Skip to main content

Installation troubleshooting

The installer checks every step and prints one line per check:

PASS NET-01 ims.my-company.ma resolves to this server
WARN PRE-06 the clock is not NTP-synchronized
FAIL KC-01 the authentication service advertises another address

The identifier (NET-01, KC-01…) means the same thing everywhere. Quote it in any support request. The package's TROUBLESHOOTING.md gives the detailed cause and the fix commands for each one; this page gives the meaning and the first action.

Run the diagnosis​

The diagnosis changes nothing and can run in production. It runs every check without stopping at the first error, and exits with code 0 when everything is fine, 1 otherwise, so it can be scheduled.

./install.sh --doctor

Run it after a reboot, an upgrade, a certificate renewal, or whenever something looks wrong.

Rules that prevent most failures​

  • Do not edit derived configuration values by hand (authentication addresses, allowed origins). Change the host name or protocol by running the installer again: it rewrites everything that depends on them.
  • Never change the database passwords in .env.
  • Always run commands from the installation directory.

PRE · Requirements​

IdentifierWhat is checkedFirst action
PRE-01Docker answersStart Docker (on Windows, Docker Desktop only starts after sign-in)
PRE-02Docker Compose v2 is presentInstall the Compose v2 plugin; the old docker-compose is not enough
PRE-034 GB of memory for DockerAdd memory; on Windows, raise the memory allocated to WSL2
PRE-0420 GB of free disk spaceFree space (old images, old backups)
PRE-05Ports 80 and 443 freeStop the service using them (another web server, IIS, VPN)
PRE-06Clock synchronizedEnable NTP synchronization: a drifting clock makes sign-ins fail
PRE-07Databases from a previous installationKeep the data by reusing the old credentials, or delete it only after a backup
PRE-08Licence server reachableAllow outbound HTTPS, or use a licence file
PRE-09Package integrityCopy the package again: a file was altered in transfer
PRE-10Traces of a previous installationInformational on recent versions

CFG · Configuration​

IdentifierWhat is checkedFirst action
CFG-01Configuration written from the templateUse the installer and template from the same package
CFG-02No unresolved variableRun the installer again; it rewrites derived values
CFG-03Missing answer (unattended install)Complete the answers file
CFG-04Summary and answers savedRun the installer as a user who can write to the directory
CFG-05Invalid answerCorrect the value shown (host name, e-mail, time zone…)
CFG-06Configuration matches the versionRun the installer again: it adds what is missing and keeps secrets
CFG-07Derived values match the host nameRun the installer again; do not fix these values one by one
CFG-08The HTTPS site uses the right host nameRun the installer again after a host name change
CFG-09Server-sharing settings consistentApplies to servers hosting several installations; contact support

IMG · Images​

IdentifierWhat is checkedFirst action
IMG-01Images loaded from the packageCheck disk space and package integrity
IMG-02Image downloadFor a server without registry access, ask for a package with embedded images
IMG-03Version images presentLoad exactly the version shown; never switch to "latest"

TLS · Certificates​

IdentifierWhat is checkedFirst action
TLS-01Let's Encrypt certificate obtainedCheck that the DNS name points to the server and port 80 is reachable from the internet
TLS-02Existing certificate in placePut the certificate and key where expected
TLS-03Configuration for HTTPS handled by your proxyProvide your proxy configuration
TLS-04Certificate validityRun the renewal again; warning 21 days before expiry
TLS-05Automatic renewal runningRestart the renewal service

RUN · Startup​

IdentifierWhat is checkedFirst action
RUN-00Application startupRead the reported cause: port in use, missing value, missing image
RUN-01All components started—
RUN-02Every component existsRun commands from the installation directory
RUN-03Every component is healthyWait during the first start (3 to 5 minutes), then read the logs

API, DB, KC, WEB · Application​

IdentifierWhat is checkedFirst action
API-01Application services answerRead the services log: the first error names the cause
API-02The browser is allowed to call the APIRun the installer again (see CFG-07)
DB-01Database migrations succeededStop using the installation: restore the pre-upgrade backup and contact support
DB-02Database matches the versionChange nothing by hand; contact support
DB-03Databases can be rebuiltRestore the original database credentials
KC-01Address advertised by authenticationRun the installer again (see CFG-07): this causes endless sign-in failures
KC-02Authentication prepared at first startRead the first-start log
KC-03The web console is known to authenticationFollow the fix in TROUBLESHOOTING.md
WEB-01The web console answersCheck that the console is running

LIC, SEC, NET · Licence, access, network​

IdentifierWhat is checkedFirst action
LIC-00Licence file supplied at installActivate the licence after sign-in
LIC-01Licence activeSign in as administrator and activate the licence; without it, the application stays restricted
LIC-02Licence storagePut the licence file back; check write permissions
SEC-01Addresses allowed for the admin consolesInformational: with no address, they stay closed
SEC-02Allowlist presentRestore it from the package: without it, the whole site is down
NET-01The host name points to this serverFix the DNS record; the name must also resolve from the server itself

UPG · Upgrade​

IdentifierWhat is checkedFirst action
UPG-01The target is an installationPoint the upgrade at the installation directory, not at the package
UPG-02The upgrade goes to a newer versionUse the newest package; downgrades are refused
UPG-03Authentication is never downgradedNothing to do
UPG-04Backup before upgradeFree space; nothing was changed
UPG-05Package files replacedFix space or permissions, then run again
UPG-06Configuration mergedRead the message; then run the diagnosis
UPG-07HTTPS configuration updatedIf you had edited it by hand, carry over the new version's changes

See Upgrades and backups to return to the previous version.

Contact support​

Include in your request:

  • the FAIL or WARN identifiers from the diagnosis;
  • the installed version (VERSION file);
  • the log of the run concerned, in install/logs/.

Never send .env or install-summary.txt: they contain secrets.