Skip to main content
Installation

Bundle install

The one-command install, downloading the bundle by hand, installing on an offline host, and every step of deploy.sh.

Every edition uses the same bundle, RST-AI-Copilot-for-Prometheus-<version>.tar.gz. It contains the gateway, Caddy and pgvector/pgvector:pg16 images and every deployment file (compose files, Caddyfile, .env.example, deploy.sh, the update and backup scripts, and the docs). Without a license it runs as the Community edition.

One-command install

curl -fsSL https://github.com/Reallysec/RST-AI-Copilot-for-Prometheus/releases/latest/download/install.sh | sudo bash

The script:

  1. Picks the newest signed release, downloads its manifest release-manifest.token and verifies it with the embedded Reallysec release key.
  2. Downloads the bundle and checks that its SHA-256 matches the signed manifest. If either check fails, it deletes the download and installs nothing.
  3. Unpacks into /opt/rst-ai-copilot-for-prometheus and runs deploy.sh from there.
OptionMeaning
--version <x.y.z>Install a specific version. Default: the newest signed release
--dir <path>Install directory. Default: /opt/rst-ai-copilot-for-prometheus
--mirror github|cnDownload source. Default: GitHub first, then the China mirror; cn tries the China mirror first
--download-onlyDownload and verify into the current directory, deploy nothing

The Tencent Cloud COS mirror for mainland China is not available yet. Whether you pass --mirror cn or use the default order, the mirror is skipped and the download falls back to GitHub Releases.

Running the same command again upgrades to the new version; .env and state/ in the install directory are kept.

Offline hosts

Download and verify on a machine with internet access, then copy the bundle to the target host:

curl -fsSL https://github.com/Reallysec/RST-AI-Copilot-for-Prometheus/releases/latest/download/install.sh | bash -s -- --download-only

You can also download RST-AI-Copilot-for-Prometheus-<version>.tar.gz and its .sha256 file from GitHub Releases and check it yourself:

sha256sum -c RST-AI-Copilot-for-Prometheus-<version>.tar.gz.sha256

On the target host, unpack into a fixed directory and run deploy.sh:

sudo mkdir -p /opt/rst-ai-copilot-for-prometheus
sudo tar xzf RST-AI-Copilot-for-Prometheus-<version>.tar.gz -C /opt/rst-ai-copilot-for-prometheus --strip-components=1
cd /opt/rst-ai-copilot-for-prometheus && sudo ./deploy.sh

The bundle contains every image, so deploying never pulls from a registry. On offline hosts, install Docker Engine 24 and the Compose plugin from your distribution's offline packages.

What deploy.sh does

deploy.sh is interactive, with prompts in Chinese and English:

  1. Checks Docker 24 and Compose v2, and creates state/machine-id and state/server_guid (the two halves of the license's hardware fingerprint; never regenerate them).
  2. Loads the bundled images.
  3. Asks for the authentication method: 1 is the gateway's own sign-in; 2 is SSO (OIDC, needs an Enterprise license), see Single sign-on.
  4. Asks for the model URL, key, model name and time zone. The model can be left blank. The time zone defaults to +08:00; the model relies on it to understand "today" and "yesterday".
  5. Asks for the data sources. Each can be left blank and filled in later under Settings > Data sources:
    • Prometheus URL, with no authentication, Basic (user name and password) or a Bearer token;
    • Alertmanager URL, same options;
    • Grafana URL (as the browser reaches it) and the UID of its Prometheus data source (default prometheus). Grafana has no credentials here; the gateway only builds links.
  6. Asks for the host name or IP. With the gateway's own sign-in, set the admin password (at least 8 characters); with SSO, enter the OIDC issuer, client id and client secret.
  7. Generates the internal secrets (gateway shared secret, admin token, PostgreSQL password), asks you to confirm, and writes .env with mode 600.
  8. Runs docker compose -f docker-compose.prod.yml up -d, waits until every container is healthy and prints the address.

When you run deploy.sh again, choose to keep the existing .env: it only loads the new images and recreates the containers. If you choose to overwrite, the old .env is first saved as .env.<time>.bak and the PostgreSQL password is carried over.

Manual install

Without the prompts: cp .env.example .env, fill in the required values (see Configuration), then:

docker load < RST-AI-Copilot-for-Prometheus-images-<version>.tar
docker compose -f docker-compose.prod.yml up -d

Using your own PostgreSQL

You need PostgreSQL 16 with the pgvector extension. Point RST_DB_URL in .env at it and start only the gateway and Caddy:

docker compose -f docker-compose.prod.yml up -d --no-deps gateway caddy

The gateway creates its tables on start; migrations only touch the product's own tables.

Check

curl -k https://copilot.corp.local/healthz   # {"status":"ok"}
curl -k https://copilot.corp.local/readyz    # db / prometheus

/healthz means the process is up. /readyz needs a reachable database and Prometheus; prometheus_configured: false means no data source has been set yet. After signing in, click Test connection for each source under Settings > Data sources.

Uninstall

Work in the install directory, and back up first:

cd /opt/rst-ai-copilot-for-prometheus
docker compose -f docker-compose.prod.yml down      # remove containers, keep data volumes
docker compose -f docker-compose.prod.yml down -v   # also delete the data volumes; cannot be undone

Your Prometheus and Alertmanager are not affected. Rule files and silences the gateway created are yours to clean up. Uninstalling does not notify the license server, so the host still counts as a node; to move hosts, restore the state/ directory to keep the fingerprint, or ask Reallysec to release the old node.

On this page