Multi-workspace geospatial server: OGC API Features/Tiles, WMS, WFS, WCS, WMTS. Go + DuckDB.
380
A modern, multi-workspace geospatial server written in Go, and a lightweight, API-driven alternative to GeoServer.
It publishes PostGIS, DuckDB, GeoParquet, vector files (GeoPackage, Shapefile, GeoJSON, FlatGeobuf) and GeoTIFF/COG rasters through:
It is managed through a REST API and an embedded admin console. Configuration and credentials live in an encrypted DuckDB catalog. It supports workspace-level RBAC, API keys, JWT and OIDC login, and per-layer access control.
Images are linux/amd64 only. Each GitHub release also carries an SBOM, SHA256SUMS and a record of the test gates the build passed.
1. Create a store key and initialize the catalog. init prints a one-time bootstrap token; save it.
export NEOSRV_STORE_KEY="$(openssl rand -hex 32)" # keep this key: it cannot be changed later
docker run --rm -v neoserver-data:/data \
-e NEOSRV_STORE_KEY \
tobilg/neoserver:latest init
2. Start the server:
docker run -d --name neoserver -p 127.0.0.1:9000:9000 \
-v neoserver-data:/data \
-e NEOSRV_STORE_KEY \
-e NEOSRV_SERVER_HTTPHOST=0.0.0.0 \
-e NEOSRV_SERVER_URLBASE=http://localhost:9000 \
-e NEOSRV_AUTH_REQUIREHTTPS=false \
-e NEOSRV_WMS_ENABLED=true -e NEOSRV_WFS_ENABLED=true \
tobilg/neoserver:latest
3. Open the admin console at http://localhost:9000/admin and sign in with the bootstrap token.
curl -H "Authorization: Bearer $TOKEN" http://localhost:9000/api/v1/workspacesNEOSRV_AUTH_REQUIREHTTPS=false is for plain HTTP on your own machine only. Docker's port forwarding makes local requests look non-local, and with HTTPS required every authenticated request is rejected with 426. For any other deployment, remove it, terminate TLS in a reverse proxy, and set NEOSRV_SERVER_TRUSTEDPROXYCIDRS.
File sources must live under /data/sources (or managed imports under /data/imports); nothing else in the container is readable as a data source. Mount a host directory read-only, readable by the container user (UID 65532):
-v "$PWD/geodata:/data/sources:ro"
Then create a service in the console pointing at e.g. /data/sources/roads.gpkg. PostGIS services connect over the network; by default only super administrators may add new database hosts (see Datasource.DatabaseHosts).
Every setting is available as an environment variable with the NEOSRV_ prefix, or through a TOML file passed with --config.
NEOSRV_WMS_ENABLED=true, …), then enable them per workspace.All state lives in the /data volume: catalog, audit log, imports, and tile cache.
NEOSRV_STORE_KEY separately; a backup cannot be opened without it.Guides:
The container runs as non-root UID 65532. Report vulnerabilities privately: https://github.com/tobilg/neoserver/security/policy
MIT. The image bundles GDAL, PROJ, DuckDB and other third-party software under their own licenses; notices are in /usr/share/doc in the image and in THIRD-PARTY-LICENSES.md.
Content type
Image
Digest
sha256:dab746cc6…
Size
220 MB
Last updated
3 days ago
docker pull tobilg/neoserver