Installing Ronne AI Marketplace
Running an instance with Docker or Node, as a service, a domain with HTTPS, the first-run setup, root, and upgrading.
From the Documentation in Ronne AI Marketplace 0.3.0.
With Docker
You need Docker with Compose 2.23.1 or later. On macOS or Linux, the install script does the rest, in a terminal.
curl -fsSL https://www.ronne.ai/marketplace/install.sh | sh
The address redirects to the script in the latest release on GitHub, which also works directly:
https://github.com/ronneai/ronne-marketplace/releases/latest/download/install.sh
It checks that Docker is running, asks whether Ronne runs on this computer or on a server with a domain (then the domain, and an optional email for certificate notices), and checks the ports: on this computer it takes the next free pair after 7650 and 7651 if they're busy. It writes compose.yaml and .env to a ronne-marketplace folder in your home folder, starts Ronne, and opens it in the browser. On this computer, Ronne answers only on this computer (127.0.0.1), not to your network: to reach it from other devices, after the setup put RONNE_PORT=0.0.0.0:7650 and PUBLIC_URL with this computer's address (http://192.168.1.20:7650, say) in that .env (the script keeps both), and run docker compose up -d there. It installs the release it comes from and never uses sudo. Run it again to upgrade: it keeps your answers, and asks before moving to a newer version.
By hand instead, you need one file: compose.yaml from the repository. It pulls the image ronneai/marketplace from Docker Hub, so no clone is needed. SQLite needs no server; for PostgreSQL or MySQL, a profile starts one next to Ronne.
mkdir ronne && cd ronne curl -fsSLO https://raw.githubusercontent.com/ronneai/ronne-marketplace/main/compose.yaml docker compose up -d # then open http://localhost:7650 docker compose --profile postgres up -d # or --profile mysql, with RONNE_DB_PASSWORD set
Then open the address and follow the setup. Your data (the SQLite file, stored items and the settings) lives in the ronne-data volume, mounted at /app/data; back that volume up.
A small proxy, Caddy, runs next to Ronne and is the only way in: it serves HTTP on port 7650 and HTTPS on 7651, ports nothing common uses. Ronne itself listens on 3000 inside, which isn't published. Settings go in a .env file next to compose.yaml; after changing it, run docker compose up -d again. RONNE_PORT=3000 keeps the address of an install from before the proxy.
A domain and HTTPS
Give Ronne a domain and the proxy gets and renews its HTTPS certificate from Let's Encrypt, and sends http:// to https://. First point the domain's DNS (A, and AAAA for IPv6) at the server, and open ports 80 and 443 in its firewall. Then, in .env:
RONNE_DOMAIN=ronne.example.com RONNE_PORT=80 RONNE_HTTPS_PORT=443 [email protected] # optional: expiry notices
The first visit to https://ronne.example.com takes a few seconds while the certificate is issued. PUBLIC_URL follows the domain, unless you set it.
| Setting | Default | What it does |
|---|---|---|
RONNE_PORT | 7650 | The HTTP port on the host. 80 with a domain. |
RONNE_HTTPS_PORT | 7651 | The HTTPS port on the host (TCP, and UDP for HTTP/3). 443 with a domain. |
RONNE_DOMAIN | empty | The name to serve over HTTPS. Empty: HTTP only, on any name. |
RONNE_TLS | auto | With a domain: auto (Let's Encrypt), files (your own certificate) or internal (the proxy's own test CA). |
RONNE_ACME_EMAIL | empty | Where the certificate authority sends expiry notices. |
RONNE_TRUSTED_PROXIES | empty | Which addresses may set X-Forwarded-For, such as private_ranges. Only behind your own proxy. |
PUBLIC_URL | https://RONNE_DOMAIN, or http://localhost:RONNE_PORT | The address people open. Set it when the defaults are wrong. |
- Your own certificate (a private network, or one from your IT team):
RONNE_TLS=files, withcert.pem(the full chain) andkey.pemin acertsfolder next tocompose.yaml. Create the folder before the firstdocker compose up: on Linux, Docker creates a missing one owned by root, and then you needsudoto write to it. After replacing them, rundocker compose up -d --force-recreate proxy.RONNE_TLS=internalissues a test certificate instead; browsers warn until its CA is trusted, andrmkneedsNODE_EXTRA_CA_CERTS. - Behind your own proxy (nginx, Apache, Traefik, a load balancer): leave
RONNE_DOMAINempty, point it athttp://127.0.0.1:7650, and setRONNE_PORT=127.0.0.1:7650,PUBLIC_URLto its https address, andRONNE_TRUSTED_PROXIES=private_ranges, so the audit log and sign-in limits see the client's address from itsX-Forwarded-For(it must append to it). Its request body limit needs to be at least 28 MB, for drafts sent with a token; nginx's default is 1 MB (client_max_body_size 28m;). - Ports 80 or 443 already in use ("port is already allocated"): another web server runs on the host. Use it as your own proxy, as above.
- No certificate: check that the DNS points at the server, that 80 and 443 are open, and that
RONNE_PORTandRONNE_HTTPS_PORTare 80 and 443.docker compose logs proxysays why. - Keep the certificates: they live in the
caddy-datavolume. Never rundocker compose down -v, which deletes it with your data; Let's Encrypt limits how often a domain can ask for new ones.
With apt or dnf
On Debian 12, Ubuntu 22.04, Fedora, RHEL 9 and newer (glibc 2.34 or later), Ronne installs as a package with Node.js inside, no Docker and no Node.js needed. Installing it makes Ronne a service, started at boot and restarted if it stops. Download the .deb or .rpm for your processor (amd64 or arm64) from the latest release on GitHub, then:
sudo apt install ./rmk-server_X.Y.Z-1_amd64.deb # or _arm64.deb sudo dnf install ./rmk-server-X.Y.Z-1.x86_64.rpm # or .aarch64.rpm
Then open http://localhost:7650 and follow the setup. Without Docker, the install script does this for you: it offers the package, checks it against the release's checksums.txt, and asks before running sudo.
- Where things are: the program in
/opt/rmk-server(and/usr/bin/rmk-server), the data in/var/lib/rmk-server, the settings in/etc/rmk-server/env, the log injournalctl -u rmk-server. It's managed with the commands of As a service, including--domainfor HTTPS. - Upgrading: install the new package the same way. The service restarts on it with the options it had, and migrations run on start.
- Removing:
sudo apt remove rmk-server(ordnf remove) stops and removes the service and keeps the data and settings;apt purgeanddnf removeprint the command that deletes them. - Without systemd (a container): the package installs, and says how to start Ronne by hand.
With Node.js
With Node.js 22.12 or later, one command downloads and starts Ronne, with no clone, no Docker and no build. Its command is rmk-server.
npx @ronneai/marketplace # then open http://localhost:7650 npm install --global @ronneai/marketplace # or keep it installed, then: rmk-server
Then follow the setup; on a terminal, the first start opens the browser. rmk-server setup runs the setup in the terminal instead (--yes for scripts), rmk-server migrate applies migrations, and rmk-server reset-root-password resets root's password.
- Network: it listens on
127.0.0.1:7650, this machine only.--host 0.0.0.0(orHOST) makes it reachable from the network, and--port(orPORT) changes the port. A busy port stops it rather than picking another, since the address is saved in the settings. - Data (settings, the SQLite database, stored items) lives in
RONNE_DATA_DIR, or by default in~/Library/Application Support/RonneAI Marketplaceon macOS,~/.local/share/rmk-serveron Linux (or underXDG_DATA_HOME), and%LOCALAPPDATA%\RonneAI\Marketplaceon Windows. - Upgrading:
npx @ronneai/marketplace@latest, ornpm install --global @ronneai/marketplaceagain. Migrations run on start.
Working on Ronne itself? From a clone, with pnpm: pnpm install, then pnpm build && pnpm start (or pnpm dev) on http://localhost:3000. The settings go to apps/web/.env and a SQLite database to apps/web/data/ by default.
As a service
On macOS, Linux and Windows, rmk-server can run as a service: in the background, started at boot and restarted if it stops (systemd on Linux, launchd on macOS, WinSW on Windows). Install Node.js for the whole machine first: the service runs under its own account, which can't read a Node.js in your home folder (nvm). If sudo rmk-server isn't found, keep your PATH: sudo env "PATH=$PATH" rmk-server service install.
npm install --global @ronneai/marketplace sudo rmk-server service install # then open http://localhost:7650 and finish the setup
| Command | Does |
|---|---|
rmk-server service status | Installed or not, running or not, the version, address, account, folders and proxy. The only one without sudo. |
sudo rmk-server service stop | start | restart | Stops, starts or restarts it. Restart after upgrading with npm. |
sudo rmk-server service logs | Follows its log. |
sudo rmk-server service uninstall | Removes the service and the accounts it made. The data and settings stay, and installing again uses them; --delete-data deletes them too, after you type the data folder's name. |
sudo rmk-server setup | The setup in the terminal, for the service's data (migrate and reset-root-password too). |
- Where things are on Linux: data in
/var/lib/rmk-server, settings in/etc/rmk-server/env, the log injournalctl -u rmk-server, run by thermk-serveraccount. On macOS: data in/usr/local/var/rmk-server(with Homebrew,/opt/homebrew/var/rmk-server), settings in the same prefix'setc/rmk-server/env, the log in/Library/Logs/rmk-server/server.log, run by_rmkserver, or by you with--user. macOS may show a notification about a new background item: that's the service. - Options:
--port(7650) and--host(127.0.0.1, this machine only;0.0.0.0opens it to the network over plain HTTP, so put it behind HTTPS). Running install again with other options updates the service and keeps the data. - A domain with HTTPS:
sudo rmk-server service install --domain ronne.example.comadds a second service,rmk-server-proxy, running Caddy on ports 80 and 443 with the same settings as Docker's proxy. It needs Caddy 2.7 or later on PATH (Debian's and Ubuntu's own package is too old: use Caddy's repository, orbrew install caddy), and stops if another web server holds 80 or 443.--tls internaluses Caddy's own authority;--tls filesreadscert.pemandkey.pemfrom/etc/rmk-server-proxy/certs(on macOS, the prefix'setc/rmk-server-proxy/certs; copies, not links; copy them again after each renewal and restart);--emailgets expiry notices. - On Windows, run the same commands without
sudo, in a terminal opened as administrator (right-click PowerShell or Terminal, Run as administrator);statusworks in any terminal, with the details for administrators. The service's account can't read your profile, where npm's global folder is (%APPDATA%\npm), so install refuses anrmk-serverthere. Use the Windows bundle (rmk-server-X.Y.Z-win32-x64.zip, or-arm64, with Node.js inside; attached to the releases from the one after 0.2.0): unzip it intoC:\Program Files\RonneAI, rename its folder toMarketplace, and run itsbin\rmk-server.cmd. Or, in the same administrator's terminal, install with npm into a folder for the whole machine and run itsrmk-server.cmdby its full path (that folder isn't on PATH): the commands are below. Data inC:\ProgramData\, settings inRonneAI\ Marketplace\ data …\Marketplace\.env, logs in…\Marketplace\logs\rmk-server-service.out.log(and.err.log), run byNT SERVICE\rmk-server. Without a domain,--host 0.0.0.0also adds a firewall rule for the port, on Private networks.--domainneeds Caddy for the whole machine (winget install --id CaddyServer.Caddy --scope machine; one in your profile is refused), adds a firewall rule for 80 and 443 on every network, and--tls filesreads…\Marketplace\proxy\certs.setup,migrateandreset-root-passwordwork on the service's data, as you. - Without systemd (a container, WSL 1, another init system): there's no service to install. Run
rmk-server start --no-openunder your own supervisor, or use Docker.
On Windows, in a terminal opened as administrator:
# The Windows bundle, unzipped and renamed: & "C:\Program Files\RonneAI\Marketplace\bin\rmk-server.cmd" service install # Or npm, into a folder for the whole machine: npm install --global --prefix "C:\Program Files\RonneAI\npm" @ronneai/marketplace & "C:\Program Files\RonneAI\npm\rmk-server.cmd" service install
The setup
Until the instance is set up, every page opens the setup, and the API answers 503 setup_required. The setup asks for:
- The database. SQLite (the default: a file, nothing else to install), MySQL or MariaDB, or PostgreSQL, with the host, port, name, user and password of an existing, empty database. Test connection connects, checks the server version and, on MySQL, the
utf8mb4character set, and checks that the user can create, write, read and drop tables (through a probe table it removes again). A problem is explained in plain words, with the driver's message. - The public address: where people open Ronne AI Marketplace. When it comes from the environment (as
compose.yamlsetsPUBLIC_URL), it's shown read-only, since the environment wins over the settings file. - The root account: email, display name and a password of 12 to 128 characters, typed twice.
- Install: the settings are written, the migrations applied and the root account created, each shown as it happens. A failure returns to the question it's about; Retry resumes from the failed step. Then Sign in opens the sign-in page with the root email filled in. Nothing needs a restart.
A setup that was interrupted after the settings were written resumes at Install on the next visit, keeping the database. Anyone who can open the address before you can set the instance up, so open it right after starting it. Running the setup again never creates a root when one exists: more roots are added from Users.
Root accounts
The setup creates the first root account. A root can do everything a moderator can, plus create and manage users, create scopes, change the instance's settings and read the audit log. Nobody signs up: a root creates every other account.
There can be several roots. In Admin › Users, any root can make another account root (when creating it, or with Change role) and change anyone's role, roots included. Roots manage each other: one can disable another or reset their password. Nobody changes their own account there; you change your password in Account, and another root does the rest. The instance always keeps at least one active root: a change that would leave none is refused.
A forgotten root password can be reset by another root in Users. If there's no other root, reset it where the instance is installed: pnpm run reset-root-password (in Docker, docker compose exec web pnpm run reset-root-password). With several roots, it asks which one, or takes --email with --yes. It sets a new password, signs that root out everywhere, revokes its access tokens and re-enables the account if it was disabled.
Upgrading
docker compose pull && docker compose up -d # Docker npm install --global @ronneai/marketplace@latest # npm sudo rmk-server service restart # npm, as a service: then this sudo apt install ./rmk-server_X.Y.Z-1_amd64.deb # a package: the new one (or dnf install) git pull && pnpm install && pnpm build && pnpm start # a clone
Pending database migrations run when the server starts. If one fails, the server stops instead of serving a half-migrated database. Each release is tagged X.Y.Z, X.Y and latest on Docker Hub; to pin one, set RONNE_IMAGE=ronneai/marketplace:X.Y.Z next to compose.yaml. The image and the npm packages share a version.