Skip to main content
Version: 0.17

Complete registry access and bundle extraction first. Commands use Bash (Git Bash on Windows).

For an SSO-only deployment, provision the license and first administrator mapping before startup using Authentication. Otherwise use the local administrator bootstrap below.

Install Enterprise with Docker Compose

a. Configure .env​

cd compose
cp .env.example .env

Minimum required edits:

SESSION_SECRET=replace_with_a_long_random_value # openssl rand -base64 32
DB_PASSWORD=replace_with_secure_password
ADMIN_EMAIL=admin@your-company.com
ADMIN_PASSWORD=ChangeThisSecurePassword123!
APP_URL=https://tokentimer.your-domain.com
API_URL=https://tokentimer.your-domain.com
warning

If you run on plain http://localhost, set SESSION_COOKIE_SECURE_LOCALHOST_OVERRIDE=true so the browser persists the session cookie. Do not enable this in production. Put HTTPS in front instead.

For every other variable (SMTP, workers, proxy hops, license grace period), see the Configuration reference and the annotated compose/.env.example in the bundle.

b. Supply the license (pick one or combine)​

  • Set TT_LICENSE_KEY in .env to the raw JWT (recommended for automation), and/or
  • Sign in after first boot and import the JWT under System Settings > License, and/or
  • For a file on disk: copy <your-id>.license.key to compose/license.key and start with the optional overlay file:
docker compose -f docker-compose.yml -f docker-compose.license-file.yml up -d

If you use only the dashboard import, you can start with plain docker compose -f docker-compose.yml up -d and no license file on disk. How the three sources are resolved against each other is documented in the Configuration reference.

c. Start the stack​

docker compose -f docker-compose.yml up -d

Compose pulls these images from harbor.tokentimer.ch/tokentimer-enterprise/ automatically:

  • tokentimer-enterprise-api:<version> (also runs the one-shot database migrations job)
  • tokentimer-enterprise-worker:<version> (6 worker services: discovery, delivery, weekly digest, auto-sync, endpoint check, certops maintenance)
  • tokentimer-enterprise-dashboard:<version>

d. Verify​

curl http://localhost:4000/health
docker compose -f docker-compose.yml ps -a
docker compose -f docker-compose.yml logs --tail 100 migrations api

You should see: the health endpoint responding, and the dashboard login page in the browser.

Log in with ADMIN_EMAIL / ADMIN_PASSWORD. Auto-sync providers (AWS, Azure, GCP, Vault) appear active in the import modal once your license entitlements load. If a provider stays greyed out, open System Settings > License (signed-in admins only; GET /api/license/status is not available without a session).

Check the effective license in System Settings → License, then follow First asset and alert check. See configuration for secrets and deployment settings.