Requirements
Nova runs as a container with a PostgreSQL database and is used in the browser. Nothing needs to be installed on workstations. The installation steps are described in Installation.
Runtime environment
| Component | Requirement |
|---|---|
| Platform | a server with Docker Engine and Docker Compose v2, or a cluster in SAP BTP, Kyma runtime |
| Database | PostgreSQL 16; the supplied templates run it as a container of its own |
| Application | Python 3.12 inside the image; the user interface is built when the image is built |
| User access | HTTPS through an upstream TLS proxy or the Kyma gateway |
When the image is built, Docker pulls the base images for Node.js and Python as well as packages from the Debian, npm and PyPI repositories. The machine that builds the image needs access to these sources.
A single instance
Nova runs as exactly one instance with one Gunicorn worker (GUNICORN_WORKERS=1). Nova keeps the scheduler for background jobs and the state of running jobs in its process; a second instance or a second worker would run scheduled jobs twice. Nova handles more load through threads (GUNICORN_THREADS, default 8).
Sizing
There is no binding sizing recommendation. Points of reference:
- The Kyma template is sized for a demo installation. It reserves 0.2 CPU and 384 MiB of memory for Nova with a limit of 1 CPU and 1 GiB, 0.1 CPU and 256 MiB for PostgreSQL with a limit of 0.5 CPU and 512 MiB, plus 2 GiB of storage for the database.
- Nova opens up to 30 connections to the database.
Network
Nova opens the connections to the target systems itself. Only the routes to the systems actually connected need to be allowed:
| Destination | Protocol and usual ports |
|---|---|
| SAP (ABAP) | RFC to the gateway of the application server, port 33‹system number›; when logging on through the message server, its port as well; optionally through a SAProuter |
| Active Directory, LDAP | LDAPS (636) or LDAP (389) |
| Microsoft Entra ID | HTTPS (443) to Microsoft sign-in and Microsoft Graph |
| Keycloak | HTTPS to the realm's sign-in and admin interfaces |
| SCIM applications | HTTPS to the application's SCIM endpoint |
| SMTP, by default port 587 with STARTTLS | |
| AI, optional | HTTPS to the cloud provider, or a connection to a self-hosted Ollama server |
The same routes apply when a system serves as a source system – for example an LDAP directory with HR data, or SAP organisational data over RFC. Details on each connection are in Target systems – Overview.
SAP: the customer's RFC SDK
For SAP, Nova uses the SAP NetWeaver RFC SDK. It is SAP software and not part of the standard image: the image from deploy/Dockerfile is built without the SDK, and SAP functions stay switched off in it. To connect SAP, the operator provides the SDK for Linux and adds it to the image together with the Python package pyrfc.
Email
Nova needs an SMTP server for notifications. It is set up under “Administration” → “Notifications” → “Email (SMTP)”. If nothing is stored there, Nova uses the environment variables NOVA_SMTP_*; at least NOVA_SMTP_HOST and NOVA_SMTP_FROM_ADDRESS are then required.
Environment variables
| Variable | Meaning |
|---|---|
SECRET_KEY | Required. Key for sign-in sessions. If it is missing, Nova generates a new one on every start, and everyone has to sign in again after each restart. The Compose template does not start without it. |
NOVA_ENCRYPTION_KEY | Required. Key Nova uses to encrypt stored credentials. Why it must be kept separately is explained in Updates and backup. |
DB_HOST, DB_PORT, DB_NAME, DB_USER, DB_PASSWORD | Database connection |
TRUST_PROXY, SESSION_COOKIE_SECURE | both set to 1 behind a TLS proxy |
Optional variables include NOVA_TIMEZONE – the time zone Nova uses to determine the calendar day for validity dates, default Europe/Berlin –, NOVA_SMTP_*, and CLAUDE_API_KEY or OPENAI_API_KEY for a cloud provider's AI. RUN_DUMMIES starts demo target systems inside the container and stays at 0 in production.