Install Noset on-prem
On-prem, the Noset server runs in your network and nothing leaves it. One command installs it; a setup wizard in the web app does the rest. An on-prem installation has exactly one organization: your company.
Requirements
Section titled “Requirements”- A Linux server with Docker and Docker Compose 2.20 or later.
- A host name people and gates use, for example
noset.example.com. - For a certificate from Let’s Encrypt: ports 80 and 443 reachable from the internet. Without inbound internet, use
--tls internal. - From Noset: the install script and a token for Noset’s image registry.
Install
Section titled “Install”-
Run the install command as root:
Terminal window sudo ./install.sh --domain noset.example.com \--registry-user <user> --registry-token-file /root/registry-tokenThe registry token comes from a file or standard input (
--registry-token-stdin), never from the command line. -
The command checks Docker and Compose, writes the configuration to
/etc/nosetand the Compose package to/opt/noset, pulls the images, starts Noset and waits until it is healthy. -
It prints a setup link, once:
https://noset.example.com/setup#token=…. It is the only secret the command ever shows. Open it.
The database password, the signing secret, the master key and the setup token are generated on the server and never printed. Only someone who ran the command, or can read /etc/noset, can open the setup wizard, so nobody else can claim a fresh installation.
Options
Section titled “Options”| Option | |
|---|---|
--domain NAME |
The host name people open. |
--tls acme / --tls internal |
A certificate from Let’s Encrypt (the default), or Caddy’s own certificate authority for a network without inbound internet. |
--email ADDRESS |
The address Let’s Encrypt writes to about certificates. |
--http-port, --https-port, --bind |
Publish on other ports or one address only. |
--trusted-proxies LIST |
Your reverse proxy in front of Noset. |
--image IMAGE |
Another server image. |
--no-start |
Write the configuration and the package, but do not start. |
./install.sh --help lists them all.
The setup wizard
Section titled “The setup wizard”The wizard creates the first user and every integration:
- Your organization: its name.
- Sign-in: your identity provider (OIDC): issuer, client id and secret. A test sign-in follows; whoever signs in becomes the first admin, and the setup link stops working.
- Slack (optional).
- Email (optional): your SMTP server.
- Evidence (optional): the time-stamp authorities and the evidence archive (S3 or MinIO with Object Lock).
- Connect the first gate (optional): the commands for your first server. See Install the gate.
You can skip any optional step and set it up later under Settings. Microsoft Teams is set up under Settings › Integrations; its bot needs https://<domain>/api/integrations/teams/messages reachable from the internet.
Update
Section titled “Update”Run the install command again. It pulls the image and restarts Noset. Nothing that is in place changes, and a set-up installation prints no setup link.
Run it
Section titled “Run it”cd /opt/noset && docker compose ps # what runscd /opt/noset && docker compose logs server # the server's logcd /opt/noset && docker compose down # stop; the data stays in the volumes