Sign inSign up

tobilg/neoserver

By tobilg

•Updated 3 days ago

Multi-workspace geospatial server: OGC API Features/Tiles, WMS, WFS, WCS, WMTS. Go + DuckDB.

Image
Integration & delivery
0

380

tobilg/neoserver repository overview

⁠neoserver

A modern, multi-workspace geospatial server written in Go, and a lightweight, API-driven alternative to GeoServer.

It publishes PostGIS, DuckDB, GeoParquet, vector files (GeoPackage, Shapefile, GeoJSON, FlatGeobuf) and GeoTIFF/COG rasters through:

  • OGC API - Features and OGC API - Tiles (vector and raster tiles, TileJSON)
  • WMS 1.3.0, including SLD, GetFeatureInfo, PNG/JPEG/GeoTIFF/PDF/SVG/KML output
  • WFS 2.0, including transactions, locking, stored queries and FES filters
  • WCS 2.1 / 2.0.1
  • WMTS 1.0

It is managed through a REST API and an embedded admin console. Configuration and credentials live in an encrypted DuckDB catalog. It supports workspace-level RBAC, API keys, JWT and OIDC login, and per-layer access control.

⁠Docker

Images are linux/amd64 only. Each GitHub release⁠ also carries an SBOM, SHA256SUMS and a record of the test gates the build passed.

⁠Quick start (local)

1. Create a store key and initialize the catalog. init prints a one-time bootstrap token; save it.

export NEOSRV_STORE_KEY="$(openssl rand -hex 32)"   # keep this key: it cannot be changed later

docker run --rm -v neoserver-data:/data \
  -e NEOSRV_STORE_KEY \
  tobilg/neoserver:latest init

2. Start the server:

docker run -d --name neoserver -p 127.0.0.1:9000:9000 \
  -v neoserver-data:/data \
  -e NEOSRV_STORE_KEY \
  -e NEOSRV_SERVER_HTTPHOST=0.0.0.0 \
  -e NEOSRV_SERVER_URLBASE=http://localhost:9000 \
  -e NEOSRV_AUTH_REQUIREHTTPS=false \
  -e NEOSRV_WMS_ENABLED=true -e NEOSRV_WFS_ENABLED=true \
  tobilg/neoserver:latest

3. Open the admin console at http://localhost:9000/admin⁠ and sign in with the bootstrap token.

NEOSRV_AUTH_REQUIREHTTPS=false is for plain HTTP on your own machine only. Docker's port forwarding makes local requests look non-local, and with HTTPS required every authenticated request is rejected with 426. For any other deployment, remove it, terminate TLS in a reverse proxy, and set NEOSRV_SERVER_TRUSTEDPROXYCIDRS.

⁠Serving your own files

File sources must live under /data/sources (or managed imports under /data/imports); nothing else in the container is readable as a data source. Mount a host directory read-only, readable by the container user (UID 65532):

-v "$PWD/geodata:/data/sources:ro"

Then create a service in the console pointing at e.g. /data/sources/roads.gpkg. PostGIS services connect over the network; by default only super administrators may add new database hosts (see Datasource.DatabaseHosts).

⁠Configuration

Every setting is available as an environment variable with the NEOSRV_ prefix, or through a TOML file passed with --config.

⁠Persistence, backups and upgrades

All state lives in the /data volume: catalog, audit log, imports, and tile cache.

  • Backups: stop the container and back up the whole volume. Store NEOSRV_STORE_KEY separately; a backup cannot be opened without it.
  • Scaling: run one server per volume. There is no clustering.
  • Upgrades: read the release notes⁠ before upgrading, and back up first.

Guides:

⁠Security

The container runs as non-root UID 65532. Report vulnerabilities privately: https://github.com/tobilg/neoserver/security/policy⁠

⁠License

MIT. The image bundles GDAL, PROJ, DuckDB and other third-party software under their own licenses; notices are in /usr/share/doc in the image and in THIRD-PARTY-LICENSES.md⁠.

Tag summary

Content type

Image

Digest

sha256:dab746cc6…

Size

220 MB

Last updated

3 days ago

docker pull tobilg/neoserver