# Install the on-prem platform

> Prepare DNS, TLS, registry access and your Linux host, then install a digest-pinned MyStocks partner release.

[Journey overview](/partners/docs/onprem) · Next: [activation and keys](/partners/docs/onprem-activation)

## Before installation

Use the [deployment planner](https://partners.mystocks.africa/partners/onprem#configure) to preview commands for an on-site, AWS, Azure, Google Cloud or other Linux VM. Enter your final choices in the access request. These targets use the same supported installer; your infrastructure team first creates the VM, networking, DNS and identity configuration. Kubernetes and private-edge selections require architecture review and a separate agreed runbook; the planner does not claim to provision them automatically.

### What resources and limits apply?

| Item                                | Current behavior                                                                                                                                          |
| ----------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Request body                        | Up to 10 MiB through the on-prem proxy.                                                                                                                   |
| Ordinary upstream request           | 30-second timeout.                                                                                                                                        |
| Server-sent events                  | Connection lifetime up to 300 seconds; reconnect and revalidate.                                                                                          |
| Private application port            | 3000 by default; installer accepts 1024 through 65535.                                                                                                    |
| CPU, RAM, disk and concurrent users | No benchmark-certified minimum or throughput guarantee is published. Submit available vCPUs, RAM and disk in GiB, and expected users for capacity review. |
| Offline use                         | Not supported; cloud verification is required for protected access.                                                                                       |

These proxy limits do not override cloud endpoint limits or your partner rate-limit tier. Resource fields in the form are planning inputs, not reservations or enforced container quotas.

### Host prerequisites

- Obtain an approved partner organization, active full API credential and authorized team accounts.
- Prepare a Linux AMD64 or ARM64 host with Docker Engine, Docker Compose and Python 3. Capacity is agreed during onboarding; no universal sizing guarantee is implied.
- Control an exact public domain and publish its supplied DNS TXT ownership challenge. Point A and any AAAA records to working addresses; remove stale IPv6 records.
- Allow inbound 80/443 as required by your HTTPS proxy and certificate challenge. Keep the application port private (default loopback port 3000).
- Allow DNS and outbound HTTPS to MyStocks, Firebase authentication and your approved image registry. Maintain accurate system time.
- Obtain a domain-bound license through a secure channel, registry reader access and an immutable approved image digest. Registry access and the installation license are separate credentials.
- Have the identity administrator register your installation domain in the authoritative Firebase project's authorized domains.
- Use Safari 16.4+, Chrome 111+ or Firefox 128+ for the workspace.

## Which installer version should we use?

These commands were checked against installer revision `ce0c36171` on 3 October 2026.
Obtain the approved image **digest** from onboarding; the installer and image have separate versions.
The download URL serves the current installer. Verify its checksum before running this revision:

```sh
curl -fsSLo install-onprem.sh https://mystocks.africa/install-onprem.sh
printf '%s  %s\n' '16540118749f778b2e4947556bcaa061d28badc6d44b176a937912deb83e22de' 'install-onprem.sh' | sha256sum --check -
bash -n install-onprem.sh
```

Stop on checksum mismatch and obtain reviewed release instructions. Do not bypass the check or
assume an updated script is compatible with an older image. Keep the verified script with the release record.

## Default installation: Docker and Caddy

Authenticate Docker to the registry specified in your release instructions before installation. Download and review the installer; do not pipe an unreviewed script into a privileged shell.

```sh
curl -fsSLo install-onprem.sh https://mystocks.africa/install-onprem.sh
# Review the file. Replace the domain and image with approved values.
sudo bash install-onprem.sh --domain trading.example.com \
  --image REGISTRY/IMAGE@sha256:DIGEST \
  --mode docker --proxy caddy
```

Enter the license at the hidden terminal prompt. For automation, use `--key-file PATH` with a file readable only by its owner; never put a license in command arguments, shell history or browser code. The installer verifies the license before pulling the image and writes a protected environment file under `/opt/mystocks` by default.

The installer uses flags rather than an interactive deployment-choice menu. Docker and Caddy are the defaults.

## Select a proxy

| Flag              | Required preparation                                                                                                                                         |
| ----------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `--proxy caddy`   | Working public DNS and certificate-challenge reachability; Caddy obtains TLS certificates.                                                                   |
| `--proxy nginx`   | Install the generated configuration, provide certificates at its configured paths and validate with `nginx -t`. Certificate issuance is your responsibility. |
| `--proxy traefik` | Provide the existing proxy network, `websecure` entrypoint and `letsencrypt` resolver. Select a network with `--traefik-network`.                            |
| `--proxy none`    | Supply and manage an external TLS reverse proxy yourself.                                                                                                    |

Preserve the verified domain's Host header, keep upstream port 3000 private, and disable response buffering for server-sent events. Do not disable TLS certificate verification. The generated installer configuration differs from the repository's example Compose networking; use one complete configuration rather than mixing fragments.

## Exact proxy commands

After verifying the script, set your approved values. The digest must contain 64 hexadecimal characters:

```sh
DOMAIN='trading.example.com'
IMAGE='REGISTRY/IMAGE@sha256:DIGEST'
# Choose ONE command matching your prepared infrastructure:
sudo bash install-onprem.sh --domain "$DOMAIN" --image "$IMAGE" --mode docker --proxy caddy
sudo bash install-onprem.sh --domain "$DOMAIN" --image "$IMAGE" --mode docker --proxy nginx
sudo bash install-onprem.sh --domain "$DOMAIN" --image "$IMAGE" --mode docker --proxy traefik --traefik-network proxy
sudo bash install-onprem.sh --domain "$DOMAIN" --image "$IMAGE" --mode docker --proxy none
```

Do not run all four alternatives. Nginx needs your installed TLS certificates; Traefik needs the
existing `proxy` network, entrypoint and resolver described above. Use `--output-dir` consistently
when your approved installation directory differs from `/opt/mystocks`.

## Native service option

Use `--mode bare-metal --proxy nginx` or `--proxy none` on Debian 12 or Ubuntu 24.04 with Node.js 22 and systemd. Docker is still required to extract the matching glibc image bundle. The application runs as a dedicated unprivileged service user; this is not a Docker-free installation path.

```sh
sudo bash install-onprem.sh --domain "$DOMAIN" --image "$IMAGE" --mode bare-metal --proxy nginx
# Or use --proxy none with your independently managed TLS ingress.
```

## Verify before accepting traffic

```sh
curl --fail --show-error https://trading.example.com/api/live
curl --fail --show-error https://trading.example.com/api/health
```

Liveness alone is insufficient. Confirm readiness, certificate hostname and chain, authorized sign-in and a read-only API call. Then test authorized sandbox workflows, rejection of anonymous/cross-partner requests, and restart recovery in a dedicated test installation. `--render-only` produces configuration with an invalid fixture credential; it does not deploy or verify a working installation.

Continue with [API connectivity](/partners/docs/onprem-connectivity) and [operations](/partners/docs/onprem-operations).
