Skip to content

Packages ​

postvec-server is published with every release as a .deb / .rpm, one per distribution and architecture (no PostgreSQL major). Verify the files as described on the packages page, then:

sudo apt install \
  ./postvec-server_0.5.0-2+deb12_amd64.deb \
  ./postvec-cli_0.5.0-2+deb12_amd64.deb \
  ./postvec-onnxruntime_*.deb \
  ./postvec-model-minilm-l6-v2_*.deb \
  ./postvec-extras_*.deb

sudo install -o root -g postvec-server -m 0644 server.crt /etc/postvec-server/server.crt
sudo install -o root -g postvec-server -m 0640 server.key /etc/postvec-server/server.key
sudo systemctl enable --now postvec-server
postvec-server status

The package installs the binary, the systemd unit, a conffile at /etc/postvec-server/config.json, the dashboard under /opt/postvec/server/ui and the postvec-server service account. postvec-cli is a Recommends of the server package (for postvec model pull); it is listed explicitly because an install from local files cannot fetch a recommended package by itself.

Files ​

The packaged unit reads /opt/postvec, where these packages install and where postvec model pull writes:

ArtifactInstalls
postvec-onnxruntimelibonnxruntime.so under /opt/postvec/libs
postvec-model-minilm-l6-v2The bundled 384-d model under /opt/postvec/models
postvec-extrasPins the two above
postvec-cli/usr/bin/postvec, for model and provider commands
dashboard/opt/postvec/server/ui, served on 22222 and the loopback admin port

TLS ​

The discovery listener requires TLS: without --insecure and without a readable certificate pair, the process exits at start. Self-signed certificates are accepted, and the trust boundary is the network.

bash
postvec-server \
  --root /opt/postvec \
  --ssl-cert /etc/postvec-server/server.crt \
  --ssl-cert-key /etc/postvec-server/server.key

The packaged configuration names /etc/postvec-server/server.crt and server.key, installed root:postvec-server, the key 0640. The package's post-install message prints the two install lines.

Start the unit ​

The package installs the unit from postvec-server/systemd/, which sets POSTVEC_PATH=/opt/postvec, plus a drop-in that hands /opt/postvec/models to the service account so the node can activate and deactivate models. The unit runs unprivileged under a strict sandbox:

bash
sudo systemctl enable --now postvec-server
journalctl -u postvec-server -f

Boot log ​

text
postvec-server <version> (onnx)
engine root: /opt/postvec
configuration file: /etc/postvec-server/config.json
advertising 10.0.0.10
gRPC address: 10.0.0.10:33333
HTTP address: https://10.0.0.10:22222
1 model root(s) resolve to 1 resident model(s) (ceiling 16)
loaded model "sentence-transformers-all-minilm-l6-v2"
warming up 1 model(s)
gRPC listening on 0.0.0.0:33333 (plaintext, unauthenticated - private networks only)
discovery listening on https://0.0.0.0:22222
admin listening on http://127.0.0.1:22223 (loopback only)
serving: 1 model(s) ready, ...

Check these two lines:

  • advertising ... If a warning says the address was autodetected and the host has more than one interface, pin it with --advertise.
  • configuration file: ... The file that was actually read.

Sockets are reserved before models load, so a port conflict fails immediately. Between reservation and serving the ports are open but silent: a healthcheck waits while the process is still starting.

Optional

bash
postvec-server status
curl -sk https://127.0.0.1:22222/ready

status prints the version and build features, readiness, the frontend address, the models and the cluster members. /ready is 200 once a model can serve, 503 before that.

License

postvec-server is Business Source License 1.1 (source-available). Personal production use, non-production environments and a 30-day production evaluation per organization are free. Production use by an organization needs postvec pro. License.

Next: connect PostgreSQL. The dashboard is https://<host>:22222.