Skip to main content

Installation

Nadigit IMS is installed on your server from an installation package supplied by Nadigit, for Linux or for Windows. The package contains a guided installer that asks a few questions, prepares the configuration, obtains the HTTPS certificate, starts the application and checks the result.

Requirements​

ItemLinuxWindows
Container engineDocker Engine with Docker Compose v2Docker Desktop (WSL2 engine) with Compose v2
Memory4 GB available to DockerAt least 4 GB in Docker Desktop (Settings → Resources)
Disk20 GB free20 GB free
NetworkPorts 80 and 443 reachable by usersSame, and Windows Firewall must allow Docker Desktop
Domain nameA DNS name already pointing to the serverSame
ClockSynchronized (NTP)Synchronized
  • For a Let's Encrypt certificate, port 80 must be reachable from the internet.
  • Online licence activation needs outbound HTTPS access to the Nadigit licence server. Without internet access, use a licence file.
  • On Windows, set the power options so the machine does not sleep: a sleeping machine stops renewing its certificate.

Package contents​

ItemRole
install.sh / install.ps1The guided installer
.env.templateThe configuration template the installer fills in
VERSION, CHECKSUMS.txtThe delivered version and the checksum of every file
scripts/Certificate issuance, backup
config/Location of the licence file
TROUBLESHOOTING.mdEvery check in detail, with the fix to apply

Some packages also embed the application images, for servers without internet access.

Install​

Extract the package into the directory that will hold the installation, for example /opt/nadigit-ims or C:\nadigit-ims, then run the installer from that directory.

./install.sh
Choose the directory once and for all

The installation stays in this directory: upgrades, backups and the licence depend on it. Do not move or rename it afterwards.

Questions asked​

QuestionExample or possible values
Public host name, the one users will typeims.my-company.ma
Public protocolhttps, unless another proxy already encrypts the traffic
TLS modeletsencrypt (free certificate, obtained automatically), existing-cert (your certificate), none (HTTPS handled by your own proxy)
Certificate contact e-mailFor Let's Encrypt
Does the server host another installation?false for an installation alone on its server
Time zoneAfrica/Casablanca
First administrator's username and e-mail, first and last name (optional)admin, admin@my-company.ma
Licence file (optional)The path of a license.json to install right away
Addresses allowed to reach the technical admin consoles (optional)Leave empty to keep them closed

Everything else is derived from these answers or generated: secrets (database passwords, technical keys) are created at the first installation and never changed afterwards.

What the installer does​

  1. Checks the requirements: Docker, memory, disk, ports, clock, DNS name.
  2. Writes the configuration (.env, readable by its owner only) and generates the secrets.
  3. Loads the application images.
  4. Obtains the HTTPS certificate, or installs yours.
  5. Starts the application and waits until every component is ready.
  6. Checks the result: each check prints PASS, WARN or FAIL with an identifier and the fix to apply.

The first start takes about five minutes: the authentication service prepares itself once, and the application waits for it. It is not stuck.

Each run is logged in install/logs/. After a failure, fix the reported cause and run the installer again: it resumes where it stopped and reuses the secrets already generated.

At the end, the installer writes two files:

  • install-summary.txt, with the initial credentials, readable by its owner only: keep it somewhere safe;
  • answers.yml, your answers without any secret, to replay the installation.

Installer options​

./install.sh --unattended --answers answers.yml # replay an installation without questions
./install.sh --dry-run # write the configuration, start nothing
./install.sh --verify # re-check a running installation
./install.sh --doctor # diagnose, read-only

The diagnosis (--doctor / -Doctor) changes nothing: it can run at any time in production, after a reboot, an upgrade or a certificate renewal. See Installation troubleshooting.

First sign-in​

  1. Open https://<your-host-name>/webconsole/.

  2. Sign in as the first administrator. The temporary password is in install-summary.txt; you are asked to change it.

  3. Activate the licence. Without a licence, the application starts in restricted mode and shows the Activate this installation screen:

    • Registration key: for a server that can reach the Nadigit licence server;
    • Licence file: for a server without internet access, with the license.json issued for this server. The screen shows the Server ID to send to Nadigit with your request.

    Activation takes effect immediately, with no restart. Only an administrator can activate the installation.

  4. Choose the organization's business profile, then follow the initial setup.

Before going live​

  • Schedule backups and copy them off the server. See Upgrades and backups.
  • Technical admin consoles. The authentication admin console and the API explorer are closed to everyone by default. Only open them to the addresses that need them: the installer offers it (last question), and TROUBLESHOOTING.md (check SEC-01) describes the change afterwards.
  • Watch the certificate. Renewal is automatic; the diagnosis flags a certificate that expires in less than 21 days.

See also​