Skip to content

Install Noset on-prem

On-prem, the Noset server runs in your network and nothing leaves it. One command installs it; a setup wizard in the web app does the rest. An on-prem installation has exactly one organization: your company.

  • A Linux server with Docker and Docker Compose 2.20 or later.
  • A host name people and gates use, for example noset.example.com.
  • For a certificate from Let’s Encrypt: ports 80 and 443 reachable from the internet. Without inbound internet, use --tls internal.
  • From Noset: the install script and a token for Noset’s image registry.
  1. Run the install command as root:

    Terminal window
    sudo ./install.sh --domain noset.example.com \
    --registry-user <user> --registry-token-file /root/registry-token

    The registry token comes from a file or standard input (--registry-token-stdin), never from the command line.

  2. The command checks Docker and Compose, writes the configuration to /etc/noset and the Compose package to /opt/noset, pulls the images, starts Noset and waits until it is healthy.

  3. It prints a setup link, once: https://noset.example.com/setup#token=…. It is the only secret the command ever shows. Open it.

The database password, the signing secret, the master key and the setup token are generated on the server and never printed. Only someone who ran the command, or can read /etc/noset, can open the setup wizard, so nobody else can claim a fresh installation.

Option
--domain NAME The host name people open.
--tls acme / --tls internal A certificate from Let’s Encrypt (the default), or Caddy’s own certificate authority for a network without inbound internet.
--email ADDRESS The address Let’s Encrypt writes to about certificates.
--http-port, --https-port, --bind Publish on other ports or one address only.
--trusted-proxies LIST Your reverse proxy in front of Noset.
--image IMAGE Another server image.
--no-start Write the configuration and the package, but do not start.

./install.sh --help lists them all.

The wizard creates the first user and every integration:

  1. Your organization: its name.
  2. Sign-in: your identity provider (OIDC): issuer, client id and secret. A test sign-in follows; whoever signs in becomes the first admin, and the setup link stops working.
  3. Slack (optional).
  4. Email (optional): your SMTP server.
  5. Evidence (optional): the time-stamp authorities and the evidence archive (S3 or MinIO with Object Lock).
  6. Connect the first gate (optional): the commands for your first server. See Install the gate.

You can skip any optional step and set it up later under Settings. Microsoft Teams is set up under Settings › Integrations; its bot needs https://<domain>/api/integrations/teams/messages reachable from the internet.

Run the install command again. It pulls the image and restarts Noset. Nothing that is in place changes, and a set-up installation prints no setup link.

Terminal window
cd /opt/noset && docker compose ps # what runs
cd /opt/noset && docker compose logs server # the server's log
cd /opt/noset && docker compose down # stop; the data stays in the volumes