Mojo UpDocs
Self-hosted AIOE

Evaluate with Docker Compose

Run AIOE on one machine, sign in with Entra ID, and enrol your first workbench.

In this tutorial you run the whole of AIOE on one computer with Docker Compose: PostgreSQL, Redis, the API and the console. You sign in with your own Entra ID tenant, approve your own AI Workbench, and watch it appear in the console. It takes about an hour, most of it in the Entra admin centre.

This is the reference layout AIOE ships for evaluation and for small on-premises installs. Everything runs over plain HTTP on localhost, so keep it on your own machine. For a real installation, use Helm or Azure.

What you need

  • Docker with Docker Compose v2.
  • The AIOE release from Mojo Up, which includes docker-compose.yml and access to the AIOE images. If you do not have it, ask Mojo Up.
  • Free ports 3001 (API), 8080 (console), 5432 (PostgreSQL) and 6379 (Redis).
  • An Entra ID tenant where you can create app registrations.
  • AI Workbench installed on the same computer.

What the compose file runs

ServiceImagePortWhat it does
dbpostgres:16-alpine5432The database aioe, user aioe, password localdev, kept in the pgdata volume.
redisredis:7-alpine6379Shared state for the relay.
apiaioe-api3001The API, with STORE=postgres, at http://localhost:3001. It waits for the database to be healthy.
consoleaioe-console8080The console, at http://localhost:8080, built to call the API at http://localhost:3001.

Evaluation only

The database password is localdev and nothing is encrypted in transit. Do not expose these ports beyond your machine.

Register AIOE in Entra ID

Follow Register AIOE in Entra ID, with these values for a local evaluation:

  • Application ID URI of the API: anything unique to you, for example api://aioe-eval.example.com.
  • Single-page application redirect URI on the client: http://localhost:8080/ (Entra accepts plain HTTP for localhost).
  • Assign yourself the admin role.

Keep four values: your tenant ID, the API registration's client ID, the client registration's client ID, and the full scope (for example api://aioe-eval.example.com/access).

Tell AIOE about your organisation

Next to docker-compose.yml, create a file named .env. Docker Compose reads it and passes the values to the API:

.env
AIOE_BOOTSTRAP_TENANT=example
AIOE_BOOTSTRAP_ORGANISATION=Example Pty Ltd
# Your email domain, and localhost so the API answers for itself on this machine.
AIOE_BOOTSTRAP_DOMAINS=example.com,localhost
AIOE_BOOTSTRAP_OIDC_ISSUER=https://login.microsoftonline.com/<tenant-id>/v2.0
AIOE_BOOTSTRAP_OIDC_AUDIENCE=<API registration client ID>
AIOE_BOOTSTRAP_OIDC_CLIENT_ID=<client registration client ID>
AIOE_BOOTSTRAP_API_SCOPE=api://aioe-eval.example.com/access

Replace every value with yours. Keep localhost in the domains: the API recognises your organisation from the host name a request arrives at, and on this machine that is localhost.

Start the stack

Terminal
docker compose up -d
docker compose logs -f api

Wait for these lines in the API's log, then press Ctrl+C to stop following it:

connected to postgres
bootstrap tenant ready
aioe api listening

Before it listens, the API applies the database migrations, so the first start takes a little longer.

Check the discovery document

Open http://localhost:3001/.well-known/aioe.json in a browser. You see your organisation's name, the API and relay addresses, your issuer, client ID and scope. This public document is what a workbench reads to find your organisation.

If you see unknown_tenant instead, the host name is not in AIOE_BOOTSTRAP_DOMAINS: add localhost, then run docker compose up -d again.

Sign in to the console

Open http://localhost:8080 and sign in with your Entra account. The console opens on Workbenches, which is empty. Open Settings: it names your organisation, its tenant name and identity provider, and shows the discovery record you would publish for a real domain.

Connect your workbench

In AI Workbench, open Settings, then Organisation. Choose Enter the platform URL instead, enter http://localhost:3001, and continue.

The workbench shows an eight-character code such as BCDF-2345, and opens the console's Enrol a workbench page in your browser with the code filled in. If the page does not open, open Enrol a workbench in the console yourself and type the code. Codes expire ten minutes after they are shown.

Approve it

The console shows the workbench's name and what it will be able to do. Screen mirroring stays off unless you grant it later. Choose Approve.

The workbench receives its token on its next poll, a few seconds later. In the console, choose Open it, or go to Workbenches: your machine is listed as online, with its workspaces.

Try it out

  • Publish a skill or a prompt in Catalogue: the workbench picks it up on its next sync.
  • Publish an organisation default in Policies: the workbench applies it as read-only overrides.
  • Open your workbench from Workbenches and control it from the browser, over the relay.
  • Look at Audit: your sign-in, the enrolment and the approval are already on the record.

Clean up

Terminal
docker compose down       # stop, keep the data
docker compose down -v    # stop and delete the database volume

To disconnect the workbench first, open it in the console and choose Revoke access.

What you have now

A complete AIOE with one organisation, signed in through your identity provider, and one enrolled workbench. A production install adds TLS on public host names, a managed PostgreSQL with backups, a DNS record so workbenches find AIOE from a work email, and Redis-backed replicas.

On this page