Install
From a clean server to an application answering on HTTPS.
Requirements
| OS | Architecture | How it is verified |
|---|---|---|
| Ubuntu 26.04 | x86_64 | Checked by hand on a reference VPS; the installer also runs in an Ubuntu 26.04 container |
| Ubuntu 24.04 | x86_64, arm64 | Real installations in automated tests, including an interruption and resume |
| Ubuntu 22.04 | x86_64 | Real installations in automated tests, as above |
| Ubuntu 22.04 | arm64 | Declared; checked by hand only |
| Debian 12 | x86_64, arm64 | Declared; checked by hand only |
Orbit's checks refuse anything else. The server also needs:
- 2 vCPUs, 2 GB of memory and 20 GB free under
/var/lib. 4 GB is better if you build Next.js or Nuxt applications on it. - Root over SSH, a synchronized clock and working DNS.
- Outbound HTTPS to github.com, release-assets.githubusercontent.com and quay.io.
- Ports 80, 443 and 6443 free. Do not use an image with a control panel or a web server.
- If your provider has a firewall, allow 22, 80 and 443. Keep 6443 and 7443 closed to the internet; open them only to the servers you add later.
Running the installer
On the server:
curl -fsSL https://github.com/getcortexlabs/orbit-releases/releases/latest/download/install.sh | sudo shThe installer:
- checks that it runs as root on Linux with systemd, on x86_64 or arm64;
- downloads Orbit for the server's architecture from the releases and refuses an archive whose SHA-256 does not match (
ORBIT_VERSION=0.1.27pins a version); - starts the service and checks the machine. If a check blocks, it stops before changing anything and says how to fix it;
- installs K3s, Traefik, cert-manager, BuildKit and the Orbit agent, in about five minutes;
- ends with the console's address and a one-time token:
Orbit is ready.
Console https://orbit.203-0-113-10.sslip.io
Token boot-7KQ2-MX9P-4TRWRunning the same command again resumes an interrupted installation or updates Orbit.
First steps
- Open the console. Open the address and create the administrator with the token. The certificate comes from Let's Encrypt, so the server must be reachable on port 80.
- Connect GitHub (optional). Under New project, choose Connect GitHub. GitHub creates an App for this Orbit and asks where to install it and which repositories it may read. See GitHub and previews.
- Deploy. Create a project from a repository or a container image. Orbit builds it on the server, gives it an HTTPS address and checks that it answers.
- Add a database to the project and connect it: the application receives
DATABASE_URLin its variables. - Set backups to external storage, so your data survives losing the server. See Backups and recovery.
What the installation adds
These services start at boot:
orbit.service, the control plane;k3s.service, Kubernetes;orbit-firewall.service, which keeps ports 6443 and 8080 reachable only from the machine and its workloads;orbit-agent.service, which reports the server's health to Orbit;orbit-buildkit.service, which builds your repositories.
Orbit keeps its data in /var/lib/orbit and the agent's identity in /var/lib/orbit-agent.
Installing by hand
Download
orbit-linux-<arch>.tar.gzfrom the releases. It holdsorbit(with the console inside),orbit-agentandorbit.service.Copy them to the server and start the service:
shscp orbit orbit-agent orbit.service root@SERVER:/tmp/ ssh root@SERVER 'install -m 0755 /tmp/orbit /tmp/orbit-agent /usr/local/bin/ \ && install -m 0644 /tmp/orbit.service /etc/systemd/system/ \ && systemctl daemon-reload && systemctl enable --now orbit'Get the one-time token to create the administrator. It works once and expires after an hour:
shssh root@SERVER orbit bootstrap-tokenUntil the runtime is installed, the console only listens on
127.0.0.1:8080. Open it through an SSH tunnel and browse to http://127.0.0.1:8080:shssh -N -L 8080:127.0.0.1:8080 root@SERVERCreate the administrator, then follow the console's checks, plan and installation, or run
sudo orbit installon the server.Within a minute of the installation, the console is published at
https://orbit.<server-ip-with-dashes>.sslip.io(orbit statusprints it), with a Let's Encrypt certificate. The tunnel keeps working.