Skip to main content

Network access and offline installation

The browser connects to your regex101 instance. Saved workspaces and accounts reside in your MySQL database. Redis stores sessions and cached responses. The deployment also uses external services for licensing, image downloads, and any configured identity providers.

Network flows​

SourceDestinationPurpose
BrowserYour HTTPS hostnameEditor, workspaces, sign-in, and integrations
NginxAPI, server rendering, and preview servicesRoute application requests inside the deployment
APIMySQL and both Redis servicesApplication data, sessions, and cache
Server renderingRedis cacheCached HTML
Preview serviceAPIRetrieve workspace data
Application servicesapi.keygen.shOnline license validation and machine-license checkout
APIdocs.regex101.comRead the Enterprise release manifest
Docker hostregistry.digidib.dev and vendor image registriesDownload images during installation or updates
Browser and APIConfigured identity providerOAuth or OpenID Connect sign-in

The database and Redis ports are internal to the supplied Compose network. They are not published on the Docker host. Your TLS proxy provides the public HTTPS endpoint.

License validation​

The application validates its license at startup and runs the validator again each day. A valid cached machine file can satisfy validation without an online request. The standard online checkout requests a machine file with a 14-day lifetime.

Without a usable local file, the application contacts Keygen to validate and activate the host, then retrieves a machine file. These requests contain license and machine identifiers. They do not contain regex patterns or test strings.

The standard cache lives inside each application container. Container recreation can require online validation again. A configured offline license file uses a persistent host file instead.

Release discovery​

The API requests https://docs.regex101.com/enterprise/releases/latest.json at startup and once per day. The request has a five-second timeout. An unavailable manifest does not stop the application.

The manifest contains release information. Discovery does not download images or install updates, and its request contains no pattern or test string. MINIMAL_INTERFACE hides release notices in the interface. It does not disable the manifest request.

Offline installations​

An offline installation uses a supplied machine license file and images already available on the Docker host. The license file must permit offline validation and match the machine fingerprint.

Obtain the machine fingerprint​

After the application image is available on the target host, run:

docker compose run --rm --no-deps api \
node --input-type=module -e "import nodeMachineId from 'node-machine-id'; console.log(await nodeMachineId.machineId())"

Send the fingerprint to contact@regex101.com to obtain the machine file. Set its host path in .env:

LICENSE_FILE=/opt/regex101/regex101.license

The Compose override mounts that file read-only into the API, server rendering, and preview containers. An invalid or expired mounted file stops license validation. The application does not replace it through an online fallback.

On a replacement host, obtain a file for that host's fingerprint. Keep LICENSE_KEY configured with the supplied key.

Transfer the images​

On a connected host with the deployment files and selected image tags, sign in and pull the images:

docker login registry.digidib.dev
docker compose pull
docker logout registry.digidib.dev

Export the selected application and vendor images:

docker compose config --images | xargs docker image save -o regex101-images.tar

Transfer the archive and deployment files to the target host. Load the archive there:

docker image load -i regex101-images.tar

The target .env must select the same image tags as the archive.

Start with local images​

The standard start.sh always logs in and pulls images. For an offline start, use Compose directly:

docker compose -f docker-compose.yml -f docker-compose.license-file.yml \
up -d --pull never

The release checker still attempts its manifest request. Network isolation can block that request without preventing startup. An external identity provider still needs a network route. Use a reachable internal OpenID Connect provider for isolated sign-in.

Privacy policy​

Read the Enterprise privacy policy for the published terms. The network flows above describe the application implementation and the deployment configuration. Questions about the policy can go to privacy@regex101.com.