Skip to content

Docker Deployment

Docker Compose is the official and only supported way to deploy SentriKat on-premises. The release bundle you download from the Customer Portal contains everything you need: the docker-compose.yml, an annotated .env.example, and the Nginx reverse-proxy configuration.

System Requirements

Component Minimum Recommended
CPU 2 cores 4+ cores
RAM 4 GB 8 GB
Disk 20 GB SSD 50 GB SSD
Docker 20.10+ Latest stable
Docker Compose v2.0+ Latest stable
Network Outbound HTTPS (443) Outbound HTTPS (443)

Why 4 GB minimum RAM?

SentriKat runs the application, PostgreSQL, and background sync tasks, and maintains a full software identity catalogue (~50K entries) in the database. The 4 GB minimum ensures stable operation under load.

Architecture

The stack consists of three services defined in the bundled docker-compose.yml:

Service Role Port
sentrikat The SentriKat application (Flask, served by Gunicorn) 5000 (inside the network)
sentrikat-db PostgreSQL database 5432 (internal only)
sentrikat-nginx Reverse proxy in front of the app 80 / 443

Database schema migrations run automatically when the application boots: there is no manual migration step, on first install or on upgrades.

Installation

1. Download SentriKat

  1. Log into the Customer Portal with your email (you'll receive a one-time code)
  2. Go to Downloads and download the latest release bundle (sentrikat-<version>.tar.gz)

2. Extract and Configure

# Extract the bundle
tar -xzf sentrikat-*.tar.gz
cd sentrikat-*/

# Load the Docker image shipped inside the bundle
docker load -i sentrikat-image-*.tar.gz

# Create your configuration from the annotated template
cp .env.example .env
${EDITOR:-nano} .env

No registry access needed

The application image ships inside the bundle, your server never needs to reach a container registry. Air-gapped installs work out of the box.

Set the required variables in .env (the .env.example in the bundle documents each one):

Variable Description How to set
SECRET_KEY Application signing key openssl rand -hex 32
ENCRYPTION_KEY Key used to encrypt stored credentials openssl rand 32 | base64 | tr '+/' '-_'
DB_PASSWORD PostgreSQL password (used by the bundled DATABASE_URL) Choose a strong password
DATABASE_URL PostgreSQL connection string Pre-wired to the bundled database service, only change it for an external PostgreSQL
SERVER_NAME Hostname SentriKat is served on (e.g. sentrikat.example.com) Your DNS name
SENTRIKAT_URL Full public base URL, used in emails and share links (e.g. https://sentrikat.example.com) Your URL
SENTRIKAT_INSTALLATION_ID Unique identifier of this installation (SK-INST-…). Your license is bound to it, keep it stable and back it up See the instructions in .env.example

Fill the required values in one shot (quick start / lab)

Tested copy-paste block, generates strong secrets and sets localhost values suitable for a trial install. For production, set SERVER_NAME and SENTRIKAT_URL to your real hostname.

sed -i "s|^SECRET_KEY=.*|SECRET_KEY=$(openssl rand -hex 32)|" .env
sed -i "s|^ENCRYPTION_KEY=.*|ENCRYPTION_KEY=$(openssl rand 32 | base64 | tr '+/' '-_')|" .env
sed -i "s|^DB_PASSWORD=.*|DB_PASSWORD=$(openssl rand -hex 24)|" .env
sed -i "s|^SERVER_NAME=.*|SERVER_NAME=localhost|" .env
sed -i "s|^SENTRIKAT_URL=.*|SENTRIKAT_URL=http://localhost:5000|" .env
sed -i "s|^SENTRIKAT_INSTALLATION_ID=.*|SENTRIKAT_INSTALLATION_ID=SK-INST-$(openssl rand -hex 8)|" .env

# verify all six are set
grep -E "^(SECRET_KEY|ENCRYPTION_KEY|DB_PASSWORD|SERVER_NAME|SENTRIKAT_URL|SENTRIKAT_INSTALLATION_ID)=" .env

3. Start the Stack

docker compose up -d

# Wait for health: every service should be "Up (healthy)" within ~60 seconds
docker compose ps

On first boot the application applies all database migrations automatically (you'll see Applying schema migrations in the logs).

4. Complete the Setup Wizard

Open http://<your-host> (through the bundled Nginx) or http://<your-host>:5000 (direct to the app). On first run, SentriKat starts a setup wizard in the browser that walks you through:

  1. Admin account: create your administrator user
  2. Organization: name your first organization
  3. Catalog seed: initial product catalog data
  4. Initial sync: the first the exploited-vulnerability catalogue sync runs automatically

After the wizard, exploited-vulnerability data stays in sync automatically on a daily schedule, no extra configuration needed.

Air-gapped installs

The the exploited-vulnerability feed, exploit probability, and software identity feeds refresh over the internet, so they cannot auto-sync on an isolated host. Refresh them with the offline bundle instead (see Air-Gapped Data Refresh below).

Air-Gapped Data Refresh

On a host with no internet access, keep the vulnerability intelligence current by moving a signed feed bundle across the boundary:

  1. On a connected machine, download the signed vuln-feed bundle from the Customer Portal.
  2. Transfer it to the air-gapped host (removable media or a data diode).
  3. In the admin UI, import the bundle. the exploited-vulnerability feed, exploit probability, and the software identity catalogue update with no internet access required.

The license is offline-signed and stays valid for the full term, so the 12-hour license heartbeat is best-effort and non-blocking on air-gapped installs.

5. Activate Your License

  1. Go to Settings → License
  2. Find your Activation Code (SK-XXXX-XXXX-XXXX-XXXX) in the Customer Portal or your purchase email
  3. Enter the code in the Online Activation section and click Activate
  4. Done! The license is applied automatically

Firewall

Your server needs outbound HTTPS access to portal.sentrikat.com:443.

  1. Go to Settings → License and copy your Installation ID (SK-INST-xxxxxxxx)
  2. On any browser, log into portal.sentrikat.com/downloads
  3. Paste your Installation ID and click Activate
  4. Copy the signed license and add it to your .env:
    SENTRIKAT_LICENSE=eyJsaWNlbnNl...your-signed-license...
    
  5. Restart: docker compose restart sentrikat

For full details, see Licensing & Activation.

Verify the Installation

# All services healthy
docker compose ps

# The app answers (200, or a redirect to the wizard/login)
curl -s -o /dev/null -w "%{http_code}\n" http://localhost:5000/

Common Operations

View Logs

# All services
docker compose logs -f

# Application only
docker compose logs -f sentrikat

# Last 100 lines
docker compose logs --tail=100 sentrikat

Restart Services

# Restart all
docker compose restart

# Restart the application only
docker compose restart sentrikat

Update SentriKat

  1. Download the latest bundle from the Customer Portal
  2. Extract it and copy your existing .env into the new directory
  3. Load the new image and start the new version:
docker load -i sentrikat-image-*.tar.gz
docker compose up -d

Schema migrations for the new version run automatically at boot. Your data lives in Docker volumes and is preserved across updates, but take a backup first anyway.

Backups

See Backup & Restore for database backup and disaster-recovery procedures.

Production Hardening

TLS / HTTPS

The default deployment serves HTTP. For production, terminate TLS at the bundled Nginx: the TLS Setup runbook covers Let's Encrypt, internal CA, and self-signed paths.

Agents and HTTP

The agent installers refuse plain HTTP by default. Set up TLS before rolling out agents, or pass the explicit allow-HTTP flag for lab use (see the agent guides).

External PostgreSQL

To use an existing PostgreSQL cluster instead of the bundled sentrikat-db service, point DATABASE_URL at it. See External Postgres.

Container Permissions

For hardened hosts (SELinux, rootless Docker, custom UID/GID mappings), see Container Permissions.

Troubleshooting

A container won't start

# Check logs
docker compose logs sentrikat

# Check container status
docker compose ps -a

# Verify the resolved configuration
docker compose config

The most common cause is a missing required variable in .env, the application refuses to start and tells you which one in the logs.

Database connection issues

# Check PostgreSQL is running and healthy
docker compose ps sentrikat-db

# Inspect database logs
docker compose logs sentrikat-db

Port conflicts

The stack binds ports 80/443 (Nginx) and 5000 (app). If something else on the host already uses them:

# Check which ports are in use
ss -tlnp | grep -E '(:80|:443|:5000)'

Then change the published port in docker-compose.yml, e.g. "8080:5000".

Looking for a manual (bare-metal) installation guide?

Bare-metal installation is not a supported path and is not documented. The container entrypoint performs setup a manual install would have to replicate by hand (CA certificates, permissions, automatic schema migrations), so Docker Compose is the only deployment that is tested and supported. If your environment cannot run Docker, contact [email protected].

Next Steps