable object storage. | No | "" |
OLLAMA_HOST | URL to your local Ollama instance for on-premise AI assistance. | No | "" |
TRUSTED_PROXY_CIDRS | CIDR blocks of upstream reverse proxies (e.g. 172.16.0.0/12). | Conditional | "" |
bge-m3 embeddings + qwen2.5-coder / gemma2).pgvector.salamandrctl)system4us/salamandrctl.| Image | Description | Architectures |
|---|---|---|
system4us/salamandr-backend | Go REST API + embedded React Web UI (Port 8080) | linux/amd64, linux/arm64 |
system4us/salamandr-worker | Background task daemon (IMAP polling, SLA timers, webhooks) | linux/amd64, linux/arm64 |
system4us/salamandrctl | Config-as-code administration CLI tool | linux/amd64, linux/arm64 |
Salamandr contains zero tracking pixels, zero analytics beacons, and zero phone-home mechanisms. Your database, conversations, and customer data remain 100% under your custody.
Content type
Image
Digest
sha256:d049bf148…
Size
123.2 MB
Last updated
26 days ago
docker pull system4us/salamandr-backend