Skip to main content

Outline

Outline is a collaborative knowledge base for handbooks, product documentation, operating procedures, and internal guides. Teams can organize documents into collections, edit together, search across knowledge, and share selected content.

Before You Deploy​

Outline requires an OpenID Connect identity provider. Create an OIDC client in your company identity system and collect these values:

  • Client ID and client secret
  • Authorization endpoint
  • Token endpoint
  • User information endpoint
  • Username claim and scopes, when they differ from your provider's defaults

The redirect URL is:

https://<your-outline-domain>/auth/oidc.callback

When your identity provider requires the exact domain, prepare the client first, deploy Outline, then add the generated Moltern URL to the client's allowed redirect URLs before the first sign-in. Keep the client secret in a password manager and never put it in source control or a screenshot.

Deploy Outline​

  1. Open Services, search for Outline, and select Deploy.
  2. Choose the environment and enter a recognizable service name.
  3. Enter the OIDC client values and the label people should see on the sign-in button.
  4. Review the required PostgreSQL and Redis services. Create dedicated services for an isolated knowledge base, or select compatible existing services intentionally.
  5. Review Capacity and scaling, then select Preview deploy.
  6. Confirm the parent service, dependencies, and storage impact and deploy.
  7. Add the generated callback URL to your identity provider, then open Outline.

The first start waits for both dependencies and prepares the application schema. Follow Live Logs when initialization takes longer than expected instead of starting a second deployment.

Complete The First Sign-In​

  1. Select the company sign-in button on the Outline welcome screen.
  2. Authenticate with an identity that is allowed to use the OIDC client.
  3. Review the profile claims returned by the provider before accepting the first owner account.
  4. Open workspace settings and confirm the workspace name, permitted domains, default language, and member invitation policy.
  5. Invite a test member and confirm that sign-in, sign-out, and account removal behave as expected before inviting the wider team.

Use groups and roles from the identity provider where your Outline edition and provider support them. Do not share the owner account.

Build The Knowledge Base​

Create collections around stable responsibilities rather than temporary projects. A practical first structure is:

  • Company handbook
  • Product and engineering
  • Customer operations
  • Sales and support playbooks
  • Security and incident response

Create one representative document with headings, links, images, callouts, and a table. Ask another member to edit it, then confirm revision history, search, comments, and collection permissions before importing more content.

Connect Applications And Agents​

Use Outline's supported API and integration settings for automation. Create a dedicated token or integration identity with only the required access and keep its credential in the consuming workload's protected configuration.

Do not give an application or coding agent the owner session. Limit it to the collections and actions it needs, and rotate the credential when access changes.

Capacity, Persistence, And Cleanup​

Documents, members, and permissions are stored in PostgreSQL. Collaboration and short-lived coordination use Redis. Images and attachments use workspace storage. Stopping and starting Outline should preserve all three; stopping is not a backup.

Resize Outline and its dependencies independently when usage changes. Schedule stateful maintenance outside active editing windows, then verify sign-in, a representative document, search, and an attachment. Review Billing for the parent service, both dependencies, and stored data.

Export important collections before deletion. The protected delete flow lets you remove stored data or retain workspace files. Retained files continue to count toward storage usage. Auto-provisioned dependencies are removed with the parent when they are not shared by another workload.

Troubleshooting​

SymptomWhat to check
No sign-in button appearsConfirm every required OIDC value is present in service settings, then restart the service.
The provider rejects the callbackAdd the exact generated /auth/oidc.callback URL to the OIDC client's allowed redirects.
Sign-in returns to the welcome pageConfirm the client secret, token endpoint, scopes, and user information endpoint.
A member is created without a useful nameCheck the username claim and ensure the provider returns profile and email claims.
Attachments failReview workspace storage capacity and the service logs, then retry with a small file.
The service does not become readyCheck that PostgreSQL and Redis are running and review the latest deployment stage.