Skip to content

Install ​

From a clean server to an application answering on HTTPS.

Requirements ​

OSArchitectureHow it is verified
Ubuntu 26.04x86_64Checked by hand on a reference VPS; the installer also runs in an Ubuntu 26.04 container
Ubuntu 24.04x86_64, arm64Real installations in automated tests, including an interruption and resume
Ubuntu 22.04x86_64Real installations in automated tests, as above
Ubuntu 22.04arm64Declared; checked by hand only
Debian 12x86_64, arm64Declared; checked by hand only

Orbit's checks refuse anything else. The server also needs:

  • 2 vCPUs, 2 GB of memory and 20 GB free under /var/lib. 4 GB is better if you build Next.js or Nuxt applications on it.
  • Root over SSH, a synchronized clock and working DNS.
  • Outbound HTTPS to github.com, release-assets.githubusercontent.com and quay.io.
  • Ports 80, 443 and 6443 free. Do not use an image with a control panel or a web server.
  • If your provider has a firewall, allow 22, 80 and 443. Keep 6443 and 7443 closed to the internet; open them only to the servers you add later.

Running the installer ​

On the server:

sh
curl -fsSL https://github.com/getcortexlabs/orbit-releases/releases/latest/download/install.sh | sudo sh

The installer:

  1. checks that it runs as root on Linux with systemd, on x86_64 or arm64;
  2. downloads Orbit for the server's architecture from the releases and refuses an archive whose SHA-256 does not match (ORBIT_VERSION=0.1.27 pins a version);
  3. starts the service and checks the machine. If a check blocks, it stops before changing anything and says how to fix it;
  4. installs K3s, Traefik, cert-manager, BuildKit and the Orbit agent, in about five minutes;
  5. ends with the console's address and a one-time token:
text
Orbit is ready.

  Console  https://orbit.203-0-113-10.sslip.io
  Token    boot-7KQ2-MX9P-4TRW

Running the same command again resumes an interrupted installation or updates Orbit.

First steps ​

  1. Open the console. Open the address and create the administrator with the token. The certificate comes from Let's Encrypt, so the server must be reachable on port 80.
  2. Connect GitHub (optional). Under New project, choose Connect GitHub. GitHub creates an App for this Orbit and asks where to install it and which repositories it may read. See GitHub and previews.
  3. Deploy. Create a project from a repository or a container image. Orbit builds it on the server, gives it an HTTPS address and checks that it answers.
  4. Add a database to the project and connect it: the application receives DATABASE_URL in its variables.
  5. Set backups to external storage, so your data survives losing the server. See Backups and recovery.

What the installation adds ​

These services start at boot:

  • orbit.service, the control plane;
  • k3s.service, Kubernetes;
  • orbit-firewall.service, which keeps ports 6443 and 8080 reachable only from the machine and its workloads;
  • orbit-agent.service, which reports the server's health to Orbit;
  • orbit-buildkit.service, which builds your repositories.

Orbit keeps its data in /var/lib/orbit and the agent's identity in /var/lib/orbit-agent.

Installing by hand ​

  1. Download orbit-linux-<arch>.tar.gz from the releases. It holds orbit (with the console inside), orbit-agent and orbit.service.

  2. Copy them to the server and start the service:

    sh
    scp orbit orbit-agent orbit.service root@SERVER:/tmp/
    ssh root@SERVER 'install -m 0755 /tmp/orbit /tmp/orbit-agent /usr/local/bin/ \
      && install -m 0644 /tmp/orbit.service /etc/systemd/system/ \
      && systemctl daemon-reload && systemctl enable --now orbit'
  3. Get the one-time token to create the administrator. It works once and expires after an hour:

    sh
    ssh root@SERVER orbit bootstrap-token
  4. Until the runtime is installed, the console only listens on 127.0.0.1:8080. Open it through an SSH tunnel and browse to http://127.0.0.1:8080:

    sh
    ssh -N -L 8080:127.0.0.1:8080 root@SERVER
  5. Create the administrator, then follow the console's checks, plan and installation, or run sudo orbit install on the server.

  6. Within a minute of the installation, the console is published at https://orbit.<server-ip-with-dashes>.sslip.io (orbit status prints it), with a Let's Encrypt certificate. The tunnel keeps working.

Orbit by Cortex Labs