Requirements and network
Check the host size, Docker version, Prometheus and Alertmanager versions, model endpoint and access address, and the inbound and outbound ports to open, before you install.
RST AI Copilot for Prometheus is delivered as Docker containers: the gateway, PostgreSQL with pgvector (accounts, audit, report history, the notification queue and knowledge-base vectors), and a Caddy reverse proxy that terminates TLS. The product does not include Prometheus. It connects to the Prometheus and Alertmanager you already run; Grafana is optional.
The bundle contains every image for these three containers, so installing does not pull from any registry.
operator browser ──HTTPS(443)──▶ Caddy ──▶ AI gateway
├─▶ PostgreSQL + pgvector (same compose project)
├─▶ your Prometheus:9090 / Alertmanager:9093
├─▶ model endpoint:443
├─▶ notification channels (Feishu, DingTalk, WeCom, email, webhook)
└─▶ license.reallysec.com:443 (activation, heartbeat, updates)Host
| Item | Requirement |
|---|---|
| Operating system | x86_64 Linux: Ubuntu 20.04, 22.04 or 24.04, RHEL or CentOS 8 or later, Kylin, UOS or any distribution that runs Docker 24 |
| Size | At least 2 vCPU, 4 GB RAM and 20 GB disk. The gateway container is capped at 2 CPU and 2 GB by default (RST_GATEWAY_CPUS, RST_GATEWAY_MEM) |
| Runtime | Docker Engine 24 or later, Docker Compose v2 (the docker compose plugin), bash 4 or later. deploy.sh checks them |
| Privileges | An account that can run docker. The one-command install needs root |
Monitoring stack
| Item | Requirement |
|---|---|
| Prometheus | 2.43 or later, reachable from the gateway host, with the HTTP API (/api/v1/*). Basic and Bearer authentication and private CAs are supported. Verified on 2.53 |
| Alertmanager | 0.25 or later with API v2 (read alerts, create and expire silences). Verified on 0.27 and 0.28 |
| Grafana | Optional, 9 or later. Only the operators' browsers need to reach it; the gateway never calls its API |
| Collection | snmp_exporter and blackbox_exporter. Vendors are recognised by sysObjectID; see Data sources |
Model
Optional. Volcengine Ark, any OpenAI-compatible endpoint, or a local vLLM or Ollama. Enter the URL, API key and model name during install, or add them later under AI settings. Without a model, queries are built by keyword from the metric dictionary and marked low confidence, and investigations only gather live metrics and runbooks as evidence without a root-cause assessment. Air-gapped sites use a local model with the air-gapped masking level.
Access address
Set CADDY_SITE_ADDRESS to the host name or IP the operators use. A bare IP works too (for example https://10.0.0.10/v2/); Caddy falls back to CADDY_DEFAULT_SNI, which deploy.sh fills in.
CADDY_TLS in .env decides the certificate, and upgrades leave it alone:
CADDY_TLS | Result |
|---|---|
internal (default) | A self-signed certificate from Caddy's internal CA, for host names and IPs. Have the operators' machines trust the root certificate |
/etc/caddy/certs/cert.pem /etc/caddy/certs/key.pem | Your own certificate: put cert.pem and key.pem in ./certs in the install directory |
you@example.com | A public Let's Encrypt certificate. Needs a public DNS name and 80 and 443 reachable from the internet |
Export the internal CA root: docker exec rst-ai-copilot-for-prometheus-caddy cat /data/caddy/pki/authorities/local/root.crt.
Ports
Inbound (to the gateway host):
| Port | Source | Purpose |
|---|---|---|
| 443/TCP | Operator network | https://<address>/v2/, the only entry point |
| 80/TCP | Operator network | Redirect to HTTPS, optional |
The gateway's port 8000 and PostgreSQL's 5432 stay on the compose network and are not exposed. On a cloud host, also open 443 in the security group.
Outbound (from the gateway host):
| Destination | Port | Purpose | Required |
|---|---|---|---|
| Your Prometheus | 9090 or the proxy port | Metric queries, PromQL validation, rule status | Yes |
| Your Alertmanager | 9093 or the proxy port | Read alerts, create and expire silences | Yes |
| Model endpoint | 443 | Inference and embeddings | With a model |
license.reallysec.com | 443 | Activation and heartbeat. Not needed with an offline license | With a license |
Notification channels (open.feishu.cn, oapi.dingtalk.com, qyapi.weixin.qq.com, SMTP, your webhooks) | 443, 25, 465, 587 | Delivering investigation conclusions and reports | When using notifications |
github.com, release-assets.githubusercontent.com | 443 | One-command install, the daily update check, bundle downloads | For the one-command install or online updates |