Install
OpenMeshTak runs as one container. It serves the Web app, the API and the built-in TAK server. This page takes you from an empty server to the first administrator account.
What you need
- a Linux server with Docker Engine and Docker Compose;
- a public DNS name for it, for example
tak.example.org; - a reverse proxy that serves HTTPS for that name, see Reverse proxy; and
- the public TAK ports
8446,8443and8089, see TAK ports.
1. Get the files
Create a directory on the server and save this file as docker-compose.yml (download):
# OpenMeshTak sample deployment: one container runs Core with the Web app, the API and the
# built-in TAK server. Put these values into a .env file next to this file:
#
# OPENMESHTAK_VERSION=0.1.0 # optional, default latest; pin it to upgrade deliberately
# PUBLIC_HOST=openmeshtak.example.org # public HTTPS host name of the Web app
# ROOT_ENCRYPTION_KEY=... # once: openssl rand -base64 32
#
# The root key is the installation's only secret. Back it up separately and never change it:
# without it, stored secrets such as channel keys and the TAK CA key cannot be decrypted. To keep it
# out of .env, put it in a file instead and use the commented secret lines below.
#
# Your reverse proxy (nginx, Caddy, a hosting panel, ...) terminates HTTPS for PUBLIC_HOST and
# forwards to http://127.0.0.1:8080. The bootstrap token for the first administrator is in
# `docker compose logs core`. TRUST_PROXY makes Core take the client address from the last
# X-Forwarded-For entry, which your proxy adds, so rate limits apply per client. Without it every
# request seems to come from the Docker gateway and all clients share one limit. This is only safe
# while 8080 is published on 127.0.0.1; if anything else can reach it, set TRUST_PROXY=false.
#
# The TAK ports go straight to Core, which terminates mutual TLS itself. The left side of each
# mapping is the public port and must match the TAK server page in the Web app, the only source
# for QR codes and profiles. If 8443 is taken (some hosting panels use it), publish Data Packages
# on e.g. "8484:8443" and enter 8484 on the TAK server page; iTAK then gets no server Data
# Packages. Keep 8446 and 8089: ATAK Quick Connect expects them.
name: openmeshtak
services:
core:
image: ghcr.io/openmeshtak/openmeshtak:${OPENMESHTAK_VERSION:-latest}
restart: unless-stopped
environment:
PUBLIC_ORIGIN: https://${PUBLIC_HOST:?Set PUBLIC_HOST in .env}
# Or keep the key in a file: remove this line and uncomment both secret blocks.
ROOT_ENCRYPTION_KEY: ${ROOT_ENCRYPTION_KEY:?Set ROOT_ENCRYPTION_KEY in .env}
LOG_LEVEL: ${LOG_LEVEL:-info}
# Only the reverse proxy reaches port 8080 below, so its X-Forwarded-For entry is trusted.
TRUST_PROXY: ${TRUST_PROXY:-true}
# Swagger UI at https://<PUBLIC_HOST>/api/docs
SWAGGER_ENABLED: ${SWAGGER_ENABLED:-false}
# secrets:
# - root_encryption_key
volumes:
- core-data:/server/data
# To reuse your reverse proxy's certificate for the TAK host, mount its certificate directory
# read-only and choose "Reverse proxy files" on the TAK server page, e.g. for certbot:
# - /etc/letsencrypt:/server/certs:ro
ports:
# Web app and API, for the reverse proxy only.
- "127.0.0.1:8080:3000"
# TAK enrollment, Data Packages (Marti) and CoT streaming.
- "8446:8446"
- "8443:8443"
- "8089:8089"
# secrets:
# root_encryption_key:
# file: ./root_encryption_key
volumes:
core-data:Next to it, save the .env example as .env.
2. Fill in .env
| Setting | Value |
|---|---|
OPENMESHTAK_VERSION | Optional. Without it, the newest release (latest) runs. Set an exact release such as 0.3.4 to upgrade only when you choose. |
PUBLIC_HOST | The public DNS name without https://, for example tak.example.org. |
ROOT_ENCRYPTION_KEY | The root key, see below. |
latest or a fixed version?
With latest, every docker compose pull can bring a new version, and OpenMeshTak updates its database on the next start. That is convenient, but make a backup before pulling. A fixed version only changes when you edit .env, so nothing updates by surprise, for example shortly before an event.
The root key
The root key is the installation's only secret. It encrypts stored secrets such as channel keys and the TAK certificate authority, and signs sign-in sessions. Create it once and paste the output as ROOT_ENCRYPTION_KEY:
openssl rand -base64 32Copy it to a safe place right away and never change it. Without it, stored secrets cannot be read and a backup cannot be restored.
Keep .env private and out of version control.
Keep the key in a separate file instead
Save the key with openssl rand -base64 32 > root_encryption_key and chmod 600 root_encryption_key. In docker-compose.yml, remove the ROOT_ENCRYPTION_KEY line and uncomment both secrets blocks. Then .env contains no secret. Setting the key in both places stops OpenMeshTak from starting.
3. Start
docker compose up -dIf Docker reports that a port is already allocated, another program uses it; follow TAK ports.
Check that Core is running:
curl --fail https://tak.example.org/api/v1/health4. Create the first administrator
- Read the one-time setup token:
docker compose logs core. - Open
https://tak.example.organd enter the token. - Create the administrator account. Its username is also the TAK login, so choose it well.
- Add a passkey if you like.
Then go through Configure the installation.