Google Cloud
Cloud Run and Cloud SQL provide the recommended cloud architecture, with separate migration, runtime, and scheduled cleanup responsibilities.
Read the deployment guideSelf-hosting
Two maintained deployment paths
Both packages use the same product capabilities and database model. The difference is how your institution provisions, scales, and supports the service.
Cloud Run and Cloud SQL provide the recommended cloud architecture, with separate migration, runtime, and scheduled cleanup responsibilities.
Read the deployment guideA Linux VPS runs the same application image with PostgreSQL 17, public HTTPS ingress, secrets, migrations, cleanup, and backups.
Read the deployment guideShared release architecture
What self-hosting includes
Installation is one part of a dependable service. Plan the application, Canvas, devices, and exam-window support as one implementation.
Deploy the released image, run migrations before traffic, monitor readiness, back up PostgreSQL, and plan upgrades and rollback.
Create the LTI and API OAuth keys, install the app at account scope, configure the deployment ID, and load the detector script.
Distribute the private certificate identity for the strongest device binding or explicitly choose compatibility mode for BYOD devices.
Own student readiness, instructor questions, exam-window response, incident handling, and coordination with Canvas and device teams.
Managed fleets and BYOD
For managed devices, distribute the private certificate identity through MDM to bind the downloaded configuration to approved clients. If that is impractical for personal devices, compatibility mode is a supported choice that preserves the remaining launch, proof, URL, and lockdown controls.
Make the device decision before rollout
Release package
Download the Cloud Run or Docker Compose bundle, review its checksums and provenance, and follow the operator documentation for setup and verification.
Managed hosting provides the same capabilities with the service operation handled for your institution.