Skip to main content
Installation

Requirements and network

Check the host size, Docker version, Prometheus and Alertmanager versions, model endpoint and access address, and the inbound and outbound ports to open, before you install.

RST AI Copilot for Prometheus is delivered as Docker containers: the gateway, PostgreSQL with pgvector (accounts, audit, report history, the notification queue and knowledge-base vectors), and a Caddy reverse proxy that terminates TLS. The product does not include Prometheus. It connects to the Prometheus and Alertmanager you already run; Grafana is optional.

The bundle contains every image for these three containers, so installing does not pull from any registry.

operator browser ──HTTPS(443)──▶ Caddy ──▶ AI gateway
                                            ├─▶ PostgreSQL + pgvector (same compose project)
                                            ├─▶ your Prometheus:9090 / Alertmanager:9093
                                            ├─▶ model endpoint:443
                                            ├─▶ notification channels (Feishu, DingTalk, WeCom, email, webhook)
                                            └─▶ license.reallysec.com:443 (activation, heartbeat, updates)

Host

ItemRequirement
Operating systemx86_64 Linux: Ubuntu 20.04, 22.04 or 24.04, RHEL or CentOS 8 or later, Kylin, UOS or any distribution that runs Docker 24
SizeAt least 2 vCPU, 4 GB RAM and 20 GB disk. The gateway container is capped at 2 CPU and 2 GB by default (RST_GATEWAY_CPUS, RST_GATEWAY_MEM)
RuntimeDocker Engine 24 or later, Docker Compose v2 (the docker compose plugin), bash 4 or later. deploy.sh checks them
PrivilegesAn account that can run docker. The one-command install needs root

Monitoring stack

ItemRequirement
Prometheus2.43 or later, reachable from the gateway host, with the HTTP API (/api/v1/*). Basic and Bearer authentication and private CAs are supported. Verified on 2.53
Alertmanager0.25 or later with API v2 (read alerts, create and expire silences). Verified on 0.27 and 0.28
GrafanaOptional, 9 or later. Only the operators' browsers need to reach it; the gateway never calls its API
Collectionsnmp_exporter and blackbox_exporter. Vendors are recognised by sysObjectID; see Data sources

Model

Optional. Volcengine Ark, any OpenAI-compatible endpoint, or a local vLLM or Ollama. Enter the URL, API key and model name during install, or add them later under AI settings. Without a model, queries are built by keyword from the metric dictionary and marked low confidence, and investigations only gather live metrics and runbooks as evidence without a root-cause assessment. Air-gapped sites use a local model with the air-gapped masking level.

Access address

Set CADDY_SITE_ADDRESS to the host name or IP the operators use. A bare IP works too (for example https://10.0.0.10/v2/); Caddy falls back to CADDY_DEFAULT_SNI, which deploy.sh fills in.

CADDY_TLS in .env decides the certificate, and upgrades leave it alone:

CADDY_TLSResult
internal (default)A self-signed certificate from Caddy's internal CA, for host names and IPs. Have the operators' machines trust the root certificate
/etc/caddy/certs/cert.pem /etc/caddy/certs/key.pemYour own certificate: put cert.pem and key.pem in ./certs in the install directory
you@example.comA public Let's Encrypt certificate. Needs a public DNS name and 80 and 443 reachable from the internet

Export the internal CA root: docker exec rst-ai-copilot-for-prometheus-caddy cat /data/caddy/pki/authorities/local/root.crt.

Ports

Inbound (to the gateway host):

PortSourcePurpose
443/TCPOperator networkhttps://<address>/v2/, the only entry point
80/TCPOperator networkRedirect to HTTPS, optional

The gateway's port 8000 and PostgreSQL's 5432 stay on the compose network and are not exposed. On a cloud host, also open 443 in the security group.

Outbound (from the gateway host):

DestinationPortPurposeRequired
Your Prometheus9090 or the proxy portMetric queries, PromQL validation, rule statusYes
Your Alertmanager9093 or the proxy portRead alerts, create and expire silencesYes
Model endpoint443Inference and embeddingsWith a model
license.reallysec.com443Activation and heartbeat. Not needed with an offline licenseWith a license
Notification channels (open.feishu.cn, oapi.dingtalk.com, qyapi.weixin.qq.com, SMTP, your webhooks)443, 25, 465, 587Delivering investigation conclusions and reportsWhen using notifications
github.com, release-assets.githubusercontent.com443One-command install, the daily update check, bundle downloadsFor the one-command install or online updates

On this page