Deploy
PDQ runs as a set of Docker containers. That is the whole deployment model — there is no PDQ-specific runtime, orchestrator or appliance underneath it. Anything that can run containers can run the platform: a cloud provider, your own hypervisor, or a single prepared VM.
What varies between installations is where each component sits relative to the data it touches, and how access to the platform is fronted and authenticated. Only Caddy is exposed, on port 443; no other component publishes a port.
In this section
| Installing and securing the platform | Host requirements, disk and Docker preparation, the systemd dependency chain and startup sequence for AME, INGEST, DLS and DWA, then Caddy, Entra access, role mapping and how upgrades are handled. |
The components you deploy
| Component | Role |
|---|---|
| AME (Active Metadata Engine) | Central metadata repository and API hub. Everything else reads its configuration from here. |
| INGEST | Extraction agents, one container per source connection. Placed close to the source system. |
| DLS (Data Lake Service) | Archives, standardises, profiles and publishes delivered files. |
| DWA (Data Warehouse Automation) | Generates SQL and orchestrates loading along the model chain: Published → Base → Core → DM. |
| Config UI | Web interface for configuring the above. |
| Caddy | TLS termination and authenticated access to the platform. It is the only component exposed, on port 443. |
Startup order matters
AME holds the metadata every other component reads at start-up. It must be running and reachable before INGEST, DLS or DWA are started. The full sequence is in Installing and securing the platform.