# System requirements

For a small to medium installation we recommend the following resources.

## Hardware

| Resource | Minimum | Recommended |
|----------|---------|-------------|
| CPU      | 2 vCPU  | 4 vCPU      |
| RAM      | 4 GB    | 8 GB        |
| Storage  | 20 GB SSD | 40 GB SSD |

## Software

- **Docker** 24+ and **Docker Compose** v2 (for the container installation)
- **PostgreSQL** 15+ with the `vector` extension, **pgvector 0.7+** (0.8+ recommended).
  0.7 is a hard floor from this release on, even if you never use 3072-dimensional
  embeddings: the schema contains two search indexes on the `halfvec` type, which only
  exists from 0.7 — both `db:migrate` and `db:schema:load` abort on older extensions.
  Before upgrading an existing installation, check
  `SELECT extversion FROM pg_extension WHERE extname='vector';` and run
  `ALTER EXTENSION vector UPDATE;` if needed.
- **libvips 8.13+** (8.15+ recommended). Rails calls `Vips.block_untrusted` at boot, a
  guard against CVE-2026-66066. Without that method **the application does not boot at
  all** — not for migrations either, and not for `rails runner`. Odd but deliberate: a
  system with **no** libvips starts (you merely lose image variants); only an **old** one
  aborts. ⚠️ Ubuntu 22.04 ships 8.12.1 and nothing newer, backports included; build
  libvips from source into `/usr/local` there, or move to Ubuntu 24.04, which carries
  8.15. Check with `vips --version`, or more precisely from the application:
  `bundle exec ruby -e 'require "vips"; p Vips.respond_to?(:block_untrusted)'`.
- A TLS certificate (e.g. via Let's Encrypt) for production

<div class="docs-callout docs-callout--warning">
  <div class="docs-callout__title">Mind the architecture</div>
  <p>Native binaries are not portable between ARM (e.g. Apple-Silicon development) and x86_64 (typical servers). Always build images on the target architecture.</p>
</div>

## Network

Lalabase needs outbound access to your AI provider (e.g. OpenAI) if you use the AI
features. All other services run inside your own infrastructure.
