Installation
Nadigit IMS is installed on your server from an installation package supplied by Nadigit, for Linux or for Windows. The package contains a guided installer that asks a few questions, prepares the configuration, obtains the HTTPS certificate, starts the application and checks the result.
Requirements
| Item | Linux | Windows |
|---|---|---|
| Container engine | Docker Engine with Docker Compose v2 | Docker Desktop (WSL2 engine) with Compose v2 |
| Memory | 4 GB available to Docker | At least 4 GB in Docker Desktop (Settings → Resources) |
| Disk | 20 GB free | 20 GB free |
| Network | Ports 80 and 443 reachable by users | Same, and Windows Firewall must allow Docker Desktop |
| Domain name | A DNS name already pointing to the server | Same |
| Clock | Synchronized (NTP) | Synchronized |
- For a Let's Encrypt certificate, port 80 must be reachable from the internet.
- Online licence activation needs outbound HTTPS access to the Nadigit licence server. Without internet access, use a licence file.
- On Windows, set the power options so the machine does not sleep: a sleeping machine stops renewing its certificate.
Package contents
| Item | Role |
|---|---|
install.sh / install.ps1 | The guided installer |
.env.template | The configuration template the installer fills in |
VERSION, CHECKSUMS.txt | The delivered version and the checksum of every file |
scripts/ | Certificate issuance, backup |
config/ | Location of the licence file |
TROUBLESHOOTING.md | Every check in detail, with the fix to apply |
Some packages also embed the application images, for servers without internet access.
Install
Extract the package into the directory that will hold the installation, for
example /opt/nadigit-ims or C:\nadigit-ims, then run the installer from that
directory.
- Linux
- Windows
./install.sh
powershell -ExecutionPolicy Bypass -File .\install.ps1
-ExecutionPolicy Bypass allows this script for this run only, without changing
the machine's policy.
The installation stays in this directory: upgrades, backups and the licence depend on it. Do not move or rename it afterwards.
Questions asked
| Question | Example or possible values |
|---|---|
| Public host name, the one users will type | ims.my-company.ma |
| Public protocol | https, unless another proxy already encrypts the traffic |
| TLS mode | letsencrypt (free certificate, obtained automatically), existing-cert (your certificate), none (HTTPS handled by your own proxy) |
| Certificate contact e-mail | For Let's Encrypt |
| Does the server host another installation? | false for an installation alone on its server |
| Time zone | Africa/Casablanca |
| First administrator's username and e-mail, first and last name (optional) | admin, admin@my-company.ma |
| Licence file (optional) | The path of a license.json to install right away |
| Addresses allowed to reach the technical admin consoles (optional) | Leave empty to keep them closed |
Everything else is derived from these answers or generated: secrets (database passwords, technical keys) are created at the first installation and never changed afterwards.
What the installer does
- Checks the requirements: Docker, memory, disk, ports, clock, DNS name.
- Writes the configuration (
.env, readable by its owner only) and generates the secrets. - Loads the application images.
- Obtains the HTTPS certificate, or installs yours.
- Starts the application and waits until every component is ready.
- Checks the result: each check prints
PASS,WARNorFAILwith an identifier and the fix to apply.
The first start takes about five minutes: the authentication service prepares itself once, and the application waits for it. It is not stuck.
Each run is logged in install/logs/. After a failure, fix the reported cause
and run the installer again: it resumes where it stopped and reuses the secrets
already generated.
At the end, the installer writes two files:
install-summary.txt, with the initial credentials, readable by its owner only: keep it somewhere safe;answers.yml, your answers without any secret, to replay the installation.
Installer options
- Linux
- Windows
./install.sh --unattended --answers answers.yml # replay an installation without questions
./install.sh --dry-run # write the configuration, start nothing
./install.sh --verify # re-check a running installation
./install.sh --doctor # diagnose, read-only
.\install.ps1 -Unattended -Answers answers.yml # replay an installation without questions
.\install.ps1 -DryRun # write the configuration, start nothing
.\install.ps1 -Verify # re-check a running installation
.\install.ps1 -Doctor # diagnose, read-only
The diagnosis (--doctor / -Doctor) changes nothing: it can run at any
time in production, after a reboot, an upgrade or a certificate renewal. See
Installation troubleshooting.
First sign-in
-
Open
https://<your-host-name>/webconsole/. -
Sign in as the first administrator. The temporary password is in
install-summary.txt; you are asked to change it. -
Activate the licence. Without a licence, the application starts in restricted mode and shows the Activate this installation screen:
- Registration key: for a server that can reach the Nadigit licence server;
- Licence file: for a server without internet access, with the
license.jsonissued for this server. The screen shows the Server ID to send to Nadigit with your request.
Activation takes effect immediately, with no restart. Only an administrator can activate the installation.
-
Choose the organization's business profile, then follow the initial setup.
Before going live
- Schedule backups and copy them off the server. See Upgrades and backups.
- Technical admin consoles. The authentication admin console and the API
explorer are closed to everyone by default. Only open them to the
addresses that need them: the installer offers it (last question), and
TROUBLESHOOTING.md(checkSEC-01) describes the change afterwards. - Watch the certificate. Renewal is automatic; the diagnosis flags a certificate that expires in less than 21 days.