Installing from the archive
Install the gateway with one command or from a downloaded archive, install on an air-gapped host, answer the deploy.sh prompts, verify the install, and install without deploy.sh.
The gateway is published on GitHub Releases as the archive RST-AI-Copilot-for-Zabbix-<version>.tar.gz, with a .sha256 file of the same name for verification and release-manifest.token, the release manifest signed by Reallysec. The archive carries the images and deployment files, and its deploy.sh does the installation: it loads the images, collects the configuration, writes .env and starts the containers. install.sh combines download, signature check, unpacking and deploy.sh into one command.
Archive contents
RST-AI-Copilot-for-Zabbix-<version>/
├── RST-AI-Copilot-for-Zabbix-images-<version>.tar # gateway and Caddy images
├── deploy.sh # interactive installer
├── docker-compose.prod.yml # standard deployment
├── docker-compose.sso.yml # SSO
├── Caddyfile, Caddyfile.sso
├── .env.example # settings, with notes
├── deploy/rst-update.sh # online update installer
├── keycloak/ # Keycloak config for the SSO demo
├── scripts/backup.sh, scripts/restore.sh
├── docs/ # INSTALL.md, LICENSING.md, BACKUP.md, SSO.md, EULA.md and more
└── THIRD-PARTY-NOTICES.md, CHANGELOG.mdInstall with one command
Prerequisites
- Docker Engine 24 or later and Docker Compose v2 are installed, along with
curl,tar,sha256sum,base64andopenssl. - The host can reach
github.com. - You run the command as root from an interactive terminal, because
deploy.shreads input.
Steps
-
Run the installer:
curl -fsSL https://github.com/Reallysec/RST-AI-Copilot-for-Zabbix/releases/latest/download/install.sh | sudo bashEvery edition uses the same archive: without a license it runs as Community, and activating a license under Settings > License unlocks that edition in place, with no reinstall.
-
Answer the
deploy.shprompts. See deploy.sh prompts below.
The script first downloads the signed release manifest release-manifest.token and verifies it with the embedded Reallysec public key. It then downloads the archive and continues only if its SHA-256 matches the manifest; otherwise it deletes the download and exits without installing anything. If the newest release has just been published and its manifest is not uploaded yet, the script skips it and installs the newest signed release.
After the checks pass, the archive is unpacked into /opt/rst-ai-copilot-for-zabbix and deploy.sh runs there. When you run it again on the same host, .env and state/ in that directory are kept, and the license's host fingerprint does not change. The same command therefore upgrades an install.
| Option | Description |
|---|---|
--version <x.y.z> | Install a specific version; the newest signed release by default. A pinned version without a signed manifest is never installed |
--dir <path> | Installation directory; /opt/rst-ai-copilot-for-zabbix by default |
--mirror github, --mirror cn | Choose the download source. The China mirror is not available yet; --mirror cn currently prints a notice and downloads from GitHub |
--download-only | Download and verify the archive into the current directory, without installing |
Options go after bash -s --:
curl -fsSL https://github.com/Reallysec/RST-AI-Copilot-for-Zabbix/releases/latest/download/install.sh | sudo bash -s -- --version 2.0.2If a GitHub download stays below 10 KB/s for 30 seconds, the script treats it as failed and exits. On a slow network, download with --download-only on another machine and copy the archive over, as described below.
Install on an air-gapped host
Steps
-
On a Linux machine that can reach GitHub, download and verify the archive. This step needs neither root nor Docker:
curl -fsSL https://github.com/Reallysec/RST-AI-Copilot-for-Zabbix/releases/latest/download/install.sh | bash -s -- --download-only -
Copy
RST-AI-Copilot-for-Zabbix-<version>.tar.gzfrom the current directory to the air-gapped host. -
On the air-gapped host, unpack it and run
deploy.sh:tar xzf RST-AI-Copilot-for-Zabbix-<version>.tar.gz cd RST-AI-Copilot-for-Zabbix-<version> sudo ./deploy.sh
A license on an air-gapped host needs offline activation (Enterprise). See License.
Install the archive by hand
Steps
-
Download
RST-AI-Copilot-for-Zabbix-<version>.tar.gzand its.sha256file from GitHub Releases. Every edition uses the same archive; the activated license decides which features are on. -
Verify and unpack it:
sha256sum -c RST-AI-Copilot-for-Zabbix-<version>.tar.gz.sha256 tar xzf RST-AI-Copilot-for-Zabbix-<version>.tar.gz cd RST-AI-Copilot-for-Zabbix-<version> -
Run
sudo ./deploy.shand answer the prompts.
The .sha256 file comes from the same place as the archive, so it only catches transfer damage. To confirm the archive was really published by Reallysec, use install.sh, which checks the signed manifest.
deploy.sh prompts
The script runs in seven steps: preflight, image load, check for an existing .env, deployment form, configuration, write .env, start.
- The preflight checks Docker, Docker Compose v2 and the deployment files, and generates
state/machine-id, the license's hardware fingerprint. If the file exists it is reused. - If
.envalready exists, the script asks whether to keep it and start; the default is no. Enterywhen upgrading. If you answer no, the old file is backed up as.env.<time>.bakand you fill in the values again. - The archive only carries the standard form, which connects to your existing Zabbix, so there is nothing to choose in that step.
| Prompt | Value |
|---|---|
| LLM endpoint URL | https://ark.cn-beijing.volces.com/api/v3 by default |
| LLM API key | Not echoed |
| LLM model id | The endpoint id on Volcengine Ark, such as ep-xxxxxxxxxxxxxx-xxxxx; the model name elsewhere |
| Zabbix JSON-RPC URL | For example https://zabbix.corp.local/api_jsonrpc.php |
| Zabbix API token | Recommended. If left empty, the script asks for a Zabbix user name (Admin by default) and password instead |
| Zabbix Web UI address | Optional, used by "Open in Zabbix" links. When empty, the scheme, host and port of the JSON-RPC URL are used |
| Caddy hostname or IP | Users open https://<hostname>/v2/; use a hostname |
| Administrator password | Password of the administrator account admin, at least 8 characters, entered twice. Other accounts are created after sign-in under Settings > Users |
The script generates RST_GATEWAY_SHARED_SECRET, RST_ADMIN_TOKEN and the administrator password hash RST_ADMIN_PASSWORD_HASH (computed with the gateway image), and after you confirm writes them to .env with mode 600. After starting, it waits up to 90 seconds for every container to become healthy, then prints the URL https://<hostname>/v2/, the sign-in account admin and RST_ADMIN_TOKEN. RST_ADMIN_TOKEN is the operations API token that scripts send in the X-RST-Admin-Token header; keep it like a password.
deploy.sh does not configure SSO. See SSO.
Verify the installation
Steps
-
Check health and readiness:
curl -k https://<hostname>/healthz # {"status":"ok"} curl -k https://<hostname>/readyz docker compose -f docker-compose.prod.yml ps -
Open
https://<hostname>/v2/, check that you land on the sign-in page, and sign in asadminwith the password you set during installation.
A ready gateway returns {"status":"ready","zabbix":"ok","zabbix_major":"<major version>"}. On a 503, the zabbix field holds the reason: a connection or authentication error, or a Zabbix version older than 6.0 (code is zabbix_version_unsupported). readyz calls Zabbix on every request, so it works as a monitoring probe.
The default certificate comes from Caddy's internal CA, and browsers warn on first visit. For production, replace tls internal in Caddyfile with your own certificate.
Install without deploy.sh
Steps
-
Load the images and prepare
.env:docker load -i RST-AI-Copilot-for-Zabbix-images-<version>.tar cp .env.example .env -
In
.env, setLLM_API_KEY,LLM_BASE_URL,LLM_MODEL,ZABBIX_URL,ZABBIX_TOKENandCADDY_SITE_ADDRESS, plusRST_GATEWAY_SHARED_SECRETandRST_ADMIN_TOKENgenerated withopenssl rand -hex 32. -
Generate the administrator password hash and write it to
RST_ADMIN_PASSWORD_HASHin.env, doubling every$as$$:docker run --rm rst-ai-copilot-for-zabbix-gateway:<version> python -m backend.session_auth '<password>' # pbkdf2_sha256$600000$... becomes pbkdf2_sha256$$600000$$...Without it, the factory credentials
admin/Admin@123apply. They only work from the gateway host itself; a remote browser sign-in returns 403. -
Generate the host fingerprint file, once:
mkdir -p state openssl rand -hex 16 > state/machine-id -
Run
docker compose -f docker-compose.prod.yml up -d. The archive has no Dockerfile, so do not add--build.
state/machine-id must exist before the first start. If it is missing, Docker creates a directory in its place and activation fails with no hardware identifier available. Never regenerate the file once created; a change means the license must be activated again.
Next steps
- To use the paid features, activate a license on the License page.
- Configure the host group allowlist, field masking and audit in Settings.
- Include
./state/machine-idand thegateway_statevolume in backups. See Upgrade, rollback and backup.
Requirements and network
Before installing, confirm the host size, Docker version, Zabbix version and API token, LLM endpoint and hostname, and the inbound and outbound ports to open.
Configuration reference
Settings in the .env file of the install directory: required settings, sign-in and accounts, Zabbix connection and data scope, content packs and online update, live problems, models, reports and inspections, platform checkup and remote diagnostics, audit and retention, resources.