Skip to main content
Upstream source: Current installation guide. SearXNG can load its bundled default settings and override the signing key and URL through environment variables, so a configuration file is not needed for this first instance. The cache volume keeps its local cache. Public bot protection needs Valkey and an explicitly configured limiter; do not treat this minimal setup as a public search service.

Towbar manifest

.towbar/services/searxng.service.yml

Configure

  1. Prepare the example server, connect the repository, and map production to the branch containing these manifests. Replace the example server IP. Commit the manifests, then sync the repository and inspect the resolved configuration.
  2. Set the Service’s declared runtime values under Service → Settings → Secrets using the table below. Replace descriptions and placeholders with actual values; do not commit passwords or keys.
  3. Keep the Service’s named volumes attached across deployments. Towbar’s Datastore backup policy does not back up Service volumes, so include them in your own recovery plan.
  4. This manifest has no public domain. Use a trusted connection to the server for the first check. Add a public route only after configuring the product’s authentication or an access gateway.
  5. Deploy the Service, then perform the checks below before enabling auto-deploy.

Runtime values

Save these values on the Service after the repository sync. The manifest declares required keys, not their values.

Verify

Run a search from a trusted connection. Before assigning a public domain, configure the upstream Valkey-backed limiter or an access gateway and verify that the base URL matches the route. For field constraints, see Service manifest.
Last modified on September 27, 2026