Timestamp GIT Secure your prior art without exposing code

← All posts

2026-10-01

Self-Hosted Blockchain Timestamping with Docker

Self-Hosted Blockchain Timestamping with Docker
timestamp git blockchain proof

Self-Hosted Blockchain Timestamping with Docker

Self-hosting blockchain timestamping is a buying decision before it is an infrastructure decision. The question is not just “can we run this ourselves?” but “where do we want the trusted boundary to sit?” Timestamp GIT’s Docker self-hosted option is aimed at teams that want automatic Git commit anchoring into Bitcoin without handing the timestamping pipeline to an external SaaS — and without learning the underlying OpenTimestamps protocol. You install a Docker Compose stack, connect your GitHub App once, and let the same production build run on your own servers.

This article is for the commercial evaluation: what you get, how pricing compares, when self-hosting pays off, and how to move from the cloud SaaS to your own infrastructure.

Why Self-Host Your Blockchain Timestamping?

The managed Timestamp GIT SaaS already keeps your source code out of the pipeline. It works with commit hashes only, creates proofs, and anchors them into Bitcoin automatically each night. Self-hosting is not a fix for a privacy problem; it is a control decision.

Self-hosting makes sense when:

  • You need data residency guarantees. Commit hashes, manifest files, and proof receipts stay on infrastructure you own.
  • You operate in an air-gapped or heavily regulated environment where production services cannot depend on external SaaS uptime.
  • Your compliance team requires that timestamping artifacts never leave the corporate network before they are written to a repo you control.
  • You want to keep the same automatic nightly anchoring, API endpoints, verification badges, and Bitcoin-anchored proofs while owning the stack end to end.

With the cloud SaaS, Timestamp GIT operates the workers that batch hashes, build the Merkle tree, and submit the anchor. With the Docker image, you run that same production build yourself. The cryptographic result is identical: proof receipts anchored in Bitcoin that remain verifiable even if Timestamp GIT disappears.

If you are still comparing timestamping to ordinary Git logs, the proof-of-existence model is covered in What Is Proof of Existence for Software Code?. Self-hosting does not change that model; it changes who runs the automation.

What You Get with the Docker Deployment

The self-hosted deployment uses two services: the Timestamp GIT application and Valkey, an in-memory key-value store used for the pending hash queue.

A minimal Docker Compose setup looks like this:

services:
  timestampgit:
    image: rue1401/timestampgit:prod
    ports:
      - "8080:8080"
    volumes:
      - ./data:/app/data
    restart: unless-stopped
  valkey:
    image: valkey/valkey:8
    restart: unless-stopped

Start it with:

docker compose pull
docker compose up -d
docker compose logs -f timestampgit

Once the container is running, the application is available at http://localhost:8080. On first launch, a setup wizard guides you through connecting your GitHub App and configuring the instance.

The Docker image is the same production build used by the Timestamp GIT SaaS. That means the self-hosted version includes the core pipeline:

  • Automatic commit detection through the GitHub App or GitHub Action.
  • Nightly hash batching and manifest creation.
  • Merkle tree construction and Bitcoin anchoring through OpenTimestamps.
  • Proof delivery to a dedicated timestamps branch or shadow repository.
  • Public status endpoints, verification badges, audit CSV export, and PDF certificates.

The confirmation in the Bitcoin blockchain normally takes several hours, so proof writing is not instant. A midnight worker groups pending hashes and anchors the daily Merkle root. You can check the result with the status API:

curl http://localhost:8080/api/statusLast/your-org/your-repo

Pricing and Licensing for Self-Hosted

Timestamp GIT’s SaaS pricing is straightforward. The self-hosted license follows a different model: you request a time-limited demo license for evaluation, then obtain a full license for production.

Deployment Price in product information Best for
Open Source Free Public repositories and evaluation
Pro Agency $49/mo Private repositories, agency client work
Enterprise ZK $199/mo GitHub Actions workflow, no source repo read access
Docker self-hosted Demo license for evaluation; production license by request On-premises, air-gapped, regulated environments

The Docker License page describes the request form. To evaluate, you submit your name, company, email, and optional phone number. A time-limited demo license file is then available for download.

The product information does not specify whether a production self-hosted license is one-time or subscription-based. Treat that as a vendor-specific pricing conversation rather than an assumption. What matters for comparison is that the self-hosted license moves the SaaS operating cost from a monthly subscription to your own infrastructure budget.

If you do not need full infrastructure control, the SaaS tiers are usually the faster path. The GitHub App automation model gives you zero-setup timestamping without Docker, servers, or maintenance.

Cost/Benefit and ROI of Self-Hosting

The ROI of self-hosted blockchain timestamping depends on three variables: repository count, regulatory pressure, and the cost of proving prior art.

At small scale, the SaaS Pro Agency plan at $49/mo is difficult to beat. At larger scale, self-hosting can flatten costs because you are no longer paying for managed infrastructure per environment or per integration. The compose file runs a single application instance plus Valkey, so the main recurring costs become a server, storage for /app/data, network access during anchoring, and license maintenance.

The larger financial benefit is defensive. Cryptographic prior art matters when a patent troll claims something you built months or years earlier. Without an immutable timestamp, you may face expensive discovery, licensing negotiations, or litigation. For more on that specific risk, see Timestamp Git Commits to Defend Against Patent Trolls.

Self-hosting also reduces a different kind of dependency. If the managed SaaS has an outage, your nightly batch can be delayed. With self-hosted Timestamp GIT, you control when the worker runs and when it attempts the Bitcoin anchor. That does not remove the need for Bitcoin network connectivity, but it removes the external service as a single point of operational failure.

Operational costs to include in your ROI model:

  • Docker host resources and disk for persistent data.
  • License fee for production use.
  • Internal time for updates, backups, and container maintenance.
  • Network egress to GitHub and Bitcoin infrastructure.
  • Monitoring and log retention for the timestampgit and valkey services.

A useful decision framework:

  • Stay on SaaS if you are a small team, mostly need public-repo proofs, or do not have anyone responsible for Docker infrastructure.
  • Move to self-hosted if you run many repositories, need local data residency, operate air-gapped systems, or have compliance requirements that forbid external SaaS dependencies.
  • Run a hybrid if only some repositories are sensitive. Timestamp GIT supports monitoring different repos in different modes, so you can keep general work on the SaaS and route sensitive work to your own instance.

Upgrade Path: From Cloud to Self-Hosted

Existing Timestamp GIT cloud users can move to a self-hosted deployment without invalidating anything already anchored.

The reason is simple: all timestamps are anchored in the Bitcoin blockchain and are independent of the Timestamp GIT service. A proof receipt remains verifiable no matter where the worker originally ran.

A practical migration path:

  1. Export your existing proof receipts and verification data from the cloud status and verification pages or API endpoints.
  2. Deploy the Docker Compose stack on your own infrastructure.
  3. Complete the setup wizard and connect your GitHub App. The self-hosted instance can use the same GitHub App identity with the appropriate repository permissions.
  4. Re-add the repositories you want to monitor on the self-hosted instance.
  5. Run a test commit and confirm that the new instance writes proofs to the configured timestamps branch or shadow repository.

Because proof verification relies on Bitcoin block data and SHA-256, migrating does not require you to re-timestamp old commits. The old proofs stay valid. New commits are picked up by the self-hosted worker at the next nightly batch.

Getting Started with Self-Hosted Timestamp GIT

If you are evaluating the self-hosted route, start with the demo license.

  1. Request a time-limited demo license from the Docker License page. The form asks for name, company, email, and optional phone number.
  2. Download the license file and create a compose.yaml file with the timestampgit and valkey services shown above.
  3. Run docker compose pull to fetch the production image.
  4. Run docker compose up -d to start the stack.
  5. Open http://localhost:8080 and complete the first-launch setup wizard.
  6. Connect your GitHub App and select the repositories you want to monitor.
  7. Configure proof storage and verify that the instance can reach the target repository.

After configuration, test the installation:

docker compose logs -f timestampgit

Then create a test commit in a monitored repository:

git commit --allow-empty -m "test: verify self-hosted timestamp"

Wait for the nightly worker to run and for the Bitcoin anchor to confirm. The proof normally appears after a few hours. Check your dedicated timestamps branch or shadow repository for the manifest and .ots receipt file.

Common Docker issues and quick checks:

  • Port conflict on 8080: change the host-side port mapping in compose.yaml, for example "9090:8080".
  • Volume permission errors: make sure the ./data directory is writable by the container user.
  • No outgoing network during anchoring: the instance needs access to GitHub and Bitcoin network infrastructure at anchor time. If you run air-gapped, schedule anchoring for a connectivity window.
  • Valkey connection issues: start both services together with docker compose up -d and confirm that Valkey is healthy before restarting Timestamp GIT.

FAQ

Q: Can I run Timestamp GIT entirely offline or in an air-gapped environment?

A: Yes, the Docker self-hosted version is designed for air-gapped environments. You can run it on a server without internet access, but note that anchoring to the Bitcoin blockchain requires connectivity to the Bitcoin network. However, you can schedule the anchoring process to occur when connectivity is available, or use a local OpenTimestamps calendar if permitted.

Q: How does the self-hosted version differ from the cloud SaaS?

A: The self-hosted version gives you full control over the infrastructure and data. All processing, including hash batching and proof generation, happens on your servers. The cloud SaaS is managed by Timestamp GIT, requiring no server setup. Feature-wise, both offer automatic nightly anchoring, verification badges, and API access.

Q: Is the self-hosted license a one-time purchase or subscription?

A: The licensing model for the self-hosted Docker image is not specified in the provided information. A time-limited demo license is available for evaluation. For production use, you need to request a full license, and the terms — one-time or subscription — would be provided by the vendor.

Q: Can I migrate from the cloud SaaS to self-hosted without losing my existing timestamps?

A: Yes, because all timestamps are anchored in the Bitcoin blockchain and are independent of the service. You can export your proof receipts and verification data from the cloud and import them into your self-hosted instance. The proofs remain valid and verifiable.

Conclusion

Self-hosted blockchain timestamping with Docker is the right purchase when infrastructure control, data residency, or air-gapped operation outweighs the convenience of a fully managed SaaS. Timestamp GIT’s Docker image gives you the same automatic, zero-CLI workflow as the cloud product: connect the GitHub App once, let the nightly worker batch commit hashes, and receive Bitcoin-anchored proof receipts on your own infrastructure.

Start with the time-limited demo license, run the compose stack, and test the flow with a monitored repository. From there, you can decide whether to keep the cloud SaaS, move fully self-hosted, or run a hybrid that matches your compliance and cost model.

Get started with the demo license at Timestamp GIT.

Related posts

EU label: AI-generated content