Skip to main content

Install Overview

Ithiltir has two deployment targets: the Dash control plane and Ithiltir-node instances. Dash must be available first because Node install scripts and binaries are distributed from Dash under /deploy.

Choose an Installation Path

PathUse caseStart here
Quick validationSingle host, small scale, personal useQuick Start
Single-host productionDash, PostgreSQL, TimescaleDB, and Redis on one hostAll-in-One Deployment
Standard productionDash + reverse proxy + managed database operationsProduction Deployment Checklist
Source validationDevelopment, troubleshooting, config validationSource and Manual Run

Deployment Order

  1. Confirm the Linux architecture and runtime mode. Use systemd service mode or explicit --service-manager=none.
  2. Download and extract the Dash release package.
  3. Run install_dash_linux.sh.
  4. Follow the prompts for app.public_url, database, Redis, admin password, and trusted reverse proxies.
  5. Let the installer run migrations and start dash.service.
  6. Configure the reverse proxy and verify /api, /theme, /deploy, and / are same-origin.
  7. Create nodes in the admin console.
  8. Install nodes with the scripts served by Dash.

The release package installer checks PostgreSQL 16+, TimescaleDB, and Redis. If they are missing or too old, it uses the distribution package manager when possible and may prompt for a Redis source build. Debian/Ubuntu systems that use apt-get do not need these dependencies installed manually first.

The recommended deployment shape is: domain + HTTPS + Nginx/Caddy reverse proxy. Dash listens on a local or private backend address such as 127.0.0.1:8080; external clients only access https://dash.example.com/. Direct http://IP:port exposure is only for temporary validation or controlled internal testing.

Deployment Boundaries

BoundaryConstraint
DashSingle instance; multiple Dash writers against the same state are not supported
PostgreSQLStores nodes, metrics, traffic, alerts, settings, and theme metadata
RedisStores admin sessions and disposable frontend caches
Reverse proxyRecommended for production; keep same-origin root paths through Nginx, Caddy, or a load balancer
NodesUse push mode to call Dash /api/node/* endpoints

Public Paths

Dash exposes these paths to browsers and nodes:

https://dash.example.com/
https://dash.example.com/api
https://dash.example.com/theme
https://dash.example.com/deploy

Nodes report metrics to:

https://dash.example.com/api/node/metrics

Static inventory is sent to:

https://dash.example.com/api/node/static

Hard Constraints

  • app.public_url must be a root URL and must not contain a path prefix such as /dash.
  • Production app.public_url should be an HTTPS domain, not direct IP+HTTP.
  • The reverse proxy must keep same-origin paths; cross-origin backend addresses require CORS, cookie, and CSRF policies to be configured together.
  • Node secrets are only for /api/node/*; never embed them in browser code.
  • Dash is a single-instance application; do not run multiple writers against the same database.
  • --no-redis moves sessions and frontend cache to process memory. Alert pending/cooldown and MTProto login state are process-local in both modes.