Skip to content

docs: add Windows Docker installation instructions - #2427

Open
gunjansonaw wants to merge 2 commits into
aboutcode-org:mainfrom
gunjansonaw:docs/windows-docker-setup
Open

gunjansonaw wants to merge 2 commits into
aboutcode-org:mainfrom
gunjansonaw:docs/windows-docker-setup

Conversation

@gunjansonaw

Copy link
Copy Markdown

Summary

Add Windows-specific Docker installation instructions.
Document PowerShell-based environment configuration.
Document the Windows Docker Compose override required to mount the configuration directory.
Remove the previous generic Windows warning now that dedicated instructions are available.
### Testing
Verified the Windows Docker setup locally with Docker Desktop.
Confirmed the application starts successfully with the documented configuration.
Confirmed http://localhost returns HTTP 200.
git diff --check passes.
Notes

The Windows instructions are Docker-based because native Windows installation is not supported.

@gunjansonaw
gunjansonaw force-pushed the docs/windows-docker-setup branch from f3cddd8 to 991e20c Compare September 2, 2026 16:36
Signed-off-by: Gunjan Sonawane <gunjansonawane462@gmail.com>
Comment thread docs/source/installation.rst Outdated
Comment on lines +123 to +138
Create ``docker-compose.override.yml`` with the configuration mount for the
application, scheduler, and both RQ workers::

services:
vulnerablecode:
volumes:
- .\vulnerablecode-config:/etc/vulnerablecode/
vulnerablecode_scheduler:
volumes:
- .\vulnerablecode-config:/etc/vulnerablecode/
vulnerablecode_rqworker:
volumes:
- .\vulnerablecode-config:/etc/vulnerablecode/
vulnerablecode_rqworker_high:
volumes:
- .\vulnerablecode-config:/etc/vulnerablecode/

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It might be a good idea to have a special Docker Compose file for Windows, docker-compose.windows.yml

Suggested change
Create ``docker-compose.override.yml`` with the configuration mount for the
application, scheduler, and both RQ workers::
services:
vulnerablecode:
volumes:
- .\vulnerablecode-config:/etc/vulnerablecode/
vulnerablecode_scheduler:
volumes:
- .\vulnerablecode-config:/etc/vulnerablecode/
vulnerablecode_rqworker:
volumes:
- .\vulnerablecode-config:/etc/vulnerablecode/
vulnerablecode_rqworker_high:
volumes:
- .\vulnerablecode-config:/etc/vulnerablecode/

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added the dedicated docker-compose.windows.yml override and updated the Windows instructions to use it explicitly.

Comment on lines -108 to -110
.. warning::
On **Windows** VulnerableCode can **only** :ref:`run_with_docker` and is not supported.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we need to remove that?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I retained and clarified the warning: native Windows installation is not supported, while Docker Desktop is supported. It now points to the Docker installation instructions.

Comment thread docs/source/installation.rst Outdated
Comment on lines +104 to +121
Create the configuration directory and environment file using PowerShell. The
following commands generate secure values for both required settings::

New-Item -ItemType Directory -Force .\vulnerablecode-config
$secretKeyBytes = New-Object byte[] 50
$rng = [System.Security.Cryptography.RandomNumberGenerator]::Create()
$rng.GetBytes($secretKeyBytes)
$secretKey = [Convert]::ToBase64String($secretKeyBytes)

$altchaKeyBytes = New-Object byte[] 32
$rng.GetBytes($altchaKeyBytes)
$altchaHmacKey = -join ($altchaKeyBytes | ForEach-Object { $_.ToString("x2") })
$rng.Dispose()

@"
SECRET_KEY="$secretKey"
ALTCHA_HMAC_KEY="$altchaHmacKey"
"@ | Set-Content .\vulnerablecode-config\.env

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please avoid generating any environment variables.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed the PowerShell secret-generation commands. The docs now show placeholder values only and tell users to replace them with unique secrets.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Gunjan Sonawane <gunjansonawane462@gmail.com>
@gunjansonaw
gunjansonaw force-pushed the docs/windows-docker-setup branch from 2237aa2 to f8ab85d Compare October 8, 2026 09:53
@gunjansonaw
gunjansonaw requested a review from ziadhany October 8, 2026 09:58

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants