Install

What you need, what the installer does on your server, how the first administrator is created and how more servers join.

RespireCloud is not publicly released. Installer bundles go to early-access partners; ask for access. These steps describe the installer as it stands in development.

Before you start

  • A fresh server you have root on.
  • A distribution the installer accepts today: Ubuntu 24.04 LTS, Debian 13 or AlmaLinux 10. Support for Ubuntu 22.04 and 26.04, Debian 12, AlmaLinux 9 and Rocky Linux 9 and 10 is being added.
  • A PostgreSQL database for the panel itself, and Valkey (or Redis) on the same server.
  • Ports: 7443 for the panel over HTTPS. 4222 only if other servers will join.

Install the first server

  1. Unpack the release bundle on the server. It contains respirecloudd, respirecloud-agent, the systemd units and the signed modules.

  2. Run the installer as root, with the database URL:

    RC_DATABASE_URL='postgres://respirecloud:PASSWORD@127.0.0.1:5432/respirecloud' ./install.sh
  3. The installer creates the respirecloud system user, installs the binaries in /usr/bin and the modules in /usr/lib/respirecloud/modules, writes /etc/respirecloud/respirecloudd.env and starts respirecloudd, which runs as that unprivileged user.

  4. It then enrols the local agent the same way as any other server: the panel writes a one-time token, the agent makes its own key, pins the panel's certificate authority and connects over TLS 1.3. The token file is deleted and respirecloud-agent starts.

  5. Open https://your-server:7443/. Until the SSL module issues a certificate for the panel, the browser sees one from the panel's internal certificate authority. Once a real certificate is deployed, the panel switches to it without a restart.

Create the first administrator

  1. On the server, read the one-time setup token:

    cat /etc/respirecloud/bootstrap.token
  2. Paste it on the setup screen and choose a password of at least 12 characters.

  3. Add a passkey and an authenticator app on your Security page, and save your recovery codes. Two-step sign-in is required for administrators and resellers.

The guided tour shows each of these screens.

Settings the installer writes

Pass any of these as environment variables to install.sh; they end up in /etc/respirecloud/respirecloudd.env.

VariableDefaultWhat it is
RC_DATABASE_URL required PostgreSQL connection string for the panel's own database.
RC_LISTEN 127.0.0.1:7080 Plain HTTP API, loopback only.
RC_TLS_LISTEN 0.0.0.0:7443 HTTPS listener for browsers, the CLI and API clients.
RC_TLS_NAMES none Extra names for the panel certificate from the internal CA.
RC_PANEL_HOSTS none Host names the panel is reached on. Also used for the terminal's Origin check.
RC_PANEL_URL http://127.0.0.1:7080 The panel address the local agent enrols against.
RC_VALKEY_URL redis://127.0.0.1:6379/0 Valkey for the session cache and rate limits.
RC_NATS_LISTEN 127.0.0.1:4222 The bus servers connect to. Open it to other servers to add them.
RC_NATS_PUBLIC_URL none The bus address other servers dial.
RC_NATS_TLS_NAMES none Extra names on the bus certificate.
RC_NODE_ID short host name The id of this server in the panel.

Add more servers

  1. In the panel, run the action core.node.enrol_token.create with the server's id, name and roles. You get a one-time token, valid for an hour, and the exact command to run.

  2. On the new server, as root:

    respirecloud-agent enrol --panel https://panel.example.com --token rcen_… --ca-sha256 FINGERPRINT
  3. The agent generates its key on the machine (the key never leaves it), proves it holds the token and connects. From then on that server can receive only its own operations and publish only its own heartbeat.

The --ca-sha256 fingerprint pins the panel's certificate authority out of band. Plain HTTP is refused for any panel that is not on the same machine, and redirects are never followed.

Coming soon

  • Install profiles chosen from the server's CPU, memory and disk, with tuned PHP-FPM, database, Valkey and mail settings.
  • PostgreSQL and Valkey installed for you.
  • Signed update channels (stable, beta and long-term) from the Store.