Documentation / Getting started
Installation
Install CloseYourIt on your own server with one command.
Requirements
- A Linux server (Debian, Ubuntu or similar) with 4 GB of memory and 20 GB of disk. Add 6 GB if you plan to turn on the ingest gateway.
- A 64-bit processor:
x86_64orarm64. - A domain, for example
bugs.example.com, with anArecord pointing to the server. - Ports 80 and 443 reachable from the internet: the certificate is issued automatically.
- Root access (
sudo), pluscurlandopenssl, which most servers already have.
You do not need to install PostgreSQL, a web server or Docker yourself. Everything runs in containers that the installer starts; see Database for what is inside.
Install
Run this on the server:
curl -fsSL https://get.closeyour.it | sudo bash
The script:
- checks Docker and the compose plugin, and installs them if they are missing;
- asks for the domain, an email for the HTTPS certificate and the administrator email;
- asks for an SMTP server (you can skip it and add it later);
- warns you if the domain does not point to this server yet;
- writes everything to
/opt/closeyourit, with every secret key generated on the spot; - starts the app, the worker, PostgreSQL and Caddy, and waits up to 5 minutes for the app to answer;
- turns on the nightly backup, at 03:00.
At the end it prints the address, the administrator email and the administrator password once. It is not shown again: write it down, then change it after the first sign-in.
Install without questions
Set the answers beforehand and the script does not ask for them:
curl -fsSL https://get.closeyour.it | sudo \
DOMAIN=bugs.example.com \
ACME_EMAIL=ops@example.com \
ADMIN_EMAIL=you@example.com \
SMTP_ADDRESS=smtp.example.com SMTP_PORT=587 \
SMTP_USERNAME=user SMTP_PASSWORD=secret \
MAIL_FROM="CloseYourIt <noreply@example.com>" \
bash
| Variable | Use |
|---|---|
DOMAIN | the address CloseYourIt answers on |
ACME_EMAIL | email for the HTTPS certificate |
ADMIN_EMAIL | the administrator account; defaults to ACME_EMAIL |
SMTP_ADDRESS, SMTP_PORT, SMTP_USERNAME, SMTP_PASSWORD, MAIL_FROM | outgoing email; set all five, or the script asks for the missing ones |
CLOSEYOURIT_VERSION | a specific version instead of the latest one |
CLOSEYOURIT_HOME | another folder instead of /opt/closeyourit |
If Docker is missing the script installs it: in a terminal it asks first, without one (cloud-init, CI) it goes ahead.
First sign-in
- Open
https://<your-domain>and sign in with the administrator email and the printed password. - Set up the second factor: the administration area stays closed until you do.
- In the administration area, create your first organization.
- Inside it, create a project, then an ingest token in the project settings.
- Connect an application: see Connect your apps.
Without an SMTP server CloseYourIt sends no email at all: no invitations, no password reset, no alerts by email. Add it before inviting other people; see Settings.
What lives where
| Path | What |
|---|---|
/opt/closeyourit/.env | settings and secret keys (readable by root only) |
/opt/closeyourit/compose.yml | the services |
/opt/closeyourit/Caddyfile | the web server in front of the app |
/opt/closeyourit/backups/ | nightly database copies |
/opt/closeyourit/ingest/ | password and encryption key of the ingest gateway |
/usr/local/bin/closeyourit | the closeyourit command |
/etc/cron.d/closeyourit | the nightly backup |
Docker volume closeyourit_postgres | the database |
Docker volume closeyourit_storage | uploaded files |
Keep the secret keys safe
/opt/closeyourit/.env holds the keys that encrypt part of your data. They exist only in that file: the database backups do not contain them. If you lose the file, the encrypted data cannot be read again, even with a good backup.
Copy .env to a safe place right after the install, and again whenever you change it.
Uninstall
This deletes CloseYourIt and all its data from the server:
cd /opt/closeyourit && docker compose --profile ingest down --volumes
rm -rf /opt/closeyourit /usr/local/bin/closeyourit /etc/cron.d/closeyourit