Self-Hosted Timestamping with Docker: Timestamp GIT
If you are evaluating Docker self-hosted timestamping, you have already moved past the “why” and into the “which deployment fits our compliance and infrastructure requirements” conversation. The purchase decision is no longer about whether Git commit hashes should be anchored in Bitcoin. It is about where the anchoring pipeline runs: on Timestamp GIT’s managed infrastructure, or inside your own Docker environment. This guide covers exactly what you get with the self-hosted option, how it compares to the managed GitHub App, and what the cost-benefit picture looks like for developers, startups, agencies, and compliance teams.
Why Self-Host Your Git Timestamping?
Self-hosting makes sense when the default managed SaaS model creates friction for a specific audience — usually developers and compliance teams inside larger organizations. Three situations push teams toward a Docker deployment:
- Data sovereignty: You need all processing infrastructure to live in your own network, not on a third-party SaaS.
- Air-gapped or restricted environments: Your build servers or repository infrastructure cannot communicate with external services except for necessary public network calls.
- Internal compliance requirements: Your security team wants a self-contained audit trail, even if the cryptographic anchoring still relies on the public Bitcoin blockchain.
The managed Timestamp GIT GitHub App is the zero-setup option. You install it once, connect a repository, and every commit is automatically batched and anchored each night. The Docker self-hosted option retains that same automation but gives you the containerized application, the queue service, and the data volume inside your own infrastructure.
The core value does not change between deployment modes: Timestamp GIT produces cryptographic proof of prior art anchored in Bitcoin without ever reading your source code. In self-hosted mode, only commit hashes are processed and anchored. Source code never leaves your environment.
What You Get with Timestamp GIT Self-Hosted
The self-hosted version ships as a Docker image with a companion Valkey instance for queue management. A minimal docker-compose.yml looks like this:
services:
timestampgit:
image: rue1401/timestampgit:prod
ports:
- "8080:8080"
volumes:
- ./data:/app/data
restart: unless-stopped
valkey:
image: valkey/valkey:8
restart: unless-stopped
Start it with:
docker compose pull
docker compose up -d
docker compose logs -f timestampgit
After startup, the application is available at http://localhost:8080. On first launch, a setup wizard guides you through connecting your GitHub App and configuring the instance. That is the same first-run experience as the managed product, but the wizard writes configuration into your own volume.
Included in the self-hosted deployment are the same automation layers you get in the managed service:
- GitHub App integration — connect the app and monitor repositories automatically.
- Automatic nightly anchoring — commit hashes are collected, batched, built into a Merkle tree, and anchored into Bitcoin via the OpenTimestamps protocol.
- Verification badges — embeddable Shields.io badges for public status display.
- REST API — public status endpoints, audit CSV export, and PDF certificate download.
- Audit logs — a full audit ledger that can be exported as CSV.
The zero-knowledge architecture remains intact in self-hosted mode. Timestamp GIT never reads, copies, or stores your source code. The pipeline works only with Git commit hashes. In the Docker deployment, you control the container, the volume, and the network path, which gives compliance teams an additional layer of confidence that no source code leaves the environment.
Licensing for the Docker image is separate from the managed tiers. A time-limited demo license is available by submitting the request form on the Docker License page with your name, company, email, and optional phone number. After evaluation, production use requires a full license. The product page at https://timestampgit.dev/docker-license has the current request form and quick-start instructions.
Cost-Benefit and ROI of Self-Hosting
The managed pricing tiers are straightforward:
- Open Source — free, for public repositories.
- Pro Agency — $49/month, for private repositories.
- Enterprise ZK — $199/month, for GitHub Actions-based zero-knowledge mode.
The Docker self-hosted license is not a fixed price on the public pricing page. It is offered as a time-limited demo for evaluation, with production licensing handled through the vendor. The Enterprise ZK tier at $199/month may include self-hosting options, but exact terms should be confirmed with Timestamp GIT.
When comparing self-hosted versus cloud, the main trade-off is control versus maintenance overhead. The managed GitHub App removes all infrastructure burden: you install it once and the service handles batching, Merkle tree construction, OpenTimestamps proofs, and proof delivery. Self-hosting gives you the same automated pipeline, but you own the container, the Valkey instance, the data volume, and the upgrade schedule.
For teams that already run Docker in production, the marginal maintenance cost is often low. A small container and a Valkey queue do not add meaningful operational load. In return, you get:
- Full control over the timestamping pipeline — including where proof files are stored and how they are delivered.
- Cleaner compliance story — the application lives inside your network, which can simplify security reviews.
- No dependency on a third-party SaaS for repository access — although the GitHub App still uses GitHub’s permission system, the processing backend is yours.
The ROI of immutable prior art is easier to state in risk terms than in revenue terms. A single patent troll dispute can cost six figures before settlement. A single authorship dispute with a departing contractor can consume weeks of engineering and legal time. Timestamp GIT produces a .ots receipt that can be verified independently against the Bitcoin blockchain. That proof converts “we had this code at some point” into “this commit hash existed no later than this Bitcoin block.”
For startups, the value shows up during due diligence. A verifiable timestamp history strengthens an IP portfolio and shortens technical review. For agencies, proof of delivery dates removes payment-dispute ambiguity. For enterprises, self-hosting maintains the same proof capability while satisfying internal deployment policies.
Upgrade Path: From Cloud to Self-Hosted
The natural progression for many teams looks like this:
- Start with the free GitHub App on public repositories. Confirm that the nightly anchor workflow fits your development rhythm.
- Move to Pro Agency when private repositories need the same proof. The commit hash pipeline is identical; only repository visibility changes.
- Move to Docker self-hosting when compliance, data sovereignty, or internal infrastructure requirements demand it.
Migration does not invalidate existing proofs. The .ots receipt files and manifests from the managed service remain valid because they are anchored in Bitcoin. You are not migrating the proof; you are migrating the pipeline that creates future proofs. You can export existing proofs from the audit ledger and store them in your own infrastructure. After reconnecting repositories in the self-hosted instance, new commits continue to be anchored nightly. The timestamp history remains continuous, and the earliest anchor date stays intact.
A key point worth emphasizing: all Timestamp GIT proofs are vendor-independent. The underlying receipts are standard OpenTimestamps .ots files. They can be verified against Bitcoin block data without any Timestamp GIT server, API, or license. If the company disappears, if you move from cloud to self-hosted, or if you change deployment models again, the proofs remain valid.
For teams that want zero code access but are not ready to operate their own Docker deployment, the Enterprise ZK mode is the middle path. A 12-line GitHub Action runs on your infrastructure and pushes only the commit hash to the Timestamp GIT API. Timestamp GIT receives no read access to the source repository. That option gives you much of the data-minimization benefit of self-hosting without running the full containerized service.
Getting Started with Docker Self-Hosted Timestamp GIT
Start by obtaining a demo license from the Docker License page. Then create the docker-compose.yml shown above in a clean directory.
Pull and start the stack:
docker compose pull
docker compose up -d
Open http://localhost:8080 and follow the setup wizard. The wizard handles three main configuration steps:
- Connect your GitHub App. The self-hosted instance needs the same GitHub App integration as the managed product. The wizard will walk you through OAuth and installation.
- Select repositories. Mark which repositories should be monitored for automatic nightly timestamping.
- Confirm the nightly anchor schedule. The worker runs once per day, groups pending commit hashes, builds the Merkle tree, and anchors the root into Bitcoin. Confirmation typically takes a few hours.
Verify that the installation is working by checking the logs:
docker compose logs -f timestampgit
Then open the status dashboard for one of your connected repositories. You should see the earliest anchor date, Bitcoin block and transaction data, and a calendar heatmap of anchored days. Download a PDF certificate for any specific date as a first confirmation that the full proof path is working end to end.
If you need to expose the status publicly, use the badge embed endpoint. The self-hosted instance serves the same Shields.io-compatible badge data as the managed service.
FAQ
What are the system requirements for running Timestamp GIT in Docker?
Timestamp GIT runs as a Docker container with minimal resource usage. The provided docker-compose.yml includes the application and a Valkey instance for queue management. You need Docker Engine and Docker Compose installed on a Linux host or a compatible environment. The application listens on port 8080 by default and stores data in a mounted volume.
How does the self-hosted version handle Bitcoin anchoring?
The self-hosted version performs the same nightly anchoring process as the managed service. It collects commit hashes, builds a Merkle tree, creates OpenTimestamps proofs using public calendars, and anchors the Merkle root into the Bitcoin blockchain. The proofs are stored locally and can be pushed to your repository or kept in your infrastructure. Bitcoin confirmation typically takes a few hours.
Is the self-hosted license perpetual or subscription-based?
The Docker self-hosted license is available as a time-limited demo for evaluation. For production use, you need to request a full license from Timestamp GIT. The pricing page lists Enterprise ZK at $199/month, which may include self-hosting options; contact the vendor for exact terms.
Can I verify timestamps without relying on Timestamp GIT’s servers?
Yes. The proofs are standard OpenTimestamps receipts in .ots file format. They can be verified independently against the Bitcoin blockchain using OpenTimestamps-compatible tools. Timestamp GIT also provides a browser-based verification page that performs all computations locally, so verification never sends your repository data to a server.
Conclusion
Docker self-hosted timestamping with Timestamp GIT is the right purchase when you want the same zero-setup nightly anchoring pipeline as the managed GitHub App, but with the container, queue, and data volume under your own control. The self-hosted option keeps the core promise intact: cryptographically anchor Git commit hashes into Bitcoin, prove prior art, and never expose source code. The licensing model starts with a time-limited demo so you can validate the deployment before committing to production use.
Start with the demo license, run the compose stack, connect a repository, and check your first PDF certificate. If self-hosting turns out to be more infrastructure than you need, the managed GitHub App and Enterprise ZK mode remain available as simpler or lighter options.
Deploy Timestamp GIT on your own Docker infrastructure and make your commit history legally defensible.
Related posts
- How to Prove Software Authorship: A Guide for Developers
- How to Verify a Git Commit Timestamp
- Automatically Timestamp Git Commits with a GitHub App