- To start from an empty cloud instance, follow Deploy Sediment on EC2. It supplies PostgreSQL, HTTPS, and the supervisor.
- To try Sediment on one machine first, follow the Quickstart.
Before you begin
You need the following:- A Debian or Ubuntu host, or macOS with Homebrew, with at least 4 CPU cores and 8 GB of memory
- Git,
curl, and OpenSSL - A dedicated operating-system account to run Sediment
- A dedicated PostgreSQL 17 database on a private network, and a superuser connection to it
- A reverse proxy that serves a stable HTTPS hostname
- Persistent storage for the account’s home directory
Install Sediment
As the account that runs Sediment, install a published release. Replace the example version with the release that you want. Optional: check the release first with Verify a release.PATH, follow it. Then check
the installed version:
Connect PostgreSQL
Sediment needs a PostgreSQL superuser (rolsuper=true) connection to create
its own database roles. Managed database services that don’t grant superuser
access can’t provision Sediment. Don’t point Sediment at a database that
another application uses.
In the server account’s private environment, set the following variables.
Replace the organization, the connection, and the Git hosts that Sediment may
clone from:
Start the API
-
Start the server:
On start, Sediment creates separate migrator, runtime, and operator database roles and applies migrations. The API runs with the runtime role only.
-
In a second terminal, check readiness:
The response shows
"status":"ok"and the installed version. - Stop the server. Configure your process supervisor to run the same command as the same account, with the same private environment. Set it to restart Sediment after a failure and after a host restart.
~/.sediment/server/server.env, and its Git mirrors to
~/.sediment/server/mirror. Keep ~/.sediment/server on persistent storage.
Expose HTTPS
-
Configure your reverse proxy to forward your HTTPS hostname to
http://127.0.0.1:8000. Preserve request bodies andAuthorizationheaders, and rate-limit authentication attempts. The API doesn’t rate-limit them. -
From another machine, check the public endpoint:
The response matches the local check.
Set up an operator shell
Reports, Derivations, exports, and quarantine commands read PostgreSQL directly through thesediment_operator role.
-
On the server, as the server account, set the following variables. Replace
the organization and the database host:
-
Check the schema:
The output shows
at_head. -
Sign in to the API with the operator token:
On loopback,
sediment loginreads the operator token from~/.sediment/server/server.env.sediment factsprints zero counts until the first capture arrives.
Next steps
- Enroll your team.
- Before you rely on the data, set up backups with Maintain a deployment.