Cloud-native geospatial server. One container exposes the same PostGIS-backed data through every major GIS protocol — GeoServices REST (FeatureServer, MapServer, ImageServer, Geometry, GPServer), OGC API (Features, Maps, Tiles, Coverages, Processes), classic OGC WMS/WFS/WMTS/WCS, STAC, OData v4, vector tiles (MVT/TileJSON), Terrain-RGB and elevation APIs, 3D Tiles, MCP for AI agents, and gRPC. ArcGIS Pro and Esri SDK clients connect unmodified; QGIS, MapLibre, Excel, and Power BI hit the same layers — no ETL, no duplication, no GDAL toolchain to install.
Honua Server is open core under the Elastic License 2.0. The GA-tier core (protocol surfaces, editing, imports, auth, operations) is production-ready and tracked on the public roadmap under the v1.0 (GA) milestone — upvote what you want next. Versioned v* releases have not been tagged yet; until the first one is cut, run the nightly-built container image (see Quick start). The server runs in Community mode with no license file; paid Pro/Enterprise features activate only via signed entitlements and are marked (Pro) / (Enterprise) below (see Editions and licensing).
Docker Compose (requires Docker with Compose v2):
git clone https://github.com/honua-io/honua-server.git && cd honua-server
docker compose up -d
docker compose psOpen http://localhost:8080/healthz/ready in a browser and wait for Ready.
The default docker-compose.yml builds the server image from source on first run, so expect the first up to take a few minutes; for an instant start use the pre-built image below. PostGIS, Redis, and Honua Server start automatically; migrations run on first boot. HTTP/1 REST and gRPC-Web are at http://localhost:8080, native h2c gRPC at http://localhost:8081. Continue with the quickstart to import a dataset and see it on a map, or add the web Console with docker compose --profile console up -d (set HONUA_CONSOLE_IMAGE to a honua-console image you have built or mirrored — no public Console image is published yet; Operate serves at http://localhost:5174/operate).
Pre-built image (bring your own PostGIS):
docker run -p 8080:8080 -p 8081:8081 \
-e ConnectionStrings__DefaultConnection="Host=host.docker.internal;Database=honua;Username=postgres;Password=postgres" \
-e HONUA_ADMIN_PASSWORD="change-me" \
-e Security__ConnectionEncryption__MasterKey="change-me-random-string-32-plus-characters" \
honuaio/honua-server:nightly:nightly (also tagged :trunk) is rebuilt from trunk every night; pin a specific build with :nightly-YYYYMMDD. The :latest tag is only promoted on tagged v* releases and will resume meaning "latest release" once the first release is cut.
Kubernetes — deploy with the Helm chart in honua-helm; see the Kubernetes guide.
Local development — .NET Aspire with a dashboard for traces, logs, and metrics:
dotnet run --project src/Honua.AppHostTo run geoprocessing jobs locally (in-process, no cloud), use the local GP dev quickstart. For self-hosted pilots, run the pilot onboarding runbook before handing a deployment to another team.
Every published layer is reachable through every protocol its service enables. The canonical matrix with examples lives in Protocols.
| Protocol | Endpoint | Typical clients |
|---|---|---|
| GeoServices FeatureServer | /rest/services/{id}/FeatureServer |
ArcGIS Pro, Esri SDKs, Esri Leaflet |
| GeoServices MapServer | /rest/services/{id}/MapServer |
ArcGIS Pro, Esri map clients |
| GeoServices ImageServer | /rest/services/{id}/ImageServer |
ArcGIS raster workflows |
| GeoServices Geometry Service | /rest/services/Utilities/Geometry/GeometryServer |
Esri SDKs (buffer, project, intersect, …) |
| GeoServices GPServer | /rest/services/{id}/GPServer |
ArcGIS Pro, async geoprocessing clients |
| GeoServices GeocodeServer | /rest/services/{locator}/GeocodeServer |
Esri geocoding clients (findAddressCandidates) |
| GeoServices VectorTileServer | /rest/services/{id}/VectorTileServer |
Esri vector-tile clients, ArcGIS SDKs |
| GeoServices NAServer (Pro) | /rest/services/{id}/NAServer |
Esri routing / network-analysis clients |
| GeoServices VersionManagementServer (Enterprise, experimental) | /rest/services/{id}/VersionManagementServer |
Esri branch-versioning editing workflows |
| Portal token issuance | /sharing/rest/generateToken |
Esri clients using username/password tokens |
| OGC API Features | /ogc/features |
QGIS, GDAL, OpenLayers, any OGC client |
| OGC API Maps | /ogc/maps |
OGC map clients |
| OGC API Tiles | /ogc/tiles |
QGIS, MapLibre |
| OGC API Coverages | /ogc/coverages |
Science and raster tooling |
| OGC API Processes | /ogc/processes |
OGC processing clients |
| OGC API Records | /ogc/records |
Catalog / metadata search clients |
| OGC API Environmental Data Retrieval (EDR) | /edr |
Environmental and scientific data clients |
| OGC API Styles | /ogc/styles |
Style-aware map clients |
| OGC SensorThings v1.1 | /sta/v1.1 |
IoT / observations clients |
| WMS 1.3 / 1.1.1 | /ogc/services/{id}/wms, /rest/services/{id}/MapServer/WMS |
QGIS, legacy OGC clients |
| WFS 2.0 / 1.1.0 / 1.0.0 | /wfs |
QGIS, GDAL/OGR, legacy stacks |
| WCS 2.0.1 | /ogc/services/{id}/wcs, /rest/services/{id}/ImageServer/WCS |
Science, elevation, coverage clients |
| WMTS 1.0 | /ogc/services/{id}/wmts, /rest/services/{id}/MapServer/WMTS |
QGIS, legacy tile clients |
| WPS 2.0 | /wps |
Classic OGC processing clients |
| OData v4 | /odata |
Excel, Power BI, Tableau, SAP |
| STAC API | /stac |
STAC browsers, catalog/search tooling |
| Vector tiles (MVT) + TileJSON | /tiles/{layerId}/{z}/{x}/{y}.mvt, /tiles/{layerId}/tile.json |
MapLibre, OpenLayers, Leaflet |
| Terrain-RGB + elevation API | /terrain/{datasetId}/…, /elevation/{datasetId}/… |
MapLibre raster-dem, field apps |
| 3D Tiles scenes | /scenes/{sceneId}/tileset.json |
CesiumJS, 3D Tiles clients |
| PMTiles | /api/v1/tiles/pmtiles/{artifactId} |
MapLibre, serverless/CDN tile hosting |
| MCP (JSON-RPC) | /mcp |
AI agents, operator automation, MCP clients |
gRPC (geospatial.v1) |
port 8081 (h2c), gRPC-Web on 8080 |
Honua SDKs, mobile, services |
Surfaces marked (Pro) / (Enterprise) require a signed license; everything unmarked is Community. The machine-readable capability vocabulary behind this table is docs/gis/data/capability-keys.v1.json (generated from CapabilityKeyCatalog.cs) — keep the table in sync with it.
Plus operational surfaces: health probes (/healthz/live, /healthz/ready), OpenAPI documents per OGC API, an interactive API explorer at /docs (dev mode or HONUA_SERVE_API_DOCS=true), the admin API (/api/v1/admin), and a capability manifest (/api/v1/capabilities/manifest) for clients to discover what a deployment supports.
- OGC CITE: 1117 / 1117 passing across 13 conformance suites (OGC API Features 1.0, OGC API Tiles 1.0, GeoPackage 1.2, GML 3.2, KML 2.2, WFS 1.0/1.1/2.0 plus WFS 2.0 Transactional, WCS 2.0, WMS 1.1.1/1.3, WMTS 1.0) as of the 2026-07-27 evidence run — see docs/cite-status.md for the authoritative snapshot and OGC conformance evidence for suite-by-suite evidence.
- Client compatibility: the supported client x protocol matrix — including known limitations — is the compatibility contract; Esri-side parity is tracked in GeoServices parity.
- gRPC stability: versioning, deprecation, and stability guarantees for the
geospatial.v1surface are defined in the gRPC reference. - Control plane stability: admin/control-plane API versioning is governed by versioning and support.
- Query and edit — FeatureServer query/applyEdits/attachments/related records, OGC API Features CRUD with CQL2, WFS 2.0 transactions, OData CRUD with spatial functions (
geo.distance,geo.intersects,$batch). FeatureServer applyEdits is (Pro); edits through the open protocols (OGC API Features, WFS-T, OData, gRPC) stay Community. Output as JSON, GeoJSON, PBF, FlatGeobuf, GeoParquet, and GeoArrow. - Esri migration and coexistence — ArcGIS Pro and Esri SDK clients connect unmodified. Import public ArcGIS REST and GeoServer services into PostGIS (service imports are (Enterprise)); scan ArcGIS Server and GeoServer for deterministic migration inventories. See Migrate from ArcGIS Server and from GeoServer.
- No GDAL required on the server — import GeoJSON, Shapefile (zip), GeoPackage, GPX, KML, WKT, FlatGeobuf, File Geodatabase (
.gdb.zip), and GeoParquet directly, with CRS auto-detection and PostGIS reprojection; the serving container ships no GDAL, while optional geoprocessing worker images bundle it separately. - Rendering and rasters — MapServer export/identify/legend, OGC API Maps, ImageServer, WCS, OGC API Coverages, cloud-optimized GeoTIFFs registered in place from S3/Azure, and server-generated Terrain-RGB elevation tiles.
- Geoprocessing and workflows — one canonical async job runtime behind GPServer, OGC API Processes, gRPC, and MCP; declarative multi-step DAG workflows with retries and cron scheduling (Redis required for durable jobs).
- AI-operable — the
/mcpsurface implements the open geospatial-mcp standard so agents can validate plans, dry-run, execute, and read results with the same authorization as any other client. MCP discovery/query and spec artifacts are Community; agent operations and spec-apply execution are (Pro); approval workflows are (Enterprise). See Connect AI agents. - Cloud-native operations — container-first and stateless; multi-layer caching with in-memory fallback (output cache and Redis caching are (Pro)); OpenTelemetry traces and metrics; API-key auth, OIDC SSO (Pro) — multi-provider OIDC, SAML 2.0, and SCIM 2.0 are (Enterprise) — and experimental mTLS client-certificate auth (off by default, not on the GA path); a server-computed operate loop for humans, Console, and agents (Operating Honua).
The admin API (/api/v1/admin) manages connections, services, layers, styles, and import jobs; the web admin UI lives in honua-console. The admin API is also the substrate for Honua's managed control-plane direction — change management and instance lifecycle workflows build on it rather than on a third-party GitOps controller.
PostGIS is the primary read/write backend. Additional providers serve data in place, read/query-only, through the same protocol surfaces:
| Provider | Access |
|---|---|
| PostGIS | Full read/write (default) |
| DuckDB | Read-only, embedded — analytics and reference layers, no external database |
| SQL Server | Read/query-only (geometry/geography tables) |
| Oracle | Read/query-only (standard SDO_GEOMETRY) |
| MySQL / MariaDB | Read/query-only (MySQL 8.0.11+, MariaDB 10.6+) |
| Amazon Redshift | Read/query-only (native Redshift spatial) |
| Snowflake | Read/query-only (GEOGRAPHY/GEOMETRY) |
| Databricks | Read/query-only (SQL Warehouse, best-effort) |
Per-provider capabilities, selection variables, and limitations are in the data sources reference.
All settings are environment variables. Copy .env.example for a full annotated reference, or see the environment variable reference.
Required (PostgreSQL provider — default):
ConnectionStrings__DefaultConnection="Host=postgres;Database=honua;Username=postgres;Password=postgres"
HONUA_ADMIN_PASSWORD="change-me"
# Encrypts stored data-connection credentials (>=32 chars). Required outside
# Development — startup fails without it; in dev, registering a data
# connection fails until it is set.
Security__ConnectionEncryption__MasterKey="change-me-random-string-32-plus-characters"Common options:
ConnectionStrings__Redis="localhost:6379" # shared caches; required for durable jobs/workflows
HONUA_OBSERVABILITY=true # metrics endpoints (health probes are always on)
HONUA_OPENTELEMETRY=true # distributed tracing
Cors__AllowedOrigins__0="https://app.example.com"Production tuning — bounded database admission is the default production posture: keep Limits__Connections__MaxConcurrentQueries aligned with the pool size and size from the shared database budget across replicas (small 4-vCPU nodes profile best in the 4–6 active-query range; larger pools can overfeed PostGIS and worsen tail latency). Adaptive admission (Limits__Connections__AdaptiveConcurrencyEnabled) is an explicit tuning profile, not the default — monitor /monitoring/metrics/connection-pool and keep fixed-cap results as the baseline. Full guidance: Scale and tune performance and admission and pooling variables.
Invalid configuration fails startup with a detailed error message.
Full hosted documentation: honua.gitbook.io/honuaio. The in-repo table of contents is docs/README.md. Frequent destinations:
| I want to… | Go to |
|---|---|
| Import a dataset and see a map in 10 minutes | Quickstart |
| Deploy to production | Docker Compose · Kubernetes · Cloud deployments |
| Operate, monitor, back up, scale | Operating Honua · Monitoring |
| Connect a client | ArcGIS Pro · QGIS · Excel/Power BI · MapLibre · AI agents (MCP) |
| Migrate from Esri or GeoServer | From ArcGIS Server · From GeoServer · ArcGIS apps and SDKs |
| Understand the architecture | Architecture · Protocols · Data model |
| Use the admin API | Control plane API |
| Check client compatibility | Compatibility contract |
| Contribute code | Contributing · AGENTS.md |
Honua is a family of repos around this server — the full map is in Ecosystem:
- honua-console — web console (Studio, Catalog, Operate, Share) over the admin API; the admin/UI home
- honua-helm — Helm chart, the Kubernetes deploy path
- honua-sdk-js · honua-sdk-python · honua-sdk-dotnet — client SDKs generated from the same admin contract
- honua-mobile — Experimental reusable .NET MAUI SDK and map/control foundation for offline field workflows (Apache-2.0)
- honua-collect — Experimental full end-user field-collection app built on
honua-mobile(ELv2) - geospatial-grpc — open gRPC protocol standard the server's
geospatial.v1surface implements - geospatial-mcp — open geospatial MCP standard behind
/mcp
GitHub Issues are the primary feedback loop. Please use the forms so reports include enough detail for triage:
- Report a bug (include screenshots and repro steps)
- Request a feature — or upvote existing roadmap items
- New ideas start in Discussions → Ideas; popular ideas graduate to roadmap issues
See SECURITY.md for how to report a vulnerability privately, response targets, and the coordinated-disclosure policy. Do not open public issues for suspected vulnerabilities.
Elastic License 2.0 (ELv2) — free to use, deploy, and modify, within the ELv2 limitations: you may not provide Honua to third parties as a hosted or managed service, may not circumvent the license-key functionality, and may not remove or obscure the licensor's notices.