You can find the detailed documentation about the Docker installation in the OpenCTI documentation space.
This stack bundles XTM One, Filigran's AI-powered assistant, alongside OpenCTI. The following services are started by default:
| Service | Description |
|---|---|
xtm-one |
XTM One platform (web UI + API, exposed on XTM_ONE_PORT) |
xtm-one-worker |
XTM One background worker |
pgsql-xtm-one |
Dedicated PostgreSQL + pgvector instance for XTM One |
XTM One reuses the shared redis and minio services and connects to OpenCTI internally via OPENCTI_API_URL. OpenCTI registers itself with XTM One using PLATFORM_REGISTRATION_TOKEN — this shared secret must be identical across every platform connected to the same XTM One instance.
All XTM One configuration (admin credentials, dedicated Postgres credentials, S3 bucket, license, log settings) lives in the XTM ONE section of .env.sample. Once the stack is healthy, XTM One is available on http://localhost:${XTM_ONE_PORT} (default 8090).
Each product has two URLs in this stack:
- the public URL you open in your browser, built from
OPENCTI_EXTERNAL_SCHEME/OPENCTI_HOST/OPENCTI_PORTandXTM_ONE_EXTERNAL_SCHEME/XTM_ONE_HOST/XTM_ONE_PORT(set the scheme tohttpstogether with the host when you publish them over TLS). It is also the identity each product signs its requests to the other with, so it is set on both XTM One containers (BASE_URL) and on OpenCTI (APP__BASE_URL); - the internal URL the containers reach each other on:
http://opencti:8080(OPENCTI_API_URLon XTM One) andhttp://xtm-one:4000(XTM__XTM_ONE_URLon OpenCTI).
The public host name does not need to resolve inside the containers: XTM One fetches OpenCTI's signing keys on the internal URL, and OpenCTI reads XTM One's public identity from http://xtm-one:4000/xtm/auth/metadata. This needs XTM One and OpenCTI releases that include XTM-One-Platform/xtm-one#4883 and OpenCTI-Platform/opencti#18585.
If OpenCTI registers with XTM One but every assistant action on OpenCTI data fails with 401, the XTM One logs (XTM JWT rejected) and the OpenCTI logs (JWT issuer is not trusted) name the URL that did not match.
Currently OpenCTI is under heavy development, if you wish to report bugs or ask for new features, you can directly use the Github issues module.
If you need support or you wish to engage a discussion about the OpenCTI platform, feel free to join us on our Slack channel. You can also send us an email to contact@opencti.io.
OpenCTI is a product designed and developed by the company Filigran.
