Step 1 of 8 · Docker
Linux with Docker
Copy link to the page “Linux with Docker”The installation script puts the appliance in a container on your Linux server and installs a small host controller alongside it. The appliance answers on port 8443. You keep the server’s operating system and Docker up to date yourself.
Before you start
Copy link to the section “Before you start”- A Linux server with 4 GB RAM and 20 GB of free disk space.
- Docker 24.0 or later with Docker Compose v2, and Python 3. If Docker is missing, the script offers to install it.
- root, or a user with sudo.
Run the installation script
Copy link to the section “Run the installation script”-
Log in to the server as the user who is to own the installation.
-
Run the script:
Terminal window bash <(curl -fsSL https://sslbrain.com/install.sh) -
Answer the questions. The default answer is yes. If the script adds your user to the
dockergroup, it stops afterwards: log out and back in, and run the script again. -
Wait while the script downloads the appliance, checks the signature and starts it. This takes up to 5 minutes.
-
The script ends with the address:
sslbrain is running.Open https://<host-ip>:8443/setup in your browser to continue.
The script takes no code or licence. The appliance is licensed from its own web interface.
First boot
Copy link to the section “First boot”-
Open
https://<appliance-address>:8443/setupin a browser. -
The browser warns about the certificate, because the appliance has created a self-signed certificate. Continue to the page.
-
The setup wizard starts with Log in with sslbrain Cloud.
Every address for the appliance must include the port, for example https://sslbrain.example.com:8443. Continue with 2. First-time setup.
If it fails
Copy link to the section “If it fails”- The script stops with code 2: something is missing on the server. Install what the script names, and run it again.
- The script stops with code 4: the appliance did not answer within 5 minutes. Read the appliance’s log with
docker logs sslbrain, and the host controller’s log indata/control/controller.log. - The browser cannot open the appliance:
docker psmust show thesslbraincontainer with the statushealthy. Browsers and service agents must be able to reach the server on port 8443. - The container keeps restarting with “Permission denied” on
/data: thedatadirectory is not owned by user 1000. Runsudo chown -R 1000:1000 ~/sslbrain/data. - The appliance cannot reach sslbrain Cloud: the server must be able to reach
cloud.sslbrain.com,acme.sslbrain.comandregistry.sslbrain.comon port 443. See Network and firewall and No connection to sslbrain Cloud.
The appliance’s data
Copy link to the section “The appliance’s data”Everything the appliance stores is in the data directory inside the installation directory, ~/sslbrain/data by default. The container sees it as /data. It holds the database, the vault, the appliance’s keys and the backups you take in the web interface.
- The directory must be owned by user and group 1000. The script sets this itself.
- Never delete or move the directory while the appliance is running.
- Copy backups off the server. See Save a backup.
- The host controller’s log is
~/sslbrain/data/control/controller.log.
Behind a reverse proxy
Copy link to the section “Behind a reverse proxy”Put the proxy’s address or network in TRUSTED_PROXIES in docker-compose.yml, for example TRUSTED_PROXIES=10.0.0.5,192.168.50.0/24. Then recreate the container with docker compose up -d. Without that line, the appliance does not trust the proxy’s X-Forwarded-For. If the proxy runs on the same server, its traffic comes from the Docker network’s gateway (docker network inspect), not from 127.0.0.1.
What the script installs
Copy link to the section “What the script installs”docker-compose.ymland two public keys for the signature check in the installation directory,~/sslbrainby default.- The host controller
/usr/local/bin/sslbrain-controller. It carries out the updates, restarts and restores you start from the web interface, and starts the appliance again if it stops. - The cron entry
* * * * * /usr/local/bin/sslbrain-controller, which runs the host controller every minute. sslbrain-shutdown.service, if the server uses systemd. It stops the appliance cleanly when the server shuts down.
Script options
Copy link to the section “Script options”| Option | Environment variable | What it does |
|---|---|---|
--deploy-dir <path> | DEPLOY_DIR | Installation directory. Default ~/sslbrain. |
--yes or -y | ASSUME_YES=1 | Answers yes to every question, for example for an unattended installation. |
--skip-cron | SKIP_CRON=1 | Creates no cron entry. The script prints how to run the controller instead. |
DECLINE_DOCKER_INSTALL=1 | Does not install Docker if it is missing. | |
--help | Shows the options. |
Exit codes
Copy link to the section “Exit codes”| Code | Meaning |
|---|---|
| 0 | The installation is complete. |
| 1 | A required step was declined, or an option was invalid. |
| 2 | Something is missing on the server, such as Docker, Compose v2 or Python 3. |
| 3 | The signature on the appliance image could not be verified. The appliance has not been started. |
| 4 | The appliance did not answer within 5 minutes. |
The compose file from Downloads and requirements
Copy link to the section “The compose file from Downloads and requirements”Downloads and requirements in sslbrain Cloud offers a compose file, docker-compose.yml. It starts the appliance on port 443 with its data in the Docker volume sslbrain-data. It does not install the host controller.