Skip to content

Install ​

OpenMeshTak runs as one container. It serves the Web app, the API and the built-in TAK server. This page takes you from an empty server to the first administrator account.

What you need ​

  • a Linux server with Docker Engine and Docker Compose;
  • a public DNS name for it, for example tak.example.org;
  • a reverse proxy that serves HTTPS for that name, see Reverse proxy; and
  • the public TAK ports 8446, 8443 and 8089, see TAK ports.

1. Get the files ​

Create a directory on the server and save this file as docker-compose.yml (download):

yml
# OpenMeshTak sample deployment: one container runs Core with the Web app, the API and the
# built-in TAK server. Put these values into a .env file next to this file:
#
#   OPENMESHTAK_VERSION=0.1.0            # optional, default latest; pin it to upgrade deliberately
#   PUBLIC_HOST=openmeshtak.example.org  # public HTTPS host name of the Web app
#   ROOT_ENCRYPTION_KEY=...              # once: openssl rand -base64 32
#
# The root key is the installation's only secret. Back it up separately and never change it:
# without it, stored secrets such as channel keys and the TAK CA key cannot be decrypted. To keep it
# out of .env, put it in a file instead and use the commented secret lines below.
#
# Your reverse proxy (nginx, Caddy, a hosting panel, ...) terminates HTTPS for PUBLIC_HOST and
# forwards to http://127.0.0.1:8080. The bootstrap token for the first administrator is in
# `docker compose logs core`. TRUST_PROXY makes Core take the client address from the last
# X-Forwarded-For entry, which your proxy adds, so rate limits apply per client. Without it every
# request seems to come from the Docker gateway and all clients share one limit. This is only safe
# while 8080 is published on 127.0.0.1; if anything else can reach it, set TRUST_PROXY=false.
#
# The TAK ports go straight to Core, which terminates mutual TLS itself. The left side of each
# mapping is the public port and must match the TAK server page in the Web app, the only source
# for QR codes and profiles. If 8443 is taken (some hosting panels use it), publish Data Packages
# on e.g. "8484:8443" and enter 8484 on the TAK server page; iTAK then gets no server Data
# Packages. Keep 8446 and 8089: ATAK Quick Connect expects them.

name: openmeshtak

services:
  core:
    image: ghcr.io/openmeshtak/openmeshtak:${OPENMESHTAK_VERSION:-latest}
    restart: unless-stopped
    environment:
      PUBLIC_ORIGIN: https://${PUBLIC_HOST:?Set PUBLIC_HOST in .env}
      # Or keep the key in a file: remove this line and uncomment both secret blocks.
      ROOT_ENCRYPTION_KEY: ${ROOT_ENCRYPTION_KEY:?Set ROOT_ENCRYPTION_KEY in .env}
      LOG_LEVEL: ${LOG_LEVEL:-info}
      # Only the reverse proxy reaches port 8080 below, so its X-Forwarded-For entry is trusted.
      TRUST_PROXY: ${TRUST_PROXY:-true}
      # Swagger UI at https://<PUBLIC_HOST>/api/docs
      SWAGGER_ENABLED: ${SWAGGER_ENABLED:-false}
    # secrets:
    #   - root_encryption_key
    volumes:
      - core-data:/server/data
      # To reuse your reverse proxy's certificate for the TAK host, mount its certificate directory
      # read-only and choose "Reverse proxy files" on the TAK server page, e.g. for certbot:
      # - /etc/letsencrypt:/server/certs:ro
    ports:
      # Web app and API, for the reverse proxy only.
      - "127.0.0.1:8080:3000"
      # TAK enrollment, Data Packages (Marti) and CoT streaming.
      - "8446:8446"
      - "8443:8443"
      - "8089:8089"

# secrets:
#   root_encryption_key:
#     file: ./root_encryption_key

volumes:
  core-data:

Next to it, save the .env example as .env.

2. Fill in .env ​

SettingValue
OPENMESHTAK_VERSIONOptional. Without it, the newest release (latest) runs. Set an exact release such as 0.3.4 to upgrade only when you choose.
PUBLIC_HOSTThe public DNS name without https://, for example tak.example.org.
ROOT_ENCRYPTION_KEYThe root key, see below.

latest or a fixed version?

With latest, every docker compose pull can bring a new version, and OpenMeshTak updates its database on the next start. That is convenient, but make a backup before pulling. A fixed version only changes when you edit .env, so nothing updates by surprise, for example shortly before an event.

The root key ​

The root key is the installation's only secret. It encrypts stored secrets such as channel keys and the TAK certificate authority, and signs sign-in sessions. Create it once and paste the output as ROOT_ENCRYPTION_KEY:

sh
openssl rand -base64 32

Copy it to a safe place right away and never change it. Without it, stored secrets cannot be read and a backup cannot be restored.

Keep .env private and out of version control.

Keep the key in a separate file instead

Save the key with openssl rand -base64 32 > root_encryption_key and chmod 600 root_encryption_key. In docker-compose.yml, remove the ROOT_ENCRYPTION_KEY line and uncomment both secrets blocks. Then .env contains no secret. Setting the key in both places stops OpenMeshTak from starting.

3. Start ​

sh
docker compose up -d

If Docker reports that a port is already allocated, another program uses it; follow TAK ports.

Check that Core is running:

sh
curl --fail https://tak.example.org/api/v1/health

4. Create the first administrator ​

  1. Read the one-time setup token: docker compose logs core.
  2. Open https://tak.example.org and enter the token.
  3. Create the administrator account. Its username is also the TAK login, so choose it well.
  4. Add a passkey if you like.

Then go through Configure the installation.

OpenMeshTak documentation is licensed under CC BY 4.0.