Self-hosting Langfuse v2 - Langfuse
We value your privacy
We use cookies to enhance your browsing experience, serve personalised ads or content, and analyse our traffic. By clicking "Accept All", you consent to our use of cookies.
CustomiseReject AllAccept All
Customise Consent Preferences
We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.
The cookies that are categorised as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... Show more
NecessaryAlways Active
Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.
- Cookie
__Secure-next-auth.csrf-token.EU
- Duration
session
- Description
Description is currently not available.
- Cookie
__Secure-next-auth.callback-url.EU
- Duration
session
- Description
Description is currently not available.
- Cookie
__Secure-next-auth.csrf-token.US
- Duration
session
- Description
Description is currently not available.
- Cookie
__Secure-next-auth.callback-url.US
- Duration
session
- Description
Description is currently not available.
- Cookie
__cf_bm
- Duration
1 hour
- Description
This cookie, set by Cloudflare, is used to support Cloudflare Bot Management.
- Cookie
__hssrc
- Duration
session
- Description
This cookie is set by Hubspot whenever it changes the session cookie. The __hssrc cookie set to 1 indicates that the user has restarted the browser, and if the cookie does not exist, it is assumed to be a new session.
- Cookie
__hssc
- Duration
1 hour
- Description
HubSpot sets this cookie to keep track of sessions and to determine if HubSpot should increment the session number and timestamps in the __hstc cookie.
- Cookie
__Secure-next-auth.csrf-token.HIPAA
- Duration
session
- Description
Description is currently not available.
- Cookie
__Secure-next-auth.callback-url.HIPAA
- Duration
session
- Description
Description is currently not available.
- Cookie
__Secure-next-auth.csrf-token.JP
- Duration
session
- Description
Description is currently not available.
- Cookie
__Secure-next-auth.callback-url.JP
- Duration
session
- Description
Description is currently not available.
- Cookie
theme
- Duration
Never Expires
- Description
No description available.
- Cookie
cookietest
- Duration
session
- Description
The cookietest cookie is typically used to determine whether the user's browser accepts cookies, essential for website functionality and user experience.
- Cookie
cookieyes-*
- Duration
1 year
- Description
CookieYes sets this cookie for consent solution management.
Functional
Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.
- Cookie
inkeepUsagePreferences_userId
- Duration
1 year
- Description
Description is currently not available.
- Cookie
_octo
- Duration
1 year
- Description
No description available.
- Cookie
logged_in
- Duration
1 year
- Description
No description available.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.
- Cookie
ph_phc_zkMwFajk8ehObUlMth0D7DtPItFnxETi3lmSvyQDrwB_posthog
- Duration
1 year
- Description
Description is currently not available.
- Cookie
__hstc
- Duration
6 months
- Description
Hubspot set this main cookie for tracking visitors. It contains the domain, initial timestamp (first visit), last timestamp (last visit), current timestamp (this visit), and session number (increments for each subsequent session).
- Cookie
hubspotutk
- Duration
6 months
- Description
HubSpot sets this cookie to keep track of the visitors to the website. This cookie is passed to HubSpot on form submission and used when deduplicating contacts.
- Cookie
_gh_sess
- Duration
session
- Description
GitHub sets this cookie for temporary application and framework state between pages like what step the user is on in a multiple step form.
- Cookie
signals-sdk-user-id
- Duration
1 year
- Description
Description is currently not available.
- Cookie
signals-sdk-session-id
- Duration
1 hour
- Description
Description is currently not available.
Performance
Performance cookies are used to understand and analyse the key performance indexes of the website which helps in delivering a better user experience for the visitors.
No cookies to display.
Advertisement
Advertisement cookies are used to provide visitors with customised advertisements based on the pages you visited previously and to analyse the effectiveness of the ad campaigns.
No cookies to display.
Uncategorised
Other uncategorised cookies are those that are being analysed and have not been classified into a category as yet.
No cookies to display.
Reject AllSave My PreferencesAccept All
Self HostingDeployment Guide
Self Hosting Legacy Docs (v2) Deployment Guide
Version: v2
Copy page
Deployment Guide (v2)
This guide covers Langfuse v2. For Langfuse v3, see the v3\ documentation. Langfuse v2 receives security updates until end of Q1 2025. If you have any questions while upgrading, please refer to the v3 upgrade guide or open a thread on GitHub Discussions.
Langfuse Server, which includes the API and Web UI, is open-source and can be self-hosted using Docker.
For a detailed component and architecture diagram, refer to CONTRIBUTING.md.
Looking for a managed solution? Consider Langfuse\ Cloud maintained by the Langfuse team.
Prerequisites: Postgres Database
Langfuse requires a persistent Postgres database to store its state. You can use a managed service on AWS, Azure, or GCP, or host it yourself. Once the database is ready, keep the connection string handy. At least version 12 is required.
Deploying the Application
Deploy the application container to your infrastructure. You can use managed services like AWS ECS, Azure Container Instances, or GCP Cloud Run, or host it yourself.
During the container startup, all database migrations will be applied automatically. This can be optionally disabled via environment variables.
docker pull langfuse/langfuse:2
docker run --name langfuse \
-e DATABASE_URL=postgresql://hello \
-e NEXTAUTH_URL=http://localhost:3000 \
-e NEXTAUTH_SECRET=mysecret \
-e SALT=mysalt \
-e ENCRYPTION_KEY=0000000000000000000000000000000000000000000000000000000000000000 \ # generate via: openssl rand -hex 32
-p 3000:3000 \
-a STDOUT \
langfuse/langfuse
We follow semantic versioning for Langfuse releases, i.e. breaking changes are only introduced in a new major version.
- We recommend automated updates within a major version to benefit from the latest features, bug fixes, and security patches (
docker pull langfuse/langfuse:2). - Subscribe to our mailing list to get notified about new releases and new major versions.
Subscribe
Recommended Instance Size
For production environments, we suggest using a configuration of 2 CPU cores and 3 GB of RAM for the Langfuse container. On AWS, this would equate to a t3.medium instance. The container is stateless, allowing you to autoscale it based on actual resource usage.
Configuring Environment Variables
Langfuse can be configured using environment variables ( .env.prod.example). Some are mandatory as defined in the table below:
| Variable | Required / Default | Description |
|---|---|---|
DATABASE_URL |
Required | Connection string of your Postgres database. Instead of DATABASE_URL, you can also use DATABASE_HOST, DATABASE_USERNAME, DATABASE_PASSWORD and DATABASE_NAME. |
DIRECT_URL |
DATABASE_URL |
Connection string of your Postgres database used for database migrations. Use this if you want to use a different user for migrations or use connection pooling on DATABASE_URL. For large deployments, configure the database user with long timeouts as migrations might need a while to complete. |
SHADOW_DATABASE_URL |
If your database user lacks the CREATE DATABASE permission, you must create a shadow database and configure the "SHADOW_DATABASE_URL". This is often the case if you use a Cloud database. Refer to the Prisma docs for detailed instructions. |
|
NEXTAUTH_URL |
Required | URL of your deployment, e.g. https://yourdomain.com or http://localhost:3000. Required for successful authentication via OAUTH. |
NEXTAUTH_SECRET |
Required | Used to validate login session cookies, generate secret with at least 256 entropy using openssl rand -base64 32. |
SALT |
Required | Used to salt hashed API keys, generate secret with at least 256 entropy using openssl rand -base64 32. |
ENCRYPTION_KEY |
Required | Used to encrypt sensitive data. Must be 256 bits, 64 string characters in hex format, generate via: openssl rand -hex 32. |
LANGFUSE_CSP_ENFORCE_HTTPS |
false |
Set to true to set CSP headers to only allow HTTPS connections. |
PORT |
3000 |
Port the server listens on. |
HOSTNAME |
localhost |
In some environments it needs to be set to 0.0.0.0 to be accessible from outside the container (e.g. Google Cloud Run). |
LANGFUSE_DEFAULT_ORG_ID |
Configure optional default organization for new users. When users create an account they will be automatically added to this organization. | |
LANGFUSE_DEFAULT_ORG_ROLE |
VIEWER |
Role of the user in the default organization (if set). Possible values are OWNER, ADMIN, MEMBER, VIEWER. See roles for details. |
LANGFUSE_DEFAULT_PROJECT_ID |
Configure optional default project for new users. When users create an account they will be automatically added to this project. | |
LANGFUSE_DEFAULT_PROJECT_ROLE |
VIEWER |
Role of the user in the default project (if set). Possible values are OWNER, ADMIN, MEMBER, VIEWER. See roles for details. |
SMTP_CONNECTION_URL |
Configure optional SMTP server connection for transactional email. Connection URL is passed to Nodemailer ( docs). | |
EMAIL_FROM_ADDRESS |
Configure from address for transactional email. Required if SMTP_CONNECTION_URL is set. |
|
S3_ENDPOINTS3_ACCESS_KEY_IDS3_SECRET_ACCESS_KEYS3_BUCKET_NAMES3_REGION |
Optional S3 configuration for enabling large exports from the UI. S3_BUCKET_NAME is required to enable exports. The other variables are optional and will use the default provider credential chain if not specified. |
|
LANGFUSE_S3_MEDIA_UPLOAD_ENABLEDLANGFUSE_S3_MEDIA_UPLOAD_BUCKETLANGFUSE_S3_MEDIA_UPLOAD_REGIONLANGFUSE_S3_MEDIA_UPLOAD_ACCESS_KEY_IDLANGFUSE_S3_MEDIA_UPLOAD_SECRET_ACCESS_KEYLANGFUSE_S3_MEDIA_UPLOAD_ENDPOINTLANGFUSE_S3_MEDIA_UPLOAD_FORCE_PATH_STYLELANGFUSE_S3_MEDIA_UPLOAD_PREFIXLANGFUSE_S3_MEDIA_MAX_CONTENT_LENGTHLANGFUSE_S3_MEDIA_DOWNLOAD_URL_EXPIRY_SECONDS |
false<br><br><br>`` 1_000_000_0003600 |
S3 configuration for enabling multi-modal attachments. All variables are optional and will use the default values shown if not specified. Set LANGFUSE_S3_MEDIA_UPLOAD_ENABLED=true to enable multi-modal attachments. Configured storage bucket must have a publicly resolvable hostname to support direct uploads via our SDKs and media asset fetching directly from the browser. |
DB_EXPORT_PAGE_SIZE |
1000 |
Optional page size for streaming exports to S3 to avoid memory issues. The page size can be adjusted if needed to optimize performance. |
LANGFUSE_AUTO_POSTGRES_MIGRATION_DISABLED |
false |
Set to true to disable automatic database migrations on docker startup. |
LANGFUSE_LOG_LEVEL |
info |
Set the log level for the application. Possible values are trace, debug, info, warn, error, fatal. |
LANGFUSE_LOG_FORMAT |
text |
Set the log format for the application. Possible values are text, json. |
NEXT_PUBLIC_BASE_PATH |
Set the base path for the application. This is useful if you want to deploy Langfuse on a subpath, especially when integrating Langfuse into existing infrastructure. Refer to the section below for details. |
Authentication
Email/Password
Email/password authentication is enabled by default. Users can sign up and log in using their email and password.
To disable email/password authentication, set AUTH_DISABLE_USERNAME_PASSWORD=true. In this case, you need to set up SSO instead.
If you want to provision a default user for your Langfuse instance, you can use the LANGFUSE_INIT_* environment variables.
Password Reset
If transactional emails are configured on your instance via the
SMTP_CONNECTION_URLandEMAIL_FROM_ADDRESSenvironments, users can reset their password by using the "Forgot password" link on the login page.If transactional emails are not set up, passwords can be reset by following these steps:
- Update the email associated with your user account in database, such as by adding a prefix.
- You can then sign up again with a new password.
- Reassign any organizations you were associated with via the
organization_membershipstable in database. - Finally, remove the old user account from the
userstable in database.
SSO
To enable OAuth/SSO provider sign-in for Langfuse, add the following environment variables:
| Provider | Variables | OAuth Redirect URL |
|---|---|---|
AUTH_GOOGLE_CLIENT_IDAUTH_GOOGLE_CLIENT_SECRETAUTH_GOOGLE_ALLOW_ACCOUNT_LINKING=true (optional)AUTH_GOOGLE_ALLOWED_DOMAINS=langfuse.com,google.com(optional, list of allowed domains based on hd OAuth claim) |
/api/auth/callback/google |
|
| GitHub | AUTH_GITHUB_CLIENT_IDAUTH_GITHUB_CLIENT_SECRETAUTH_GITHUB_ALLOW_ACCOUNT_LINKING=true (optional) |
/api/auth/callback/github |
| GitHub Enterprise | AUTH_GITHUB_ENTERPRISE_CLIENT_IDAUTH_GITHUB_ENTERPRISE_CLIENT_SECRETAUTH_GITHUB_ENTERPRISE_BASE_URLAUTH_GITHUB_ENTERPRISE_ALLOW_ACCOUNT_LINKING=false (optional) |
/api/auth/callback/github-enterprise |
| GitLab | AUTH_GITLAB_CLIENT_IDAUTH_GITLAB_CLIENT_SECRETAUTH_GITLAB_ISSUER (optional)AUTH_GITLAB_ALLOW_ACCOUNT_LINKING=true (optional) |
/api/auth/callback/gitlab |
| AzureAD/Entra ID | AUTH_AZURE_AD_CLIENT_IDAUTH_AZURE_AD_CLIENT_SECRETAUTH_AZURE_AD_TENANT_IDAUTH_AZURE_ALLOW_ACCOUNT_LINKING=true (optional) |
/api/auth/callback/azure-ad |
| Okta | AUTH_OKTA_CLIENT_IDAUTH_OKTA_CLIENT_SECRETAUTH_OKTA_ISSUERAUTH_OKTA_ALLOW_ACCOUNT_LINKING=true (optional) |
/api/auth/callback/okta |
| OneLogin | AUTH_ONELOGIN_CLIENT_IDAUTH_ONELOGIN_CLIENT_SECRETAUTH_ONELOGIN_ISSUERAUTH_ONELOGIN_ALLOW_ACCOUNT_LINKING=true (optional) |
/api/auth/callback/onelogin |
| Auth0 | AUTH_AUTH0_CLIENT_IDAUTH_AUTH0_CLIENT_SECRETAUTH_AUTH0_ISSUERAUTH_AUTH0_ALLOW_ACCOUNT_LINKING=true (optional) |
/api/auth/callback/auth0 |
| AWS Cognito | AUTH_COGNITO_CLIENT_IDAUTH_COGNITO_CLIENT_SECRETAUTH_COGNITO_ISSUERAUTH_COGNITO_ALLOW_ACCOUNT_LINKING=true (optional) |
/api/auth/callback/cognito |
| Keycloak | AUTH_KEYCLOAK_CLIENT_IDAUTH_KEYCLOAK_CLIENT_SECRETAUTH_KEYCLOAK_ISSUERAUTH_KEYCLOAK_ALLOW_ACCOUNT_LINKING=true (optional) |
/api/auth/callback/keycloak |
| Custom OAuth ( source) | AUTH_CUSTOM_CLIENT_IDAUTH_CUSTOM_CLIENT_SECRETAUTH_CUSTOM_ISSUERAUTH_CUSTOM_NAME (any, used only in UI)AUTH_CUSTOM_ALLOW_ACCOUNT_LINKING=true (optional)AUTH_CUSTOM_SCOPE (optional, defaults to "openid email profile") |
/api/auth/callback/custom |
Use *_ALLOW_ACCOUNT_LINKING to allow merging accounts with the same email address. This is useful when users sign in with different providers or email/password but have the same email address. You need to be careful with this setting as it can lead to security issues if the emails are not verified.
Need another provider? Langfuse uses Auth.js, which integrates with many providers. Add a feature request on GitHub if you want us to add support for a specific provider.
Additional configuration
| Variable | Description |
|---|---|
AUTH_DOMAINS_WITH_SSO_ENFORCEMENT |
Comma-separated list of domains that are only allowed to sign in using SSO. Email/password sign in is disabled for these domains. E.g. domain1.com,domain2.com |
AUTH_DISABLE_SIGNUP |
Set to true to disable sign up for new users. Only existing users can sign in. This affects all new users that try to sign up, also those who received an invite to a project and have no account yet. |
AUTH_SESSION_MAX_AGE |
Set the maximum age of the session (JWT) in minutes. The default is 30 days (43200). The value must be greater than 5 minutes, as the front-end application refreshes its session every 5 minutes. |
Headless Initialization
By default, you need to create a user account, organization and project via the Langfuse UI before being able to use the API. You can find the API keys in the project settings within the UI.
If you want to automatically initialize these resources, you can optionally use the following LANGFUSE_INIT_* environment variables. When these variables are set, Langfuse will automatically create the specified resources on startup if they don't already exist. This allows for easy integration with infrastructure-as-code and automated deployment pipelines.
| Environment Variable | Description | Required to Create Resource | Example |
|---|---|---|---|
LANGFUSE_INIT_ORG_ID |
Unique identifier for the organization | Yes | my-org |
LANGFUSE_INIT_ORG_NAME |
Name of the organization | No | My Org |
LANGFUSE_INIT_PROJECT_ID |
Unique identifier for the project | Yes | my-project |
LANGFUSE_INIT_PROJECT_NAME |
Name of the project | No | My Project |
LANGFUSE_INIT_PROJECT_PUBLIC_KEY |
Public API key for the project | Yes | lf_pk_1234567890 |
LANGFUSE_INIT_PROJECT_SECRET_KEY |
Secret API key for the project | Yes | lf_sk_1234567890 |
LANGFUSE_INIT_USER_EMAIL |
Email address of the initial user | Yes | user@example.com |
LANGFUSE_INIT_USER_NAME |
Name of the initial user | No | John Doe |
LANGFUSE_INIT_USER_PASSWORD |
Password for the initial user | Yes | password123 |
The different resources depend on each other in the following way. You can e.g. initialize an organization and a user without having to also initialize a project and API keys, but you cannot initialize a project without also initializing an organization.
Organization
├── Project (part of organization)
│ └── API Keys (set for project)
└── User (owner of organization)
Troubleshooting:
- If you use
LANGFUSE_INIT_*in Docker Compose, do not double-quote the values ( GitHub issue). - The resources depend on one another (see note above). For example, you must create an organization to initialize a project.
Configuring the Enterprise Edition
The Enterprise Edition ( compare versions) of Langfuse includes additional optional configuration options that can be set via environment variables.
| Variable | Description |
|---|---|
LANGFUSE_ALLOWED_ORGANIZATION_CREATORS |
Comma-separated list of allowlisted users that can create new organizations. By default, all users can create organizations. E.g. user1@langfuse.com,user2@langfuse.com. |
LANGFUSE_UI_API_HOST |
Customize the hostname that is referenced in the settings. Defaults to window.origin. |
LANGFUSE_UI_DOCUMENTATION_HREF |
Customize the documentation link reference in the menu and settings. |
LANGFUSE_UI_SUPPORT_HREF |
Customize the support link reference in the menu and settings. |
LANGFUSE_UI_FEEDBACK_HREF |
Replace the default feedback widget with your own feedback link. |
LANGFUSE_UI_LOGO_DARK_MODE_HREFLANGFUSE_UI_LOGO_LIGHT_MODE_HREF |
Co-brand the Langfuse interface with your own logo. Langfuse adapts to the logo width, with a maximum aspect ratio of 1:3. Narrower ratios (e.g., 2:3, 1:1) also work. The logo is fitted into a bounding box, so there are no specific pixel constraints. For reference, the example logo is 160px x 400px. |
LANGFUSE_UI_DEFAULT_MODEL_ADAPTER |
Set the default model adapter for the LLM playground and evals. Options: OpenAI, Anthropic, Azure. Example: Anthropic |
LANGFUSE_UI_DEFAULT_BASE_URL_OPENAI |
Set the default base URL for OpenAI API in the LLM playground and evals. Example: https://api.openai.com/v1 |
LANGFUSE_UI_DEFAULT_BASE_URL_ANTHROPIC |
Set the default base URL for Anthropic API in the LLM playground and evals. Example: https://api.anthropic.com |
LANGFUSE_UI_DEFAULT_BASE_URL_AZURE_OPENAI |
Set the default base URL for Azure OpenAI API in the LLM playground and evals. Example: https://{instanceName}.openai.azure.com/openai/deployments |
Health and Readiness Check Endpoint
Langfuse includes a health check endpoint at /api/public/health and a readiness check endpoint at /api/public/ready.
The health check endpoint checks the API functionality and indicates if the application is alive.
The readiness check endpoint indicates if the application is ready to serve traffic.
Access the health and readiness check endpoints:
curl http://localhost:3000/api/public/health
curl http://localhost:3000/api/public/ready
The potential responses from the health check endpoint are:
200 OK: Both the API is functioning normally and a successful connection to the database was made.503 Service Unavailable: Either the API is not functioning or it couldn't establish a connection to the database.
The potential responses from the readiness check endpoint are:
200 OK: The application is ready to serve traffic.500 Internal Server Error: The application received a SIGTERM or SIGINT and should not receive traffic.
Applications and monitoring services can call this endpoint periodically for health updates.
Per default, the healthcheck endpoint does not validate if the database is reachable, as there are cases where the
database is unavailable, but the application still serves traffic.
If you want to run database healthchecks, you can add ?failIfDatabaseUnavailable=true to the healthcheck endpoint.
Encryption
Encryption in transit (HTTPS)
For encryption in transit, HTTPS is strongly recommended. Langfuse itself does not handle HTTPS directly. Instead, HTTPS is typically managed at the infrastructure level. There are two main approaches to handle HTTPS for Langfuse:
- Load Balancer Termination:
In this approach, HTTPS is terminated at the load balancer level. The load balancer handles the SSL/TLS certificates and encryption, then forwards the decrypted traffic to the Langfuse container over HTTP. This is a common and straightforward method, especially in cloud environments.
- Pros: Simplifies certificate management as it is usually a fully managed service (e.g. AWS ALB), offloads encryption overhead from application servers.
- Cons: Traffic between load balancer and Langfuse container is unencrypted (though typically within a secure network).
- Service Mesh Sidecar:
This method involves using a service mesh like Istio or Linkerd. A sidecar proxy is deployed alongside each Langfuse container, handling all network traffic including HTTPS.
- Pros: Provides end-to-end encryption (mutual TLS), offers advanced traffic management and observability.
- Cons: Adds complexity to the deployment, requires understanding of service mesh concepts.
Once HTTPS is enabled, you can configure add LANGFUSE_CSP_ENFORCE_HTTPS=true to ensure browser only allow HTTPS connections when using Langfuse.
Encryption at rest (database)
All Langfuse data is stored in your Postgres database. Database-level encryption is recommended for a secure production deployment and available across cloud providers.
The Langfuse team has implemented this for Langfuse Cloud and it is fully ISO27001, SOC2 Type 2, HIPAA, and GDPR compliant ( security center).
Additional application-level encryption
In addition to in-transit and at-rest encryption, sensitive data is also encrypted or hashed at the application level.
| Data | Encryption |
|---|---|
| API keys | Hashed using SALT |
| Langfuse Console JWTs | Encrypted via NEXTAUTH_SECRET |
| LLM API credentials stored in Langfuse | Encrypted using ENCRYPTION_KEY |
| Integration credentials (e.g. PostHog) | Encrypted using ENCRYPTION_KEY |
| Input/Outputs of LLM Calls, Traces, Spans | Work in progress, contact sales if you are interested in this |
Build Langfuse from source
While we recommend using the prebuilt docker image, you can also build the image yourself from source.
The repo includes multiple Dockerfile files. You only need to build the web Dockerfile as shown below.
# clone repo
git clone https://github.com/langfuse/langfuse.git
cd langfuse
# checkout v2 branch
# main branch includes unreleased changes that might be unstable
git checkout v2
# build image
docker build -t langfuse/langfuse -f ./web/Dockerfile .
Custom Base Path
If you want to deploy Langfuse behind a custom base path (e.g. https://yourdomain.com/langfuse), you can set the NEXT_PUBLIC_BASE_PATH environment variable. This is useful if you want to deploy Langfuse on a subpath, especially when integrating Langfuse into existing infrastructure.
As this base path is inlined in static assets, you cannot use the prebuilt docker image. You need to build the image from source with the NEXT_PUBLIC_BASE_PATH environment variable set at build time.
When using a custom base path, NEXTAUTH_URL must be set to the full URL including the base path and /api/auth. For example, if you are deploying Langfuse at https://yourdomain.com/langfuse-base-path, you need to set:
.env
NEXT_PUBLIC_BASE_PATH="/langfuse-base-path"
NEXTAUTH_URL="https://yourdomain.com/langfuse-base-path/api/auth"
Build image with NEXT_PUBLIC_BASE_PATH as build argument:
# clone repo
git clone https://github.com/langfuse/langfuse.git
cd langfuse
# checkout v2 branch
# main branch includes unreleased changes that might be unstable
git checkout v2
# build image with NEXT_PUBLIC_BASE_PATH
docker build -t langfuse/langfuse --build-arg NEXT_PUBLIC_BASE_PATH=/langfuse-base-path -f ./web/Dockerfile .
Once your Langfuse instance is running, you can access both the API and console through your configured custom base path. When connecting via SDKs, make sure to include the custom base path in the hostname.
Troubleshooting
If you encounter issues, ensure the following:
NEXTAUTH_URLexactly matches the URL you're accessing Langfuse with. Pay attention to the protocol (http vs https) and the port (e.g., 3000 if you do not expose Langfuse on port 80).- Set
HOSTNAMEto0.0.0.0if you cannot access Langfuse. - Encode special characters in
DATABASE_URL, see this StackOverflow answer for details. - If you use the SDKs to connect with Langfuse, use
auth_check()to verify that the connection works. - Make sure you are at least on Postgres 12.
- When using Docker Compose / Kubernetes, your application needs to connect to the Langfuse container at the docker internal network address that you specified, e.g.
http://langfuse:3000/http://langfuse.docker.internal:3000. Learn more: docker compose networking documentation, kubernetes networking documentation - SSO
- Ensure that the OAuth provider is configured correctly. The return path needs to match the
NEXTAUTH_URL, and the OAuth client needs to be configured with the correct callback URL. - Langfuse uses NextAuth.js. Please refer to the NextAuth.js documentation for more information.
- Ensure that the OAuth provider is configured correctly. The return path needs to match the
Updating the Application
We recommend enabling automated updates within the current major version to benefit from the latest features, bug fixes, and security patches.
Coming from Langfuse v1? Please refer to the upgrade\ guide for more details.
To update the application:
- Stop the container.
- Pull the latest container.
- Restart the application.
During container startup, any necessary database migrations will be applied automatically if the database schema has changed. This can be optionally disabled via environment variables.
Langfuse is released through tagged semver releases. Check GitHub releases for information about the changes in each version.
Watch the repository on GitHub to get notified about new releases
Kubernetes deployments
Kubernetes is a popular choice for deploying Langfuse when teams maintain the rest of their infrastructure using Kubernetes. You can find community-maintained templates and Helm Charts in the langfuse/langfuse-k8s repository.
If you encounter any bugs or have suggestions for improvements, please contribute to the repository by submitting issues or pull requests.
Platform-specific information
This section is work in progress and relies on community contributions. The Langfuse team/maintainers do not have the capacity to maintain or test this section. If you have successfully deployed Langfuse on a specific platform, consider contributing a guide either via a GitHub PR/Issue or by reaching\ out to the maintainers. Please also let us know if one of these guides does not work anymore or if you have a better solution.
Railway
Porter.run
If you use Porter to deploy your application, you can easily add a Langfuse instance to your cluster via the "Add-ons". The add-on will automatically configure the necessary environment variables, inject your database credentials, and deploy and autoscale the Langfuse container. Learn more about this in our changelog.
AWS
We recommend deploying Langfuse on AWS using the Elastic Container Service (ECS) and Fargate for a scalable and low-maintenance container deployment. Note: you can use AWS Cognito for SSO.
Have a look at this configuration template: aws-samples/deploy-langfuse-on-ecs-with-fargate
Azure
Deploy Langfuse to Azure using the Azure Container Instances service for a flexible and low-maintenance container deployment. Note: you can use Azure AD for SSO.
You can deploy Langfuse to Azure via the Azure Developer CLI using this template: Azure-Samples/langfuse-on-azure.
Google Cloud Platform (Cloud Run & Cloud SQL)
The simplest way to deploy Langfuse on Google Cloud Platform is to use Cloud Run for the containerized application and Cloud SQL for the database.
Option 1: UI Deployment
Create Cloud SQL Instance:
- Open Google Cloud SQL.
- Click on Create Instance.
- Choose PostgreSQL and configure the instance according to your requirements.
- You'll need the following details:
- default > user: postgres
- default > database schema: public
- setup > password:
<password> - connection > connection name:
<google-cloud-project-id>:<region-id>:<sql-instance-id>
Optionally: Create OAuth Credentials for sign-in with Google
- Open API Credentials
- Click "Create Credentials" and then "OAuth Client ID"
- Choose "Web Application" and then give it an appropriate name
- Click Create
Create Secrets:
- Open Secret Manager
- For each secret needed (at least
AUTH_GOOGLE_CLIENT_ID, AUTH_GOOGLE_CLIENT_SECRET, DATABASE_URL, DIRECT_URL, NEXTAUTH_SECRET, NEXTAUTH_URL,andSALT), click "Create Secret" and fill in the name and value.
Notes:
DATABASE_URLis the connection string to the Cloud SQL instance.postgresql://<user-name>:<password>@localhost/<db-name>/?host=/cloudsql/<google-cloud-project-id>:<region-id>:<sql-instance-id>&sslmode=none&pgbouncer=trueDIRECT_URLis for database migrations, without&pgbouncer=true, the value should look like this:postgresql://<user-name>:<password>@localhost/<db-name>/?host=/cloudsql/<google-cloud-project-id>:<region-id>:<sql-instance-id>&sslmode=none- Set
NEXTAUTH_URLtohttp://localhost:3000. This is a placeholder, we'll update it later.
Deploy on Cloud Run:
Open Google Cloud Run.
Click on Create Service.
Enter the following container image URL:
docker.io/langfuse/langfuse:2. We use tag2to pin the major version.Configure the service name and region according to your requirements.
Select authentication as 'Allow unauthenticated invocations', as Langfuse will have its own built-in Authentication that you can use.
Choose 'CPU Allocation and Pricing' as "CPU is only allocated during request processing" to scale down the instance to 0 when there are no requests.
Configure ingress control according to your needs. For most cases, 'All' should suffice.
"Container(s), Volumes, Networking & Security":
- Specify container port as
3000. - On "Variables & Secrets" tab, add the required environment variables (see table above):
SALT,NEXTAUTH_URL,NEXTAUTH_SECRET, andDATABASE_URL, etc.
- Specify container port as
Scroll all the way down to enable the Cloud SQL connections. Select the created Cloud SQL instance in the dropdown. Context: Your Cloud Run service won't be assigned a static IP, so you can't whitelist the ingress IP in Cloud SQL or any other hosted databases. Instead, we use the Google Cloud SQL Proxy.
Finally, you can finish deploying the application.
While the application is deployed for the first time, you can see how the database migrations are applied in the logs.
Once the application is up and running, you can find the Cloud Run service URL on top of the page. Now, choose "Edit and deploy new revision" to update the
NEXTAUTH_URLenvironment variable to the Cloud Run service URL ending in.run.app.Optionally, configure a custom domain for the Cloud Run service.
Troubleshooting: Cloud SQL Connection Issues
If you encounter an error like "Error 403: boss::NOT_AUTHORIZED: Not authorized to access resource" or "Possibly missing permission cloudsql.instances.connect" when deploying the Langfuse container, you may need to grant 'Cloud SQL Client' permissions to the relevant service accounts. Here's how to resolve this:
- In the Google Cloud search box, search for and select "Service Accounts".
- Find the service accounts with names ending in
@appspot.gserviceaccount.comand-compute@developer.gserviceaccount.com. - In the Google Cloud search box, search for and select "IAM & Admin".
- Click "Grant Access", then "Add Principals".
- Enter the name of the first service account you found.
- Select the "Cloud SQL Client" role and save.
- Repeat steps 4-6 for the second service account.
After granting these permissions, try redeploying your Cloud Run service. This should resolve any authorization issues related to connecting to your Cloud SQL instance.
Option 2: Cloud Build
Google Cloud Build is GCP's continuous integration and continuous deployment (CI/CD) service that automates the building, testing, and deployment of your applications. To deploy Langfuse, you can specify your workflow in a cloudbuild.yaml file. Additionally, GCP's Secret Manager can be used to securely handle sensitive information like DATABASE_URL and NEXTAUTH_SECRET. Below is an example of how to set up a Cloud Build configuration:
# Deployment configuration for Langfuse on Google Cloud Run
substitutions:
_SERVICE_NAME: langfuse
_REGION: europe-west1 # Change to your desired region
_PROJECT_ID: your-project-id # Change to your Google Cloud project ID
_SQL_INSTANCE_ID: my-cool-db # the name of the cloud sql database you create
tags: ["${_PROJECT_ID}", "${_SERVICE_NAME}"]
steps:
# Step to deploy the Docker image to Google Cloud Run
- name: "gcr.io/cloud-builders/gcloud"
id: deploy-cloud-run
entrypoint: bash
args:
- "-c"
- |
gcloud run deploy ${_SERVICE_NAME} --image docker.io/langfuse/langfuse:2 \
--region ${_REGION} \
--project ${_PROJECT_ID} \
--platform managed \
--port 3000 \
--allow-unauthenticated \
--memory 2Gi \
--cpu 1 \
--min-instances 0 \
--max-instances 3 \
--set-env-vars HOSTNAME=0.0.0.0 \
--add-cloudsql-instances=${_PROJECT_ID}:${_REGION}:${_SQL_INSTANCE_ID} \
--update-secrets AUTH_GOOGLE_CLIENT_ID=AUTH_GOOGLE_CLIENT_ID:latest,AUTH_GOOGLE_CLIENT_SECRET=AUTH_GOOGLE_CLIENT_SECRET:latest,SALT=SALT:latest,NEXTAUTH_URL=NEXTAUTH_URL:latest,NEXTAUTH_SECRET=NEXTAUTH_SECRET:latest,DATABASE_URL=DATABASE_URL:latest,DIRECT_URL=DIRECT_URL:latest
You can submit this build using gcloud build submit in your local console by issuing the below in the same folder as the cloudbuild.yaml file.
To submit this build, use the following command in your local console, in the directory containing the cloudbuild.yaml file:
gcloud builds submit .
For automatic rebuilds upon new commits, set up a Cloud Build Trigger linked to your repository holding the cloudbuild.yaml file. This will redeploy Langfuse whenever changes are pushed to the repository.
Note on AlloyDB
AlloyDB is a fully-managed postgres compatible database offered by Google Cloud Platform that is tuned for better performance for tasks such as analytical queries and in-database embeddings. It is recommend you use it within a Shared VPC with your Cloud Run runtime, which will expose AlloyDB's private ip address to your application. If you are using it the DB connection string changes slightly:
# ALLOYDB_CONNECTION_STRING
postgresql://<USER>:<PASSWORD>@<ALLOY_DB_PRIVATE_IP>:5432/<ALLOY_DB_DATABASE>/?sslmode=none&pgbouncer=true
# ALLOYDB_DIRECT_URL
postgresql://<USER>:<PASSWORD>@<ALLOY_DB_PRIVATE_IP>:5432/<ALLOY_DB_DATABASE>/?sslmode=none
Heroku
To deploy this image on heroku you have to run through the steps in the following deployment guide:
- Pull the docker image. This can be achieved by running the following command in your terminal:
docker pull langfuse/langfuse:2
- Get the ID of the pulled image
Linux / MacOS:
Running the following command should result in directly printing the image ID
docker images | grep langfuse/langfuse | awk '[print $3]'
Following this tutorial, you will always have to insert this image ID when [IMAGE_ID] is written.
Windows:
On windows you can print the full information of the pulled image using:
docker images | findstr /S "langfuse/langfuse"
This will result in something like:
langfuse/langfuse 2 cec90c920468 28 hours ago 595MB
Here you have to manually retrieve the image ID which in this case is cec90c920468. It should be located between the tag 2 and the created 28 hours ago in this example.
- Prepare your terminal and docker image
First of all, you will have to be logged in to heroku using
heroku login
If this is not working, please visit the heroku CLI setup.
If you succeeded in logging in to heroku via the CLI, you can continue by following the next steps:
Tag the docker image (Insert your image ID into the command). You will also have to insert the name of your heroku app/dyno into [HEROKU_APP_NAME]:
docker tag [IMAGE_ID] registry.heroku.com/[HEROKU_APP_NAME]/web
- Setup a database for your heroku app
In the dashboard of your heroku app, add the Heroku Postgres-AddOn. This will add a PostgreSQL database to your application.
- Set the environment variables
For the minimum deployment in heroku, you will have to set the following environment variables (see table above). The DATABASE_URL is your database connection string starting with postgres:// in the configuration of your added PostgreSQL database.
DATABASE_URL=
NEXTAUTH_SECRET=
NEXTAUTH_URL=
SALT=
Have a look at the other optional environment variables in the table above and set them if needed to configure your deployment.
- Push to heroku container registry
In this step you will push the docker image to the heroku container registry: (Insert the name of your heroku app/dyno)
docker push registry.heroku.com/[HEROKU_APP_NAME]/web
- Deploy the docker image from the heroku registry
In the last step you will have to execute the following command to finally deploy the image. Again insert the name of your heroku app:
heroku container:release web --app=[HEROKU_APP_NAME]
FAQ
- Are older versions of the SDK compatible with newer versions of Langfuse?
- Are prebuilt ARM images available?
- Can I deploy multiple instances of Langfuse behind a load balancer?
- Clickhouse handling failed migrations in self-hosted Langfuse
- How can I migrate data between Langfuse instances?
- How can I restrict access on my self-hosted instance to internal users?
- How do I migrate Langfuse from ClickHouse OSS to Cloud or BYOC?
- How do I reduce ClickHouse disk size on self-hosted Langfuse?
- How do I troubleshoot the self-hosted Langfuse Assistant?
- How to manage different environments in Langfuse?
- I cannot connect to my docker deployment, what should I do?
- I have forgotten my password
- Intermittent 502 and 504 network errors in self-hosted Langfuse
- JavaScript heap out of memory error in self-hosted Langfuse
- Missing events after POST /api/public/ingestion in self-hosted Langfuse
- PostgreSQL table ownership and migration failures in self-hosted Langfuse
- Queue management with BullMQ Admin API in self-hosted Langfuse
- Socket usage at capacity error in self-hosted Langfuse
- Timezone errors in self-hosted Langfuse
- Where can I find the API reference for self-hosted Langfuse?
- Why is my data retention job running into timeouts?
GitHub Discussions
Handling Rapid ClickHouse Growth (320GB+ in 60 days) via S3 Tiered Storage on EKS Clickhouse with S3 not accessiable by Langfuse web and worker containers I need help for setting up SMTP URL Connection S3 / Object Storage migration approach recommendations Prompt cache keys never written to Redis on self-hosted prod (v3.133) Custom modification in web and build custom image InvalidAccessKeyId: The Access Key Id you provided does not exist in our records Support needed for update (self hosted) Azure AD auth with PROXY: OAUTH_PARSE_PROFILE_ERROR Best practices to setup replication, backup/restore and Disaster recovery in Langfuse underlying storage How to debug when evaluations are stalling Langfuse Web Failing to start Because ClickHouse Tables in Readonly Mode and Zookeeper Metadata Not Found Migrate Projects and Users from one Langfuse env to another environment CROSSSLOT Redis Error Causing Prompt Creation Failure with Azure Cache for Redis in Cluster Mode (Self host in openshift) Best practices for resyncing ClickHouse replicas without impacting Langfuse Helm deployed ClickHouse doesn't work Options for Hosting ClickHouse Outside EKS Cluster Is v2 branch having production code for server and db? Recommendation for timeout setting Does Langfuse's specific ClickHouse usage require RWX or RWO? Azure EntraID SSO - Timeout on Self-Hosted PostgreSQL Authentication Failed on Docker Compose Deployment - "provided database credentials for postgres are not valid" Langfuse SSO "No email found in the user profile" when idToken enabled, or "id_token detected in the response" when disabled Pulled latest version but still dont see the newer models Langfuse self hosted setup not working due to Postgres DB error Langfuse Free Plan Data Retention Issue (Data Only Visible for 3 Days) Does NEXT_PUBLIC_SENTRY_DSN work properly in self-hosted? Issue when exporting large amount of data How do I deploy to `render.com` properly Langfuse +Docker+Pytest Self Hosting Issue Self hosted Postgres DB supporting external authentication requires project-scoped API key I can't get it,ask for help RBAC / Role-Based Authorization with External IdP (Keycloak) in Langfuse OSS Background migrations stuck in "Queued" status Setting default Data Retention value via LANGFUSE_INIT_PROJECT_RETENTION env variable doesn't work. Unable to connect the Langfuse Chart to the Postgres DB with Client Certificate i want to know minio default account and password Can't see any traces when app is deployed on AWS ECS Connect Langfuse to RAGflow Data Migration from Clickhouse OSS (running in EKS) to Clickhouse Cloud Rolling Upgrades Slow loading on UI + Clickhouse Timeout Errors How to correctly restore the PostgreSQL database for self-hosted Langfuse? Evals not executing in real time in high throughput environment Inquiry on Licensing for Self-Implemented Enterprise Features (Project-Level RBAC) on Langfuse OSS Is running ClickHouse migrations on every web container startup safe when scaling? (golang-migrate concurrency) Hosting on Azure Issue Intermittent Traces from App Install Langfuse + Strands Agent without cloud and without local docker PostgreSQL Authentication Failed Despite Setting Credentials in Helm Values During Langfuse Kubernetes Deployment (Self-Hosting) IngestionQueue failed not getting populated with failed events during clickhouse downtime Postgres table audit_logs filling up in langfuse open source FATAL: database "admin" does not exist How can i setup langfuse enviroment for run experiment? Limits Free Tier self-hosted ClickHouse (self-hosted) upgrade Langfuse self hosting issue in Internet facing Traces stop appear in self-hosted Langfuse after restart pods Issue with EFS-CSI Driver with the official terraform module Need help understanding the role of blob storage in Langfuse Cannot change database port with docker-compose Azure Application Gateway certificate unwanted changed Self-hosting 1-click deployments Auto re-connect database when db is ready Clarification related to metadata persistence while running clickhouse as an ECS fargate service Langfuse platform features and deployment questions Self-Hosted with ElastiCache and RDS Aurora PostgreSQL - UI Doesn't show traces Clickhouse timeout errors USE_AZURE_BLOB should be set to true by default when deploying to Azure Azure Terraform - switch from Access Policies to RBAC for Azure KeyVault “Body exceeded 1mb limit” error on dataset upload Disable Create Organizations Trying to call the langfuse batch ingestion api from a lambda function, all events not visible on dashboard despite 201 success how many langfuse.flush() will retry for network faliure ? Documentation / help for recovering Langfuse from a Clickhouse DB backup Self hosting Langfuse within our Cloud provider as a Highly available architecture Migration between databases Self hosted migration issue DOCKER-COMPOSE.BUILD.YML NO FUNCIONA Rate Limit on self-hosted webapp ClickHouse migrations marked as "dirty" prevent Langfuse Web from starting Migrate from one data region to another Langfuse-web failure Custom email claim with keycloak (self-hosted) Any easy way of ingesting the langfuse S3/blob store data to clickhouse SMTP_CONNECTION_URL invalid due to unencoded `/` in password Self-hosted headless initialization Failed ClickHouse Migration - "Dirty database version 23" and authentication error Custom Build Failure with node:24-alpine on K8s, Despite Increased Resources Does LangFuse support setting up usage alerting functionality in the self-hosted version? Traces displayed in the UI are 12-24 hours behind real-time How to rollback langfuse? Traces saved to S3 but not RDS on AWS CDK deployment with latest image Langfuse Worker OOM kills due to low memory resource request How to tell if migration is working? (And do all project keys reset when migrating to v3?) OpenTelemetry SSL Handshake Error Support login when Keycloak/LDAP users have no valid email Backup of prompt table when self-hosting Langfuse "Device or resource busy" when fetching prompt in production Genuine sign-in getting flagged as phishing bug: connection to self-hosted langfuse is not working Bug: Error message during langfuse web startup. Cannot set property message of ZodError which has only a getter Langfuse Selfhosted Deployment containers sequence High Inode Usage on MinIO Backend (~8.6M files/day) Leading to Rapid Filesystem Exhaustion Azure self-hosted deployment SSO configuration issue Azure deployment SSO error Local helm deployment (colima, macOS, k3s) Really slow latency for viewing traces within a timestamp and viewing a specific trace. Self-Hosted docker connectivity issues Possible to get Keycloack Realm to manage Langfuse organizations or projects Error: Body exceeded 4.5mb limit when migrating from Langfuse Cloud to Self-hosted Backfilling traces, observations and scores on langfuse Web to Clickhouse connection issue CROSSSLOT error initializing worker container Langfuse LLM as judge stuck at Running Evaluator Will langfuse open source ever allow programmatic org/project management? How to package langfuse into our own enterprise software? Azure deployment 404 error rate limit issue when calling evalution in aws self hosted environment. Open Source Self-Hosting Appears Unusable Help to fix the error: Max retries exceed with url: /v1/traces Deploying with AWS Terraform Unable to load from S3 on new task deployment on ECS Langfuseweb sometimes unable to connect to clickhouse Clickhouse storage increases even when there is no activity How to enable Organizations API for OSS self-hosted deployments? Langfuse on Terraform GCP without a custom domain Langfuse Web image takes lot of time to build and fails [3.75.1]] Certificate error while calling the self hosted llm from local machine When Langfuse traces are stored in ClickHouse, the project_id column is available, but there is no direct mapping or column provided for the project_name. Invalid credentials error when running langfuse & otel-collector locally Migration of Clickhouse to new location Redis only supported in standalone mode? Could we use Redis 6.2 instead? ClickHouse container keeps restarting with Exit Code 210: "Operation not permitted" during system table loading Ingestion failing due to CPU wait time Store traces and observations in postgres for downstream applications Getting "Unexpected error occurred. Please check your request and contact support: https://langfuse.com/support." Background migrations stuck at Queued Strange behaviour between self hosted and cloud langfuse : input output null and 0 token on self hosted Upgrading self-hosted langfuse from 2 to 3 Batch export configuration missing in docker-compose.yml Trace does not have a timestamp, using event time Self-Hosted Backups Data resilience options for ClickHouse component of Langfuse Error uploading media Leaner docker-compose.yaml file for self-hosters... Langfuse 1.0.0 Helm Chart Self-Hosting LangFuse:3 with ECS, CFN, and ECS Service Connect Image Deployment Issue Highly available Postgres and Redis in K8s Chart Delete traces via API Is there a tutorial available for installing langfuse without using Docker? Hardware resource recommendations for Redis and ClickHouse Is there a way to automate apiKey/apiSecret creation for new projects? Self-hosted Langfuse V3 just removed the database Requirements doubled from v2 to v3 Disable Background Migrations Challenges in Deploying Langfuse v3 in Active-Active Mode Using Docker Compose Langfuse V3 Self-Hosting: Deployment Options, Cost, and Scaling Considerations Values.yaml should contains storageClassName: Langfuse Docker Container Exits with “failed to parse scheme from database URL: no scheme” Despite Correct Environment Variables [self-hosted] Keycloak Login gets emtpy body Change default postgres schema Changing default user and password for Redis results in WRONGPASS error How to perform backup and restore between 2 langfuse instances Bug ? can connect with REDIS_CONNECTION_STRING works but not when setting REDIS_(HOST|REDIS_PORT|REDIS_AUTH) How to migrate twice? (background migrations) Langfuse v3 K8s resource recommendations Multi-Tenancy and others After database migration: One Google Login does not work anymore Clickhouse failing to initialise on EKS Error running background migrations Timeout error in update V2 to V3 After the traces table is empty, data can still be seen on the dashboard langfuse V3 , Next.js 14.2.21 - Failed to prepare server TypeError: Cannot set property message Exec docker compose up failed [self-hosted] google OAuth workflow sends to localhost:3000 Inconsistent API results in multi-shard clickhouse cluster V2 to V3 - Records of Postgres DB is not read by langfuse v3 Connecting to Langfuse API when self-hosting and using Google GCP IAP Langfuse v3 container fails to start due to Clickhouse permission issue New Users are unable to see Organizations in Automated Access Provisioning self hosting installation with docker compose langfuse-langfuse-web-1 restarting lots of "Read from postgres only" logs after upgrading to 2.93.6 Azure SSO return "No email found in user object" Process to restore Clickhouse state from S3 raw events? Langfuse self-hosted Hangs with no response when ran through docker compose Traces Disapeared on my webui, but are still available through api (python sdk) Support: Azure Entra ID Authentication for existing Azure Web App LANGFUSE_HOST for SDK client with custom base path Running Langfuse behind Nginx with custom base path Help needed with CustomSSOProvider Configuration for GitHub Enterprise Unexpected error occurred How/which environment var do I need to set to get OAuth2.0 authentication flow? Is there a way to keep database connections open longer? Is there a way to get process to exit on DB connection errors when rotating database passwords? Langfuse User Management with Custom Oauth How to prevent strangers from creating an account on your app Langfuse deployment issue on k8 Can you use the app without OAuth? For which kinds of data is `ENCRYPTION_KEY` used? How to set environment variables for custom oauth2.0 sso? Is there a way to clear trace data in batch? Azure AD auth: OAUTH_PARSE_PROFILE_ERROR Self host Langfuse not working - column `t6.cloud_config` does not exist Request Timeout for Dashboard Monitoring self-hosted langfuse. Error when trying to upgrade my langfuse deployment Langfuse not tracing code from my VM (server) Docs for K8s deployments Automated provisioning of default resources in self hosting create api keys pair using some method or api error ❌ tRPC failed on public.checkUpdate: Failed to fetch or json parse the latest releases Failed to fetch or json parse the latest releases Applying database migrations failed. This is mostly caused by the database being unavailable How to provide a TLS Cert for PGSQL cloud connection in Langfuse docker container? How to run langfuse locally while using a hosted database Right way to migrate langfuse deployed on K8s within an AWS account Help setting up GCP host (cloudbuild or console) Module not found: Can't resolve '@langfuse' Dockerfile of langfuse/langfuse:2 image Deployment into Azure Support for configuring SMTP email at project level Tracing directly to queue instead of http api Change port database in file docker-compose.yml Change port connection in docker compose No space left on device db error cannot execute INSERT in a read-only transaction [Errno 111] Connection refused when connecting to langfuse within docker compose Migrate a local deployment of langfuse from one computer to another Getting issue with local setup Can't see any traces or logs when running Langfuse locally. [Migration] Auto-migration DB error when upgrade langfuse version Can RBAC Role Assignment be done using Azure AD SSO token? Unable to get hello world program working due to incorrect public key / host Possibilities for auth Auth0 not working DevOps: What is the best way to create separate Langfuse instances in different environments: Dev, Test, QA, Prod? Not able to build docker image from web/Dockerfile Deploy to heroku How to add default user and project to self-hosted docker? 502-Bad Request bug: Potential bug with AzureAD auth setup How to automatically log in after configuring CUSTOM SSO in v4.21.0 Support short lived credentials for infrastructure dependencies Org. or project level langfuse workers Support configurable post-logout redirect for SSO (Keycloak federated logout) Add OCI Object Storage provider with multi-auth support (Instance Principal, Workload Identity, Resource Principal, OCI Profile, Session Token) vault-agent and aws pod identity support Support Multi Shard Clickhouse DB for Langfuse Support client-side encryption for S3 uploads With MinIO dead, I'm looking into decoupling the helm chart deployment from minio, potentially using rook Surface Redis eviction policy misconfiguration in UI / system health (noeviction required) Allow disabling manual signups without affecting SSO Deployment: Add easy deployment for `render.com` similar to `railway.com` Azure Workload Identity Support for Blob Storage Is it possible to add data retention (TTL) for traces, scores etc. in the UI? Custom base path with prebuilt image Specify SSL certificate for AppGW in Azure Terraform Support Dynamic Headers in Otel Traces and Langfuse API calls Data retention configuration at global and organization levels (not only per project) Docs on Backups lack docs on Restores Can we CustomBasePath support without rebuilding the image Self-hosted Langfuse resource connection via Managed Identity Disallow new org creation on self-hosted (without EE 😄 ) delete the raw events in minio after it is successfully stored in the postgresql Native GCS Scheduled Exports super admin account for maintainence purpose Request: Support for Cloud SQL proxy on helm chart The langfuse repo works fine with the default image (langfuse/langfuse:3). However, after making some code changes and building it locally with the docker image langfuse_main_llm:latest, I'm encountering the following error message. How can we resolve this? feat(ui): Allow multi nextjs environment pathbased with cookies feat(db): contribute Apache Doris as a OLAP database backend featrue: Azure Storage add support for MSI Add Google Cloud Storage support Allow configuration of two URLs for MinIO (internal and external) Langfuse V2, enable server access logs Support SingleStore as an OLAP Database Implementing Storage Policy with S3 in ClickHouse Make TCP port 9000 optional to support HTTP-only ClickHouse operation on Lambda Enable OpenTelemetry observability for self-hosted Add `updatePrompt` to langfuse v2 API Support GCP Workload Identity Add custom UID and GID support in Dockerfile Add multi-timezone support in Langfuse Support multi-shard clickhouse clusters MyScale DB instead of Clickhouse Make clickhouse usage more configurable [clickhouse] support customizable clickhouse database name Support for Cloudflare R2 (S3 compatible object storage) Add Separate Environment Variable for Public S3 Endpoint in Self-Hosted Setup Could we support Redis Cluster? Microsoft Azure Deployment Stack for Langfuse v3 Google Cloud (GCP) Deployment Stack for Langfuse v3 AWS Deployment Stack for Langfuse v3 Disable authentication in self-hosted deployments feat: add support for SSR to allow runtime BASE_PATH Centralized API Key Management with Secret Store Integration (e.g. HashiCorp Vault) Feature Request: Enable Invites with `AUTH_DISABLE_SIGNUP` (or/and GitHub OAuth for a given organization) Support for Atlassian OAuth-Provider Add organization / project / user / API key management API Ability to export all traces/sessions/scores from langfuse and import back to another langfuse instance Pre-defined user access Feature: Add CAS (and maybe SAML) as a authentication method Add AWS as a deployment option in the documentation Support for Custom Base URL Prefix in Langfuse (nextjs basepath) Add ARM64 docker image Support SAML login protocol Bring Langfuse to Cloud Marketplaces Terraform Provider for internal Langfuse configuration [oauth] Keycloak provider support Auth using Microsoft Entra ID Limit new user registration SSO: Cognito Add support for ZITADEL OIDC Ability to run langfuse in tests automatically without manual involvement Loose prisma datasource db provider. Enhancements for Langfuse User Sign-Up Control bug: Not allowing to limit Azure AD authentication for selected users in same tenent Use proper logger for backend API to make it configurable Support alternative databases next to Postgres, e.g. MySQL Admin API: projects, api keys, user management feat: Publish arm64 compatible docker images add optional TLS for Redis Sentinel connections via env flag Langfuse v4 GA Upcoming architecture changes: Simplify Langfuse for Scale (v4) Open Sourcing All Product Features Langfuse Kubernetes Helm Chart 1.0.0 Release Upcoming architecture changes for Langfuse 3.0 (self-hosted)
GitHubSupportGitHubIdeas
Upvotes
- 8votes\ \ Self-Hosted Backups\ \ jsirex•3/21/2025•\ \ 1Resolved
- 6votes\ \ Can RBAC Role Assignment be done using Azure AD SSO token?\ \ joshwright10•6/13/2024•\ \ 2Resolved
- 5votes\ \ Self-hosted headless initialization\ \ xavieralmendros-aily•9/23/2025•\ \ 2
- 4votes\ \ When Langfuse traces are stored in ClickHouse, the project_id column is available, but there is no direct mapping or column provided for the project_name.\ \ Nit31•6/19/2025•\ \ 2Resolved
- 3votes\ \ Inquiry on Licensing for Self-Implemented Enterprise Features (Project-Level RBAC) on Langfuse OSS\ \ Sprexatura•11/27/2025•\ \ 2Resolved
- 3votes\ \ OpenTelemetry SSL Handshake Error\ \ ivasquezv•9/12/2025•\ \ 1
- 3votes\ \ Bug: Error message during langfuse web startup. Cannot set property message of ZodError which has only a getter\ \ mohankn01•8/28/2025•\ \ 4
Discussions last updated: 9/16/2026, 8:29:53 PM (2 hours ago)
If you experience any issues when self-hosting Langfuse, please:
- Check out Troubleshooting & FAQ page.
- Use Ask AI to get instant answers to your questions.
- Ask the maintainers on GitHub Discussions.
- Create a bug report or feature request on GitHub.
Enterprise-grade support is available when self-hosting Langfuse. Learn more on our pricing page.
Was this page helpful?
Good
Bad
Last updated on 9/4/2026
PreviousOverview NextLocal Deployment (docker compose)
On this page
Deployment Guide (v2) Prerequisites: Postgres Database Deploying the Application Recommended Instance Size Configuring Environment Variables Authentication Email/Password SSO Additional configuration Headless Initialization Configuring the Enterprise Edition Health and Readiness Check Endpoint Encryption Encryption in transit (HTTPS) Encryption at rest (database) Additional application-level encryption Build Langfuse from source Custom Base Path Troubleshooting Updating the Application Kubernetes deployments Platform-specific information Railway Porter.run AWS Azure Google Cloud Platform (Cloud Run & Cloud SQL) Option 1: UI Deployment Option 2: Cloud Build Note on AlloyDB Heroku FAQ GitHub Discussions
Actions
Give us feedback Edit this page on GitHub
Contributors
Last edited Sep 4, 2026
Marc Klingen](https://github.com/marcklingen) Ben Bachem](https://github.com/bezbac) omahs](https://github.com/omahs) +1 more
Ask AI A
A