Install the on-prem platform
Prepare DNS, TLS, registry access and your Linux host, then install a digest-pinned MyStocks partner release.
Journey overview · Next: activation and keys
Before installation
Use the deployment planner to preview commands for an on-site, AWS, Azure, Google Cloud or other Linux VM. Enter your final choices in the access request. These targets use the same supported installer; your infrastructure team first creates the VM, networking, DNS and identity configuration. Kubernetes and private-edge selections require architecture review and a separate agreed runbook; the planner does not claim to provision them automatically.
What resources and limits apply?
| Item | Current behavior |
|---|---|
| Request body | Up to 10 MiB through the on-prem proxy. |
| Ordinary upstream request | 30-second timeout. |
| Server-sent events | Connection lifetime up to 300 seconds; reconnect and revalidate. |
| Private application port | 3000 by default; installer accepts 1024 through 65535. |
| CPU, RAM, disk and concurrent users | No benchmark-certified minimum or throughput guarantee is published. Submit available vCPUs, RAM and disk in GiB, and expected users for capacity review. |
| Offline use | Not supported; cloud verification is required for protected access. |
These proxy limits do not override cloud endpoint limits or your partner rate-limit tier. Resource fields in the form are planning inputs, not reservations or enforced container quotas.
Host prerequisites
- Obtain an approved partner organization, active full API credential and authorized team accounts.
- Prepare a Linux AMD64 or ARM64 host with Docker Engine, Docker Compose and Python 3. Capacity is agreed during onboarding; no universal sizing guarantee is implied.
- Control an exact public domain and publish its supplied DNS TXT ownership challenge. Point A and any AAAA records to working addresses; remove stale IPv6 records.
- Allow inbound 80/443 as required by your HTTPS proxy and certificate challenge. Keep the application port private (default loopback port 3000).
- Allow DNS and outbound HTTPS to MyStocks, Firebase authentication and your approved image registry. Maintain accurate system time.
- Obtain a domain-bound license through a secure channel, registry reader access and an immutable approved image digest. Registry access and the installation license are separate credentials.
- Have the identity administrator register your installation domain in the authoritative Firebase project's authorized domains.
- Use Safari 16.4+, Chrome 111+ or Firefox 128+ for the workspace.
Which installer version should we use?
These commands were checked against installer revision ce0c36171 on 3 October 2026.
Obtain the approved image digest from onboarding; the installer and image have separate versions.
The download URL serves the current installer. Verify its checksum before running this revision:
Stop on checksum mismatch and obtain reviewed release instructions. Do not bypass the check or assume an updated script is compatible with an older image. Keep the verified script with the release record.
Default installation: Docker and Caddy
Authenticate Docker to the registry specified in your release instructions before installation. Download and review the installer; do not pipe an unreviewed script into a privileged shell.
Enter the license at the hidden terminal prompt. For automation, use --key-file PATH with a file readable only by its owner; never put a license in command arguments, shell history or browser code. The installer verifies the license before pulling the image and writes a protected environment file under /opt/mystocks by default.
The installer uses flags rather than an interactive deployment-choice menu. Docker and Caddy are the defaults.
Select a proxy
| Flag | Required preparation |
|---|---|
--proxy caddy | Working public DNS and certificate-challenge reachability; Caddy obtains TLS certificates. |
--proxy nginx | Install the generated configuration, provide certificates at its configured paths and validate with nginx -t. Certificate issuance is your responsibility. |
--proxy traefik | Provide the existing proxy network, websecure entrypoint and letsencrypt resolver. Select a network with --traefik-network. |
--proxy none | Supply and manage an external TLS reverse proxy yourself. |
Preserve the verified domain's Host header, keep upstream port 3000 private, and disable response buffering for server-sent events. Do not disable TLS certificate verification. The generated installer configuration differs from the repository's example Compose networking; use one complete configuration rather than mixing fragments.
Exact proxy commands
After verifying the script, set your approved values. The digest must contain 64 hexadecimal characters:
Do not run all four alternatives. Nginx needs your installed TLS certificates; Traefik needs the
existing proxy network, entrypoint and resolver described above. Use --output-dir consistently
when your approved installation directory differs from /opt/mystocks.
Native service option
Use --mode bare-metal --proxy nginx or --proxy none on Debian 12 or Ubuntu 24.04 with Node.js 22 and systemd. Docker is still required to extract the matching glibc image bundle. The application runs as a dedicated unprivileged service user; this is not a Docker-free installation path.
Verify before accepting traffic
Liveness alone is insufficient. Confirm readiness, certificate hostname and chain, authorized sign-in and a read-only API call. Then test authorized sandbox workflows, rejection of anonymous/cross-partner requests, and restart recovery in a dedicated test installation. --render-only produces configuration with an invalid fixture credential; it does not deploy or verify a working installation.
Continue with API connectivity and operations.
Was this page useful?
Your signal helps us tighten partner onboarding docs.
Last updated on