ox Docs
Log in

Services catalog

Every service ox provisions from one [[services]] block in ox.toml. Each entry carries its tested_on matrix: the Ubuntu releases a real verification run covered on a disposable VPS, running the exact script linked from the entry. Deploys target Debian-based hosts, tailored to Ubuntu LTS; a host release outside an entry's tested_on still deploys, with a loud warning naming the verified releases.

19 entries · 19 verified on at least one Ubuntu release. Local listing: ox catalog list; one entry: ox catalog show postgres@17.

[[services]]
id = "postgres@17"          # pinned variant; the bare name picks the default

[services.args]
extensions = ["vector"]

[[services]]
id = "celery@5"
[services.args]
app = "myproj"
workers = 4
queues = ["default", "mail"]

celery-beat@5

default variant of celery-beat worker · project-shared · 128 MB floor

tested_on: ubuntu-24.04 · verify.sh

Celery beat scheduler rendered from the app's runtime: one project unit running the periodic-task schedule, with its schedule file under the service data dir. Pair with celery@5 for the workers.

arg type description
app string the celery app module; empty runs bare `celery` from the release directory

celery@5

default variant of celery worker · project-shared · 256 MB floor

tested_on: ubuntu-24.04 · verify.sh

Celery worker rendered from the app's runtime: one project unit consuming the declared queues at the declared concurrency. The broker is whatever the app's env carries (declare redis or rabbitmq as a service to get CELERY_BROKER_URL).

arg type description
app string the celery app module (e.g. "myproj.celery" or "myproj"); empty runs bare `celery` from the release directory
workers int worker concurrency (--concurrency)
queues strings queues to consume (--queues); the default is celery's own default queue name, which is where a vanilla celery app publishes

clickhouse@24

default variant of clickhouse datastore · host-shared · 1024 MB floor

tested_on: ubuntu-24.04 · verify.sh

ClickHouse server from the official repository. Default user, no password, 127.0.0.1 only (single-operator host); the project's database is created by the recipe.

provides: CLICKHOUSE_URL, CLICKHOUSE_HOST, CLICKHOUSE_PORT

flower@1

default variant of flower ui · project-shared · 128 MB floor

tested_on: ubuntu-24.04 · verify.sh

Flower, the Celery monitoring UI, as a project unit reading the same broker the workers use. The app needs `flower` in its dependencies.

provides: FLOWER_URL

requires: celery

arg type description
app string the celery app module; empty runs bare `celery` from the release directory

livekit@1

default variant of livekit daemon · project-shared · 256 MB floor

tested_on: ubuntu-24.04 · verify.sh

LiveKit media server (pinned release binary) as a project unit with generated API credentials (LIVEKIT_API_KEY / LIVEKIT_API_SECRET). Binds the allocated TCP port on 127.0.0.1; WebRTC media needs the host's UDP range reachable when clients connect from outside.

provides: LIVEKIT_URL, LIVEKIT_API_KEY, LIVEKIT_API_SECRET

mailpit@1

default variant of mailpit daemon · project-shared · 64 MB floor

tested_on: ubuntu-24.04 · verify.sh

Mailpit (pinned release binary) as a project unit: SMTP on the allocated port, the web UI on the next one. Point the app's SMTP at SMTP_URL and read mail in the browser at MAILPIT_URL.

provides: SMTP_URL, MAILPIT_URL

meilisearch@1

default variant of meilisearch datastore · project-shared · 256 MB floor

tested_on: ubuntu-24.04 · verify.sh

Meilisearch (pinned release binary) running as a project unit with a generated master key (MEILI_MASTER_KEY); production mode on the allocated port.

provides: MEILISEARCH_URL, MEILI_MASTER_KEY

memcached@1

default variant of memcached datastore · host-shared · 128 MB floor

tested_on: ubuntu-24.04 · verify.sh

Memcached (the Ubuntu package) on 127.0.0.1:11211; every project shares the one cache.

provides: MEMCACHED_URL

mongodb@8

default variant of mongodb datastore · host-shared · 768 MB floor

tested_on: ubuntu-24.04 · verify.sh

MongoDB 8.0 Community from the official repository (7.0 has no ubuntu-24.04 repository, so the first verified variant is 8.0). Binds 127.0.0.1:27017 with no auth (single-operator host; auth lands with a later entry version); the project's database is created on first use.

provides: MONGODB_URI, MONGODB_DB

mysql@8

default variant of mysql datastore · host-shared · 512 MB floor

tested_on: ubuntu-24.04 · verify.sh

MySQL 8 (the Ubuntu mysql-server package). Per-project user and database named after the project, converged from MYSQL_PASSWORD on every deploy.

provides: MYSQL_URL, MYSQL_HOST, MYSQL_PORT, MYSQL_USER, MYSQL_PASSWORD, MYSQL_DATABASE

nats@2

default variant of nats datastore · project-shared · 128 MB floor

tested_on: ubuntu-24.04 · verify.sh

NATS server (pinned release binary) running as a project unit: one instance per project, so subject namespaces stay private; no auth inside the sandbox (127.0.0.1 bind).

provides: NATS_URL

neo4j@5

default variant of neo4j datastore · host-shared · 1024 MB floor

tested_on: ubuntu-24.04 · verify.sh

Neo4j 5 from the official Debian repository. The admin password is generated into NEO4J_PASSWORD and converged on every deploy (probe, reset, re-probe); NEO4J_URI points at the local Bolt endpoint.

provides: NEO4J_URI, NEO4J_PASSWORD

postgres@16

datastore · host-shared · 512 MB floor

tested_on: ubuntu-24.04 · verify.sh

PostgreSQL 16 from PGDG. Per-project role/database/credentials are driven by the app's DATABASE_URL env (autowire fills a local one); extensions land on that database.

provides: DATABASE_URL

arg type description
extensions strings extensions to CREATE EXTENSION on the app's database (vector, postgis, pg_trgm, uuid-ossp, ...); the apt package for the installed major is inferred
databases strings database names to ensure beside the env-driven one; the env's database and its extensions stay the source of truth

postgres@17

default variant of postgres datastore · host-shared · 512 MB floor

tested_on: ubuntu-24.04 · verify.sh

PostgreSQL 17 from PGDG. Per-project role/database/credentials are driven by the app's DATABASE_URL env (autowire fills a local one); extensions land on that database.

provides: DATABASE_URL

arg type description
extensions strings extensions to CREATE EXTENSION on the app's database (vector, postgis, pg_trgm, uuid-ossp, ...); the apt package for the installed major is inferred
databases strings database names to ensure beside the env-driven one; the env's database and its extensions stay the source of truth

prometheus@2

default variant of prometheus daemon · host-shared · 512 MB floor

tested_on: ubuntu-24.04 · verify.sh

Prometheus (the Ubuntu package) on 127.0.0.1:9090, ready to scrape this host's exporters; add scrape config through /etc/prometheus.

provides: PROMETHEUS_URL

qdrant@1

default variant of qdrant datastore · project-shared · 512 MB floor

tested_on: ubuntu-24.04 · verify.sh

Qdrant vector database (pinned release binary) running as a project unit: one instance per project, data under the project's service dir, port allocated by ox.

provides: QDRANT_URL

rabbitmq@3

default variant of rabbitmq datastore · host-shared · 256 MB floor

tested_on: ubuntu-24.04 · verify.sh

RabbitMQ (the Ubuntu rabbitmq-server package). One shared broker; every project gets its own vhost and user, converged from AMQP_PASSWORD on every deploy.

provides: AMQP_URL, CELERY_BROKER_URL

redis@7

default variant of redis datastore · host-shared · 128 MB floor

tested_on: ubuntu-24.04 · verify.sh

Redis 7 (the Ubuntu redis-server package). One shared instance; every project gets its own database index so queues and result keys never collide.

provides: REDIS_URL, REDIS_CONNECTION_URL

sqlite@3

default variant of sqlite datastore · project-shared

tested_on: ubuntu-24.04 · verify.sh

SQLite: ensures the sqlite3 CLI for migrations, inspection, and backups. No daemon and no port; the database file lives wherever the app puts it (keep it under a writable path or the project's service data dir).

How testing works

Every entry ships with its verification (S-15): a disposable Ubuntu VPS runs the entry's rendered recipe per variant and configuration, and the run records two artifacts — verify.sh, the exact flattened command script that ran, and the host facts (release, arch, installed versions, probes). tested_on derives from the green runs; a variant without a green run on a release never claims it. Provisioning renders the same command sequence with the project's parameters, so what ships is what was tested. Runs repeat on every entry version bump and every new Ubuntu LTS.

So far 19 of 19 entries carry a green run. The rest deploy with a warning until their run lands.