Offline bundle

Install Nixt DNA Server at a site with no internet route for software, from one archive holding the packages, the container image, the Helm chart and their checksums.

The offline bundle is one archive with everything needed to install a release of Nixt DNA Server without reaching anything outside your site:

  • the server program for Linux;
  • the .deb and .rpm packages;
  • the container image, as an archive you can load into a registry of your own;
  • the Helm chart;
  • the source code of every library the server is built from, and a software bill of materials (SBOM);
  • SHA256SUMS, the checksum of every file, and verify.sh, which checks them.

1. Check the bundle

Copy the archive across, unpack it and run verify.sh inside it:

tar xzf nixt-server-<version>-bundle.tar.gz
cd nixt-server-<version>
./verify.sh

verify.sh checks every file against SHA256SUMS, and that no file is there that the list does not name. Each problem is listed as MISSING, CHANGED or UNLISTED, and the script ends the bundle is not what was listed. Do not install it.

When cosign is installed, verify.sh also checks each file’s signature, offline. Without cosign it stops and says so; run ./verify.sh --checksums-only to check the checksums alone.

2. Install

Use the part of the bundle that fits how you run the server:

MethodFrom the bundleThen
PackageThe .deb or .rpm for your machineQuick start
ContainerThe image archive: load it with docker load, or push it to your own registryIn a container
KubernetesThe chart, with image.repository set to your own registryKubernetes

Your licence needs no connection either: the server checks it offline. See Licences.

Upgrades

Unpack the new release’s bundle, check it with verify.sh, then point the upgrade at its folder. See Upgrades.

Something unclear or out of date on this page? Tell us.