Prepare the instance
- Launch an Ubuntu 24.04 instance on 64-bit Intel, AMD, or Arm hardware. Give it at least 4 virtual CPUs (vCPUs), 8 GB of memory, and encrypted persistent storage for the database, credentials, mirrors, and backups.
- Sign in over SSH as a dedicated non-root operator account that has
sudoaccess. Run the remaining commands on this page from that session. - Install
curl, OpenSSL, and Docker Engine with its Compose plugin. For Docker, follow Install Docker Engine on Ubuntu. - To run Docker as a non-root user, follow Linux post-installation steps for Docker Engine, and then sign in again. Docker access gives this account root-level control of the host.
- Run
docker infoanddocker compose versionwithoutsudo. Both commands succeed. - Associate an Elastic IP address with the instance.
- Point your hostname’s DNS A record at the Elastic IP address. If you also publish an AAAA record, make the host reachable over IPv6.
- Configure the instance security group and the host firewall:
- Allow inbound TCP ports 80 and 443. Certificate renewal requires inbound port 80 and outbound access to the certificate authority.
- Restrict SSH to the operator’s IP address.
- Keep ports 5432 and 8000 private.
Install Sediment
- Select a published release. Optional: check it with Verify a release.
-
As the operator account, run the installer. This example installs version
0.3.0:
The output shows the version that you selected.
UV_NO_BUILD=1 makes the installation fail instead of building a missing wheel
from source.
Configure PostgreSQL and Traefik
-
Create a private deployment directory and its environment files. Before you
run the following commands, replace the example hostname, certificate contact
email, and organization. The commands stop if the directory already exists.
Keep
.env,server.env, andcertificates/private. Don’t source these files or share them with developers. -
Save the following as
compose.yamlin~/sediment-deploy: -
Save the following as
routes.ymlbesidecompose.yaml: -
Make the routing file readable by the proxy, and then start the database:
PostgreSQL reports
healthy. If it doesn’t, inspectdocker compose logs --tail 100 postgresbefore you continue.
Run Sediment as a service
-
Create the systemd user directory:
mkdir -p ~/.config/systemd/user. -
Save the following unit as
~/.config/systemd/user/sediment.service: -
Enable startup at boot and after logout, and then start Sediment:
The health response shows
"status":"ok"and the version that you selected. If startup fails, inspectjournalctl --user -u sediment.service -n 100 --no-pager.
~/.sediment/server/server.env, and its Git
mirrors to ~/.sediment/server/mirror.
Enable and verify HTTPS
-
From
~/sediment-deploy, start Traefik and check the public endpoint:The health response matches the local check. Don’t bypass certificate verification.
docker compose restart proxy and repeat the
public health check.
The request limit applies to each client address: an average of 100 requests
per second, with bursts of 200. Clients behind one outbound address share that
limit.
Set up an operator shell
Reports, Derivations, exports, and quarantine commands read PostgreSQL directly through thesediment_operator role.
-
In your SSH session, set the following variables. Set
SEDIMENT_ORG_IDto the value in~/sediment-deploy/server.env: -
Check the schema:
The output shows
at_head. -
Sign in to the API with the operator token:
On loopback,
sediment loginreads the operator token from~/.sediment/server/server.env.sediment factsprints zero counts until the first capture arrives.
Manage the services
Where another page tells you to stop, start, restart, or inspect Sediment, use these commands:
Stop the API before you stop the database.
Warning:
docker compose down --volumes permanently deletes the database.
To upgrade Sediment, follow
Maintain a deployment, and rerun the installer
command from Install Sediment with the target version. To
upgrade PostgreSQL or Traefik, follow its own release notes. Don’t change the
PostgreSQL major version on an existing volume.
Next steps
- Enroll your team with
https://sediment.example.comas the endpoint. - A single instance is a single point of failure. Before you rely on the
data, set up backups of the
postgres-datavolume,~/sediment-deploy, and~/.sediment/server.