Skip to content
Documentation: Installing

Installing Ronne AI Marketplace

Running an instance with Docker or Node, as a service, a domain with HTTPS, the first-run setup, root, and upgrading.

From the Documentation in Ronne AI Marketplace 0.3.0.

With Docker

You need Docker with Compose 2.23.1 or later. On macOS or Linux, the install script does the rest, in a terminal.

curl -fsSL https://www.ronne.ai/marketplace/install.sh | sh

The address redirects to the script in the latest release on GitHub, which also works directly:

https://github.com/ronneai/ronne-marketplace/releases/latest/download/install.sh

It checks that Docker is running, asks whether Ronne runs on this computer or on a server with a domain (then the domain, and an optional email for certificate notices), and checks the ports: on this computer it takes the next free pair after 7650 and 7651 if they're busy. It writes compose.yaml and .env to a ronne-marketplace folder in your home folder, starts Ronne, and opens it in the browser. On this computer, Ronne answers only on this computer (127.0.0.1), not to your network: to reach it from other devices, after the setup put RONNE_PORT=0.0.0.0:7650 and PUBLIC_URL with this computer's address (http://192.168.1.20:7650, say) in that .env (the script keeps both), and run docker compose up -d there. It installs the release it comes from and never uses sudo. Run it again to upgrade: it keeps your answers, and asks before moving to a newer version.

By hand instead, you need one file: compose.yaml from the repository. It pulls the image ronneai/marketplace from Docker Hub, so no clone is needed. SQLite needs no server; for PostgreSQL or MySQL, a profile starts one next to Ronne.

mkdir ronne && cd ronne
curl -fsSLO https://raw.githubusercontent.com/ronneai/ronne-marketplace/main/compose.yaml
docker compose up -d                          # then open http://localhost:7650
docker compose --profile postgres up -d       # or --profile mysql, with RONNE_DB_PASSWORD set

Then open the address and follow the setup. Your data (the SQLite file, stored items and the settings) lives in the ronne-data volume, mounted at /app/data; back that volume up.

A small proxy, Caddy, runs next to Ronne and is the only way in: it serves HTTP on port 7650 and HTTPS on 7651, ports nothing common uses. Ronne itself listens on 3000 inside, which isn't published. Settings go in a .env file next to compose.yaml; after changing it, run docker compose up -d again. RONNE_PORT=3000 keeps the address of an install from before the proxy.

A domain and HTTPS

Give Ronne a domain and the proxy gets and renews its HTTPS certificate from Let's Encrypt, and sends http:// to https://. First point the domain's DNS (A, and AAAA for IPv6) at the server, and open ports 80 and 443 in its firewall. Then, in .env:

RONNE_DOMAIN=ronne.example.com
RONNE_PORT=80
RONNE_HTTPS_PORT=443
[email protected]   # optional: expiry notices

The first visit to https://ronne.example.com takes a few seconds while the certificate is issued. PUBLIC_URL follows the domain, unless you set it.

SettingDefaultWhat it does
RONNE_PORT7650The HTTP port on the host. 80 with a domain.
RONNE_HTTPS_PORT7651The HTTPS port on the host (TCP, and UDP for HTTP/3). 443 with a domain.
RONNE_DOMAINemptyThe name to serve over HTTPS. Empty: HTTP only, on any name.
RONNE_TLSautoWith a domain: auto (Let's Encrypt), files (your own certificate) or internal (the proxy's own test CA).
RONNE_ACME_EMAILemptyWhere the certificate authority sends expiry notices.
RONNE_TRUSTED_PROXIESemptyWhich addresses may set X-Forwarded-For, such as private_ranges. Only behind your own proxy.
PUBLIC_URLhttps://RONNE_DOMAIN, or http://localhost:RONNE_PORTThe address people open. Set it when the defaults are wrong.
  • Your own certificate (a private network, or one from your IT team): RONNE_TLS=files, with cert.pem (the full chain) and key.pem in a certs folder next to compose.yaml. Create the folder before the first docker compose up: on Linux, Docker creates a missing one owned by root, and then you need sudo to write to it. After replacing them, run docker compose up -d --force-recreate proxy. RONNE_TLS=internal issues a test certificate instead; browsers warn until its CA is trusted, and rmk needs NODE_EXTRA_CA_CERTS.
  • Behind your own proxy (nginx, Apache, Traefik, a load balancer): leave RONNE_DOMAIN empty, point it at http://127.0.0.1:7650, and set RONNE_PORT=127.0.0.1:7650, PUBLIC_URL to its https address, and RONNE_TRUSTED_PROXIES=private_ranges, so the audit log and sign-in limits see the client's address from its X-Forwarded-For (it must append to it). Its request body limit needs to be at least 28 MB, for drafts sent with a token; nginx's default is 1 MB (client_max_body_size 28m;).
  • Ports 80 or 443 already in use ("port is already allocated"): another web server runs on the host. Use it as your own proxy, as above.
  • No certificate: check that the DNS points at the server, that 80 and 443 are open, and that RONNE_PORT and RONNE_HTTPS_PORT are 80 and 443. docker compose logs proxy says why.
  • Keep the certificates: they live in the caddy-data volume. Never run docker compose down -v, which deletes it with your data; Let's Encrypt limits how often a domain can ask for new ones.

With apt or dnf

On Debian 12, Ubuntu 22.04, Fedora, RHEL 9 and newer (glibc 2.34 or later), Ronne installs as a package with Node.js inside, no Docker and no Node.js needed. Installing it makes Ronne a service, started at boot and restarted if it stops. Download the .deb or .rpm for your processor (amd64 or arm64) from the latest release on GitHub, then:

sudo apt install ./rmk-server_X.Y.Z-1_amd64.deb     # or _arm64.deb
sudo dnf install ./rmk-server-X.Y.Z-1.x86_64.rpm    # or .aarch64.rpm

Then open http://localhost:7650 and follow the setup. Without Docker, the install script does this for you: it offers the package, checks it against the release's checksums.txt, and asks before running sudo.

  • Where things are: the program in /opt/rmk-server (and /usr/bin/rmk-server), the data in /var/lib/rmk-server, the settings in /etc/rmk-server/env, the log in journalctl -u rmk-server. It's managed with the commands of As a service, including --domain for HTTPS.
  • Upgrading: install the new package the same way. The service restarts on it with the options it had, and migrations run on start.
  • Removing: sudo apt remove rmk-server (or dnf remove) stops and removes the service and keeps the data and settings; apt purge and dnf remove print the command that deletes them.
  • Without systemd (a container): the package installs, and says how to start Ronne by hand.

With Node.js

With Node.js 22.12 or later, one command downloads and starts Ronne, with no clone, no Docker and no build. Its command is rmk-server.

npx @ronneai/marketplace                    # then open http://localhost:7650
npm install --global @ronneai/marketplace    # or keep it installed, then: rmk-server

Then follow the setup; on a terminal, the first start opens the browser. rmk-server setup runs the setup in the terminal instead (--yes for scripts), rmk-server migrate applies migrations, and rmk-server reset-root-password resets root's password.

  • Network: it listens on 127.0.0.1:7650, this machine only. --host 0.0.0.0 (or HOST) makes it reachable from the network, and --port (or PORT) changes the port. A busy port stops it rather than picking another, since the address is saved in the settings.
  • Data (settings, the SQLite database, stored items) lives in RONNE_DATA_DIR, or by default in ~/Library/Application Support/RonneAI Marketplace on macOS, ~/.local/share/rmk-server on Linux (or under XDG_DATA_HOME), and %LOCALAPPDATA%\RonneAI\Marketplace on Windows.
  • Upgrading: npx @ronneai/marketplace@latest, or npm install --global @ronneai/marketplace again. Migrations run on start.

Working on Ronne itself? From a clone, with pnpm: pnpm install, then pnpm build && pnpm start (or pnpm dev) on http://localhost:3000. The settings go to apps/web/.env and a SQLite database to apps/web/data/ by default.

As a service

On macOS, Linux and Windows, rmk-server can run as a service: in the background, started at boot and restarted if it stops (systemd on Linux, launchd on macOS, WinSW on Windows). Install Node.js for the whole machine first: the service runs under its own account, which can't read a Node.js in your home folder (nvm). If sudo rmk-server isn't found, keep your PATH: sudo env "PATH=$PATH" rmk-server service install.

npm install --global @ronneai/marketplace
sudo rmk-server service install      # then open http://localhost:7650 and finish the setup
CommandDoes
rmk-server service statusInstalled or not, running or not, the version, address, account, folders and proxy. The only one without sudo.
sudo rmk-server service stop | start | restartStops, starts or restarts it. Restart after upgrading with npm.
sudo rmk-server service logsFollows its log.
sudo rmk-server service uninstallRemoves the service and the accounts it made. The data and settings stay, and installing again uses them; --delete-data deletes them too, after you type the data folder's name.
sudo rmk-server setupThe setup in the terminal, for the service's data (migrate and reset-root-password too).
  • Where things are on Linux: data in /var/lib/rmk-server, settings in /etc/rmk-server/env, the log in journalctl -u rmk-server, run by the rmk-server account. On macOS: data in /usr/local/var/rmk-server (with Homebrew, /opt/homebrew/var/rmk-server), settings in the same prefix's etc/rmk-server/env, the log in /Library/Logs/rmk-server/server.log, run by _rmkserver, or by you with --user. macOS may show a notification about a new background item: that's the service.
  • Options: --port (7650) and --host (127.0.0.1, this machine only; 0.0.0.0 opens it to the network over plain HTTP, so put it behind HTTPS). Running install again with other options updates the service and keeps the data.
  • A domain with HTTPS: sudo rmk-server service install --domain ronne.example.com adds a second service, rmk-server-proxy, running Caddy on ports 80 and 443 with the same settings as Docker's proxy. It needs Caddy 2.7 or later on PATH (Debian's and Ubuntu's own package is too old: use Caddy's repository, or brew install caddy), and stops if another web server holds 80 or 443. --tls internal uses Caddy's own authority; --tls files reads cert.pem and key.pem from /etc/rmk-server-proxy/certs (on macOS, the prefix's etc/rmk-server-proxy/certs; copies, not links; copy them again after each renewal and restart); --email gets expiry notices.
  • On Windows, run the same commands without sudo, in a terminal opened as administrator (right-click PowerShell or Terminal, Run as administrator); status works in any terminal, with the details for administrators. The service's account can't read your profile, where npm's global folder is (%APPDATA%\npm), so install refuses an rmk-server there. Use the Windows bundle (rmk-server-X.Y.Z-win32-x64.zip, or -arm64, with Node.js inside; attached to the releases from the one after 0.2.0): unzip it into C:\Program Files\RonneAI, rename its folder to Marketplace, and run its bin\rmk-server.cmd. Or, in the same administrator's terminal, install with npm into a folder for the whole machine and run its rmk-server.cmd by its full path (that folder isn't on PATH): the commands are below. Data in C:\ProgramData\RonneAI\Marketplace\data, settings in …\Marketplace\.env, logs in …\Marketplace\logs\rmk-server-service.out.log (and .err.log), run by NT SERVICE\rmk-server. Without a domain, --host 0.0.0.0 also adds a firewall rule for the port, on Private networks. --domain needs Caddy for the whole machine (winget install --id CaddyServer.Caddy --scope machine; one in your profile is refused), adds a firewall rule for 80 and 443 on every network, and --tls files reads …\Marketplace\proxy\certs. setup, migrate and reset-root-password work on the service's data, as you.
  • Without systemd (a container, WSL 1, another init system): there's no service to install. Run rmk-server start --no-open under your own supervisor, or use Docker.

On Windows, in a terminal opened as administrator:

# The Windows bundle, unzipped and renamed:
& "C:\Program Files\RonneAI\Marketplace\bin\rmk-server.cmd" service install

# Or npm, into a folder for the whole machine:
npm install --global --prefix "C:\Program Files\RonneAI\npm" @ronneai/marketplace
& "C:\Program Files\RonneAI\npm\rmk-server.cmd" service install

The setup

Until the instance is set up, every page opens the setup, and the API answers 503 setup_required. The setup asks for:

  1. The database. SQLite (the default: a file, nothing else to install), MySQL or MariaDB, or PostgreSQL, with the host, port, name, user and password of an existing, empty database. Test connection connects, checks the server version and, on MySQL, the utf8mb4 character set, and checks that the user can create, write, read and drop tables (through a probe table it removes again). A problem is explained in plain words, with the driver's message.
  2. The public address: where people open Ronne AI Marketplace. When it comes from the environment (as compose.yaml sets PUBLIC_URL), it's shown read-only, since the environment wins over the settings file.
  3. The root account: email, display name and a password of 12 to 128 characters, typed twice.
  4. Install: the settings are written, the migrations applied and the root account created, each shown as it happens. A failure returns to the question it's about; Retry resumes from the failed step. Then Sign in opens the sign-in page with the root email filled in. Nothing needs a restart.

A setup that was interrupted after the settings were written resumes at Install on the next visit, keeping the database. Anyone who can open the address before you can set the instance up, so open it right after starting it. Running the setup again never creates a root when one exists: more roots are added from Users.

Root accounts

The setup creates the first root account. A root can do everything a moderator can, plus create and manage users, create scopes, change the instance's settings and read the audit log. Nobody signs up: a root creates every other account.

There can be several roots. In Admin › Users, any root can make another account root (when creating it, or with Change role) and change anyone's role, roots included. Roots manage each other: one can disable another or reset their password. Nobody changes their own account there; you change your password in Account, and another root does the rest. The instance always keeps at least one active root: a change that would leave none is refused.

A forgotten root password can be reset by another root in Users. If there's no other root, reset it where the instance is installed: pnpm run reset-root-password (in Docker, docker compose exec web pnpm run reset-root-password). With several roots, it asks which one, or takes --email with --yes. It sets a new password, signs that root out everywhere, revokes its access tokens and re-enables the account if it was disabled.

Upgrading

docker compose pull && docker compose up -d         # Docker
npm install --global @ronneai/marketplace@latest     # npm
sudo rmk-server service restart                      # npm, as a service: then this
sudo apt install ./rmk-server_X.Y.Z-1_amd64.deb      # a package: the new one (or dnf install)
git pull && pnpm install && pnpm build && pnpm start   # a clone

Pending database migrations run when the server starts. If one fails, the server stops instead of serving a half-migrated database. Each release is tagged X.Y.Z, X.Y and latest on Docker Hub; to pin one, set RONNE_IMAGE=ronneai/marketplace:X.Y.Z next to compose.yaml. The image and the npm packages share a version.