Run Broka Community from one compose file.
Two files, four steps. The recipe is the one the product repository tests against, published here byte for byte with its checksums, and the console is up on port 3000 when the last step finishes.
- compose.yml — 3,457 bytes
- .env.example — 1,322 bytes
Community is free and runs Kafka. Redis, RabbitMQ, Artemis and Memcached — and forwarding the audit trail to Kafka or RabbitMQ, data masking, the MCP server, Applications, Access Review, read recording and Slack, Teams and webhook alerts — are Commercial, which is not on sale yet. Downloading or running the image accepts the licence agreement. Nothing here creates an account, and nothing in a Community installation calls out to us.
Get it running
- Download compose.yml and .env.example into an empty folder. A browser saves the second as
env.example, without its dot: rename it back, or fetch both, with their checksums, from a terminal:curl -fsSLO "https://broka.dev/download/1.0.1/{compose.yml,.env.example,SHA256SUMS}" - Copy
.env.exampleto.envand fill in the secrets. The file says how to generate each one, and which lines must never change on a running installation. - Run
docker compose up -d. Everything the console needs, PostgreSQL included, is in the file; the Orchestrator applies its schema on first start. - Open
http://localhost:3000and create the first administrator.
Check what arrived
Every published file is listed with its SHA-256, and SHA256SUMS holds the same values in the format sha256sum reads. Download it next to the two files and run:
sha256sum -c SHA256SUMSadef470e18c6132fc9a4d6be1a57e9c29c453b241ffab7f3292d529ece68416d3,457 bytes
b24bd9a317c8aa5b291d24b916a021dce8ae84041f6e85ee6873d0a24808afbf1,322 bytes
These sums show the files arrived intact; they do not prove who published them. The two files on this page are not signed, and this page will not claim otherwise. The container images the recipe pulls are: each is signed with Broka’s image-signing key, whose public half is at https://broka.dev/keys/cosign.pub, and carries its software bill of materials (CycloneDX) attested with the same key. With cosign 3 or later, check both before the first start:
for image in broka-ui broka-orchestrator broka-broker; do
cosign verify --key https://broka.dev/keys/cosign.pub orchestalabs/$image:1.0.1
cosign verify-attestation --key https://broka.dev/keys/cosign.pub --type cyclonedx orchestalabs/$image:1.0.1 > /dev/null
doneThe compose file pins orchestalabs/broka-ui, orchestalabs/broka-orchestrator and orchestalabs/broka-broker at 1.0.1: the Community images, on Docker Hub. It pulls them on first start. Setting up the console and connecting your first cluster are in the documentation.

