Skip to main content

Overview

The on-prem collector is a lightweight agent that runs within your network. It clones repositories, analyzes commits using an LLM, and streams only structured metadata (knowledge graphs, summaries, metrics) back to the Navigara cloud. Source code never leaves your infrastructure. The collector connects to the Navigara API over a persistent gRPC stream. It receives work assignments (which repos/commits to analyze), processes them locally, and sends back structured results. If the connection drops, it automatically reconnects with exponential backoff and replays any buffered results.

Prerequisites

  • Docker Engine 24+ and Docker Compose v2+ on a Linux host (Ubuntu 24.04 LTS or Debian 13+ recommended)
  • Network access to your Git repositories (GitHub, GitLab, Bitbucket, or self-hosted)
  • Outbound HTTPS to the Navigara API (app.navigara.com:443)
  • LLM API endpoint — see LLM Configuration below

Hardware Requirements

Disk is used for temporary Git clones during analysis. The collector caches cloned repositories to speed up subsequent analyses — SSD storage is recommended.

Git Provider Authentication

The collector supports multiple authentication methods depending on your Git provider and security requirements. All credentials are configured in the Navigara dashboard and forwarded to the collector on demand over the encrypted gRPC stream — no static Git tokens are stored on the collector host. Install the Navigara GitHub App on your GitHub organization. The Navigara cloud automatically generates short-lived installation tokens and sends them to the collector over the gRPC stream. No static credentials are stored on the collector. How it works:
  1. Install the Navigara GitHub App on your GitHub organization (or specific repositories)
  2. Add the repositories in the Navigara dashboard
  3. The backend generates scoped installation tokens on demand and sends them to the collector
  4. Tokens are short-lived and automatically rotated
Advantages:
  • No static tokens to manage or rotate
  • Fine-grained repository access (select specific repos during app installation)
  • Works with both GitHub.com and GitHub Enterprise
This is the recommended approach for GitHub users.

Option 2: Provider Tokens, End-to-End Encrypted (All Providers)

For any provider not covered by the GitHub App, use a personal access token — encrypted end-to-end so that Navigara can never read it. You generate a keypair on the collector host, encrypt the token locally, and paste the resulting blob into the dashboard. Navigara stores and forwards that blob verbatim — there is no server-side key and no server-side decryption. The collector holds the private key and decrypts each token in memory, only at the moment it authenticates to the Git host. The plaintext token and the private key never leave your network.
This applies to the on-prem collector specifically. In a full on-premises deployment the entire platform already runs inside your network, so the token never leaves your infrastructure regardless — paste it directly without the encryption steps.
1

Create a personal access token

Create a fine-grained personal access token with:
  • Repository access: Select the repositories you want to analyze
  • Permissions: Contents (read), Pull requests (read), Metadata (read)
2

Generate a keypair on the collector host

Writes private.pem (mode 0600) and public.pem to /opt/navigara/keys, and prints the key fingerprint. Keep private.pem on this host — it is never shared.
3

Give the collector the private key

Mount the key and set COLLECTOR_PRIVATE_KEY_PATH in your docker-compose.yml, then restart:
4

Encrypt the token

Copy the navigara-enc-v1:… blob it prints.
5

Paste the blob into the dashboard

Add the blob as the provider token under Settings → Connections → Source control when connecting your Git account. Navigara stores it as-is and your next analysis run uses it automatically.
Switching an existing connection over to encryption? Mint a fresh PAT at your Git host, encrypt it, paste the blob, then revoke the old token — a clean rotation with no downtime.
The collector can load several private keys at once (comma-separate paths in COLLECTOR_PRIVATE_KEY_PATH, or use COLLECTOR_PRIVATE_KEY_PEM for inline PEM) and selects the matching key per blob by fingerprint, so you can roll a new key before re-encrypting old tokens. If a blob can’t be decrypted — wrong key, tampering, or a paste error — the collector drops it and fails the task loudly; it is never forwarded to the Git host.
For the full collector CLI reference (keygen, encrypt-token, decrypt-token) and key rotation, see Encrypted Git Tokens.

Installation

1. Prepare the host

2. Generate a Collector API Token

In the Navigara dashboard, go to Settings → API Tokens and create a new API token. This token authenticates the collector with the Navigara backend. Copy it — you’ll need it in the next step.

3. Configure the deployment

Create the deployment directory:
Create docker-compose.yml:
Create a .env file:

LLM Configuration

Navigara requires an LLM API endpoint for AI-powered commit analysis. Supported providers:

4. Start the collector

Verify the collector is running and connected:
You should see output indicating a successful connection:

5. Add repositories

Once the collector is running, add repositories through the Navigara dashboard:
  1. Go to Settings → Repositories → Add Repository
  2. Select your Git provider and authenticate (if using cloud-managed tokens or GitHub App)
  3. Select the repositories to analyze
  4. The collector will automatically begin processing

Configuration Reference

Running Multiple Collectors

You can run multiple collector instances for higher throughput or geographic distribution. Each collector must have a unique COLLECTOR_ID. The Navigara backend distributes work across connected collectors with affinity routing — it prefers sending work to a collector that already has a repository cached locally.

Network Requirements

The collector host must have outbound access to the following services:
No inbound ports need to be opened. The collector initiates all connections outbound.

Upgrades

The collector is stateless — it can be stopped and restarted at any time without data loss. In-progress work is automatically reassigned by the Navigara backend.

Troubleshooting