Deployment Guide • Production-Ready • Ubuntu 22.04 / 24.04 LTS

First-Time Installation & Setup Guide

Deploy GoSecureShare on your own private infrastructure. Choose between the recommended Automated 1-Command Installer (<5 minutes) or manual Docker Compose configuration.

OS Target
Ubuntu 22/24 LTS
Min Compute
1 vCPU • 1 GB RAM
Deployment
Docker Compose
Registry
GitHub GHCR
1

Method 1 (Recommended): 30-Day Evaluation Trial Installer

30-Day Trial • 5-Min Setup

Deploy a fully functional 30-day GoSecureShare Enterprise evaluation on a fresh Ubuntu 22.04 or 24.04 LTS server. No credit card or GitHub personal access token (PAT) required — the installer automatically configures Docker, Nginx SSL, database, and a local 30-day evaluation license:

bash — run as root or sudo
curl -fsSL https://raw.githubusercontent.com/kisa-ops/GSS-trial/main/install.sh | sudo bash
What the 30-Day Trial Installer Performs:
check_circle Checks system prerequisites (CPU, RAM, disk space) and installs Docker Engine & Docker Compose if not present.
check_circle Creates the deployment directory structure under /opt/gosecureshare/.
check_circle Generates cryptographic secrets and AES-256 KMS master encryption keys using openssl rand -base64 32.
check_circle Generates an offline 30-day evaluation enterprise license key automatically without external phone-home dependencies.
check_circle Configures Nginx reverse proxy with TLS certificates and brings up the complete enterprise platform.
Seamless Production Upgrade: When upgrading from the 30-day trial to the full annual license ($499/yr), simply update the license key in /opt/gosecureshare/.env and restart containers. All configuration, settings, and database secrets are fully preserved.
2

Method 2: Manual Advanced Docker Compose Deployment

For custom DevOps pipelines, Kubernetes migrations, or internal registries.

A

Authenticate to GitHub Container Registry (GHCR)

GoSecureShare Enterprise container images are hosted on GHCR. Authenticate your Docker daemon using your GitHub Personal Access Token (PAT) with the read:packages scope:

bash
echo $CR_PAT | docker login ghcr.io -u YOUR_GITHUB_USERNAME --password-stdin
B

Create Directory & Environment File (.env)

Create a dedicated deployment folder and create the .env file containing your domain, database passwords, and KMS master key:

bash
git clone https://github.com/kisa-ops/GoSecureShare.git /opt/gosecureshare && cd /opt/gosecureshare
.env template
APP_ENV=production APP_DOMAIN=vault.yourcompany.com POSTGRES_DB=gosecureshare POSTGRES_USER=gss_user POSTGRES_PASSWORD=<generate-with-openssl> MASTER_KMS_KEY=<generate-32-byte-base64> SESSION_SECRET=<generate-32-byte-base64>
C

Pull Images & Start Services

Launch the PostgreSQL database, backend API, frontend web application, and Nginx reverse proxy containers:

bash
docker compose pull && docker compose up -d

build Day-2 Operations & Maintenance

Service Health Check

Verify that all 4 containers are reporting healthy status:

docker compose ps
Tail Live Logs

Inspect real-time authentication and secret API events:

docker compose logs -f backend
Automated Backup

Take an encrypted snapshot of the PostgreSQL database:

docker compose exec -T db pg_dump -U gss_user gosecureshare > backup.sql
One-Click Upgrade

Pull the latest GHCR enterprise container release and restart:

docker compose pull && docker compose up -d

Need Assisted Enterprise Onboarding?

Our engineering team can assist your security or infrastructure team with Active Directory SSO configuration, firewall rules, and custom domain setup.