Network access and offline installation
The browser connects to your regex101 instance. Saved workspaces and accounts reside in your MySQL database. Redis stores sessions and cached responses. The deployment also uses external services for licensing, image downloads, and any configured identity providers.
Network flows
| Source | Destination | Purpose |
|---|---|---|
| Browser | Your HTTPS hostname | Editor, workspaces, sign-in, and integrations |
| Nginx | API, server rendering, and preview services | Route application requests inside the deployment |
| API | MySQL and both Redis services | Application data, sessions, and cache |
| Server rendering | Redis cache | Cached HTML |
| Preview service | API | Retrieve workspace data |
| Application services | api.keygen.sh | Online license validation and machine-license checkout |
| API | docs.regex101.com | Read the Enterprise release manifest |
| Docker host | registry.digidib.dev and vendor image registries | Download images during installation or updates |
| Browser and API | Configured identity provider | OAuth or OpenID Connect sign-in |
The database and Redis ports are internal to the supplied Compose network. They are not published on the Docker host. Your TLS proxy provides the public HTTPS endpoint.
License validation
The application validates its license at startup and runs the validator again each day. A valid cached machine file can satisfy validation without an online request. The standard online checkout requests a machine file with a 14-day lifetime.
Without a usable local file, the application contacts Keygen to validate and activate the host, then retrieves a machine file. These requests contain license and machine identifiers. They do not contain regex patterns or test strings.
The standard cache lives inside each application container. Container recreation can require online validation again. A configured offline license file uses a persistent host file instead.
Release discovery
The API requests https://docs.regex101.com/enterprise/releases/latest.json at startup and once per day.
The request has a five-second timeout. An unavailable manifest does not stop the application.
The manifest contains release information. Discovery does not download images or install updates, and its request contains no pattern or test string.
MINIMAL_INTERFACE hides release notices in the interface. It does not disable the manifest request.
Offline installations
An offline installation uses a supplied machine license file and images already available on the Docker host. The license file must permit offline validation and match the machine fingerprint.
Obtain the machine fingerprint
After the application image is available on the target host, run:
docker compose run --rm --no-deps api \
node --input-type=module -e "import nodeMachineId from 'node-machine-id'; console.log(await nodeMachineId.machineId())"
Send the fingerprint to contact@regex101.com to obtain the machine file.
Set its host path in .env:
LICENSE_FILE=/opt/regex101/regex101.license
The Compose override mounts that file read-only into the API, server rendering, and preview containers. An invalid or expired mounted file stops license validation. The application does not replace it through an online fallback.
On a replacement host, obtain a file for that host's fingerprint. Keep LICENSE_KEY configured with the supplied key.
Transfer the images
On a connected host with the deployment files and selected image tags, sign in and pull the images:
docker login registry.digidib.dev
docker compose pull
docker logout registry.digidib.dev
Export the selected application and vendor images:
docker compose config --images | xargs docker image save -o regex101-images.tar
Transfer the archive and deployment files to the target host. Load the archive there:
docker image load -i regex101-images.tar
The target .env must select the same image tags as the archive.
Start with local images
The standard start.sh always logs in and pulls images. For an offline start, use Compose directly:
docker compose -f docker-compose.yml -f docker-compose.license-file.yml \
up -d --pull never
The release checker still attempts its manifest request. Network isolation can block that request without preventing startup. An external identity provider still needs a network route. Use a reachable internal OpenID Connect provider for isolated sign-in.
Privacy policy
Read the Enterprise privacy policy for the published terms. The network flows above describe the application implementation and the deployment configuration. Questions about the policy can go to privacy@regex101.com.