Bundle install
The one-command install, downloading the bundle by hand, installing on an offline host, and every step of deploy.sh.
Every edition uses the same bundle, RST-AI-Copilot-for-Prometheus-<version>.tar.gz. It contains the gateway, Caddy and pgvector/pgvector:pg16 images and every deployment file (compose files, Caddyfile, .env.example, deploy.sh, the update and backup scripts, and the docs). Without a license it runs as the Community edition.
One-command install
curl -fsSL https://github.com/Reallysec/RST-AI-Copilot-for-Prometheus/releases/latest/download/install.sh | sudo bashThe script:
- Picks the newest signed release, downloads its manifest
release-manifest.tokenand verifies it with the embedded Reallysec release key. - Downloads the bundle and checks that its SHA-256 matches the signed manifest. If either check fails, it deletes the download and installs nothing.
- Unpacks into
/opt/rst-ai-copilot-for-prometheusand runsdeploy.shfrom there.
| Option | Meaning |
|---|---|
--version <x.y.z> | Install a specific version. Default: the newest signed release |
--dir <path> | Install directory. Default: /opt/rst-ai-copilot-for-prometheus |
--mirror github|cn | Download source. Default: GitHub first, then the China mirror; cn tries the China mirror first |
--download-only | Download and verify into the current directory, deploy nothing |
The Tencent Cloud COS mirror for mainland China is not available yet. Whether you pass --mirror cn or use the default order, the mirror is skipped and the download falls back to GitHub Releases.
Running the same command again upgrades to the new version; .env and state/ in the install directory are kept.
Offline hosts
Download and verify on a machine with internet access, then copy the bundle to the target host:
curl -fsSL https://github.com/Reallysec/RST-AI-Copilot-for-Prometheus/releases/latest/download/install.sh | bash -s -- --download-onlyYou can also download RST-AI-Copilot-for-Prometheus-<version>.tar.gz and its .sha256 file from GitHub Releases and check it yourself:
sha256sum -c RST-AI-Copilot-for-Prometheus-<version>.tar.gz.sha256On the target host, unpack into a fixed directory and run deploy.sh:
sudo mkdir -p /opt/rst-ai-copilot-for-prometheus
sudo tar xzf RST-AI-Copilot-for-Prometheus-<version>.tar.gz -C /opt/rst-ai-copilot-for-prometheus --strip-components=1
cd /opt/rst-ai-copilot-for-prometheus && sudo ./deploy.shThe bundle contains every image, so deploying never pulls from a registry. On offline hosts, install Docker Engine 24 and the Compose plugin from your distribution's offline packages.
What deploy.sh does
deploy.sh is interactive, with prompts in Chinese and English:
- Checks Docker 24 and Compose v2, and creates
state/machine-idandstate/server_guid(the two halves of the license's hardware fingerprint; never regenerate them). - Loads the bundled images.
- Asks for the authentication method: 1 is the gateway's own sign-in; 2 is SSO (OIDC, needs an Enterprise license), see Single sign-on.
- Asks for the model URL, key, model name and time zone. The model can be left blank. The time zone defaults to
+08:00; the model relies on it to understand "today" and "yesterday". - Asks for the data sources. Each can be left blank and filled in later under Settings > Data sources:
- Prometheus URL, with no authentication, Basic (user name and password) or a Bearer token;
- Alertmanager URL, same options;
- Grafana URL (as the browser reaches it) and the UID of its Prometheus data source (default
prometheus). Grafana has no credentials here; the gateway only builds links.
- Asks for the host name or IP. With the gateway's own sign-in, set the
adminpassword (at least 8 characters); with SSO, enter the OIDC issuer, client id and client secret. - Generates the internal secrets (gateway shared secret, admin token, PostgreSQL password), asks you to confirm, and writes
.envwith mode 600. - Runs
docker compose -f docker-compose.prod.yml up -d, waits until every container is healthy and prints the address.
When you run deploy.sh again, choose to keep the existing .env: it only loads the new images and recreates the containers. If you choose to overwrite, the old .env is first saved as .env.<time>.bak and the PostgreSQL password is carried over.
Manual install
Without the prompts: cp .env.example .env, fill in the required values (see Configuration), then:
docker load < RST-AI-Copilot-for-Prometheus-images-<version>.tar
docker compose -f docker-compose.prod.yml up -dUsing your own PostgreSQL
You need PostgreSQL 16 with the pgvector extension. Point RST_DB_URL in .env at it and start only the gateway and Caddy:
docker compose -f docker-compose.prod.yml up -d --no-deps gateway caddyThe gateway creates its tables on start; migrations only touch the product's own tables.
Check
curl -k https://copilot.corp.local/healthz # {"status":"ok"}
curl -k https://copilot.corp.local/readyz # db / prometheus/healthz means the process is up. /readyz needs a reachable database and Prometheus; prometheus_configured: false means no data source has been set yet. After signing in, click Test connection for each source under Settings > Data sources.
Uninstall
Work in the install directory, and back up first:
cd /opt/rst-ai-copilot-for-prometheus
docker compose -f docker-compose.prod.yml down # remove containers, keep data volumes
docker compose -f docker-compose.prod.yml down -v # also delete the data volumes; cannot be undoneYour Prometheus and Alertmanager are not affected. Rule files and silences the gateway created are yours to clean up. Uninstalling does not notify the license server, so the host still counts as a node; to move hosts, restore the state/ directory to keep the fingerprint, or ask Reallysec to release the old node.
Requirements and network
Check the host size, Docker version, Prometheus and Alertmanager versions, model endpoint and access address, and the inbound and outbound ports to open, before you install.
Configuration
Key settings in .env: model, data sources, database, gateway authentication, reverse proxy, the rule write-back directory and optional settings.