Skip to main content
The enterprise appliance is the whole Fish Audio TTS stack — model weights included — in one container. It needs no Kubernetes and no network access at runtime, which makes it suitable for on-prem, single-tenant, and air-gapped deployments.
The appliance is part of an enterprise agreement. Your team needs the Self Host feature and a grant for the All-in-One artifact before the commands below will work. If Developer → Self Host does not appear in your dashboard, contact your account manager.

What you get

1. Prerequisites

  • Docker with the NVIDIA Container Toolkit installed and the nvidia runtime registered. Verify with docker run --rm --gpus all <cuda-image> nvidia-smi.
  • Enough disk for the image: roughly 28 GB compressed, 60 GB unpacked.
  • A deploy token, created in Developer → Self Host. That page also shows the version to run.

2. Sign in and pull

Your username is your Fish Audio account email; the password is a deploy token.
Developer → Self Host renders both of these commands with your email and the current version already filled in. Copy them from there rather than typing the version by hand.
For an air-gapped host, pull on a machine that can reach the registry, then move the image:

3. Run

Generate a JWT secret once, store it, and reuse the same value on every run.
JWT_SECRET is required for any production deployment. Without it the container falls back to a fixed built-in development default, which is not secret. Changing the value later invalidates every token and session issued under the old one.
--gpus all pins the worker to GPU 0 and the vocoder to GPU 1. On a host with more than two GPUs it takes the first two; to choose specific cards use --gpus '"device=0,1"'. -v fish-tts-shared:/mnt/shared is one persistent volume for everything that must survive a restart: the compile and CUDA-graph caches, the vocoder engine, reference voices, and the usage ledger. It is what makes restarts fast.
The first start compiles for around 10 minutes once the image is on the host. A completely cold host that also has to transfer the ~28 GB image can take 45–75 minutes end to end, depending on the network. Later starts on the same volume take minutes. Keep the volume.
The container runs fully non-root — PID 1 and every service as UID 1000. A fresh named volume inherits that ownership and works as-is; an existing volume or a host bind-mount must be writable by UID 1000.

4. Check it is serving

Upgrading

Developer → Self Host shows the version your team recorded and tells you when a newer one is available, with a link to what changed. Upgrading is: pull the new tag, stop the old container, start a new one with the same volume and the same JWT_SECRET.
The volume is reused deliberately: the caches in it are keyed by content, so a new image rebuilds only what actually changed. Keep the old image on the host until the new one has served traffic — rolling back is then just starting the previous tag again. See Appliance Releases for the version list.