Packages
postvec-server is published with every release as a .deb / .rpm, one per distribution and architecture (no PostgreSQL major). Verify the files as described on the packages page, then:
sudo apt install \
./postvec-server_0.5.0-2+deb12_amd64.deb \
./postvec-cli_0.5.0-2+deb12_amd64.deb \
./postvec-onnxruntime_*.deb \
./postvec-model-minilm-l6-v2_*.deb \
./postvec-extras_*.deb
sudo install -o root -g postvec-server -m 0644 server.crt /etc/postvec-server/server.crt
sudo install -o root -g postvec-server -m 0640 server.key /etc/postvec-server/server.key
sudo systemctl enable --now postvec-server
postvec-server statusThe package installs the binary, the systemd unit, a conffile at /etc/postvec-server/config.json, the dashboard under /opt/postvec/server/ui and the postvec-server service account. postvec-cli is a Recommends of the server package (for postvec model pull); it is listed explicitly because an install from local files cannot fetch a recommended package by itself.
Files
The packaged unit reads /opt/postvec, where these packages install and where postvec model pull writes:
| Artifact | Installs |
|---|---|
postvec-onnxruntime | libonnxruntime.so under /opt/postvec/libs |
postvec-model-minilm-l6-v2 | The bundled 384-d model under /opt/postvec/models |
postvec-extras | Pins the two above |
postvec-cli | /usr/bin/postvec, for model and provider commands |
| dashboard | /opt/postvec/server/ui, served on 22222 and the loopback admin port |
TLS
The discovery listener requires TLS: without --insecure and without a readable certificate pair, the process exits at start. Self-signed certificates are accepted, and the trust boundary is the network.
postvec-server \
--root /opt/postvec \
--ssl-cert /etc/postvec-server/server.crt \
--ssl-cert-key /etc/postvec-server/server.keyThe packaged configuration names /etc/postvec-server/server.crt and server.key, installed root:postvec-server, the key 0640. The package's post-install message prints the two install lines.
Start the unit
The package installs the unit from postvec-server/systemd/, which sets POSTVEC_PATH=/opt/postvec, plus a drop-in that hands /opt/postvec/models to the service account so the node can activate and deactivate models. The unit runs unprivileged under a strict sandbox:
sudo systemctl enable --now postvec-server
journalctl -u postvec-server -fBoot log
postvec-server <version> (onnx)
engine root: /opt/postvec
configuration file: /etc/postvec-server/config.json
advertising 10.0.0.10
gRPC address: 10.0.0.10:33333
HTTP address: https://10.0.0.10:22222
1 model root(s) resolve to 1 resident model(s) (ceiling 16)
loaded model "sentence-transformers-all-minilm-l6-v2"
warming up 1 model(s)
gRPC listening on 0.0.0.0:33333 (plaintext, unauthenticated - private networks only)
discovery listening on https://0.0.0.0:22222
admin listening on http://127.0.0.1:22223 (loopback only)
serving: 1 model(s) ready, ...Check these two lines:
advertising ...If a warning says the address was autodetected and the host has more than one interface, pin it with--advertise.configuration file: ...The file that was actually read.
Sockets are reserved before models load, so a port conflict fails immediately. Between reservation and serving the ports are open but silent: a healthcheck waits while the process is still starting.
Optional
postvec-server status
curl -sk https://127.0.0.1:22222/readystatus prints the version and build features, readiness, the frontend address, the models and the cluster members. /ready is 200 once a model can serve, 503 before that.
License
postvec-server is Business Source License 1.1 (source-available). Personal production use, non-production environments and a 30-day production evaluation per organization are free. Production use by an organization needs postvec pro. License.
Next: connect PostgreSQL. The dashboard is https://<host>:22222.