System Requirements
Software
| Software | Minimum Version | Notes |
|---|---|---|
| Docker | 24.0+ | Required for every deployment mode except the Windows Installer below |
| Docker Compose | 2.20+ | V2 plugin (docker compose) recommended; not needed for the Windows Installer |
OrbisID is distributed as Docker images for every deployment mode on this page except one: on Windows, the Windows Installer installs OrbisID as native Windows services instead, with no Docker requirement — it bundles its own Java runtime, Node.js runtime, and (optionally) PostgreSQL binaries. It doesn't include the AI/Intelligence Layer (Ollama) — see that option's Known Limitations.
Hardware
| Resource | Minimum | Recommended |
|---|---|---|
| CPU | 2 cores | 4+ cores |
| RAM | 8 GB | 16+ GB |
| Disk | 20 GB | 60+ GB |
Both release packages start a local AI runtime (Ollama) automatically, which raises the baseline versus a database-and-app-only deployment — CPU-only LLM inference is memory-hungry even for the small default model. If you don't plan to use AI features and are resource-constrained, stop the bundled container (docker compose stop ollama ollama-init) and the minimums drop back to roughly 4 GB RAM / 10 GB disk.
Disk usage otherwise grows with the number of systems scanned, how long you retain audit logs and scan history, and the Ollama runtime — the Ollama container image (a few GB; not included in the release download itself) and the two default chat/embedding models (~2 GB) are both pulled from the internet the first time you start the stack.
Network
Inbound Ports
| Port | Protocol | Purpose |
|---|---|---|
| 80 | TCP | HTTP (redirect to HTTPS in production) |
| 443 | TCP | HTTPS (recommended for production) |
Outbound Ports (from OrbisID to target systems)
| Target System Type | Protocol | Port(s) | Notes |
|---|---|---|---|
| Active Directory | LDAP | 389 TCP | Unencrypted (not recommended for production) |
| Active Directory | LDAPS | 636 TCP | Recommended — encrypted |
| Linux | SSH | 22 TCP | Configurable |
| Windows | WinRM HTTP | 5985 TCP | Unencrypted |
| Windows | WinRM HTTPS | 5986 TCP | Recommended — encrypted |
| SQL Server | JDBC | 1433 TCP | Configurable |
| On-Premise Agent | HTTPS | 443 TCP | OrbisID polls agents for job completion |
See Target Systems for full per-system connection requirements.
If target systems are in segmented networks not directly reachable from OrbisID, deploy an On-Premise Agent in those network segments instead.
TLS Certificates
Production deployments should use HTTPS. OrbisID uses Nginx as a reverse proxy, so certificates are configured at the Nginx layer. See Deployment — Enabling HTTPS for how to configure Nginx with your certificate files.
Option A: Let's Encrypt (Certbot)
Use this when the OrbisID host has a public DNS name and internet access:
- Linux
- macOS
- Windows
# Install Certbot
sudo apt install certbot # Debian/Ubuntu
# or
sudo yum install certbot # RHEL/CentOS
# Obtain a certificate (standalone mode — stop Nginx first if running on port 80)
sudo certbot certonly --standalone -d your.orbisid.domain.com
# Certificate files are written to:
# /etc/letsencrypt/live/your.orbisid.domain.com/fullchain.pem
# /etc/letsencrypt/live/your.orbisid.domain.com/privkey.pem
# Install Certbot
brew install certbot
# Obtain a certificate (standalone mode — stop Nginx first if running on port 80)
sudo certbot certonly --standalone -d your.orbisid.domain.com
# Certificate files are written to:
# /etc/letsencrypt/live/your.orbisid.domain.com/fullchain.pem
# /etc/letsencrypt/live/your.orbisid.domain.com/privkey.pem
# Install Certbot — download and run the official Windows installer from
# https://certbot.eff.org/instructions?ws=other&os=windows (a separate .exe,
# not available via apt/yum). It installs a `certbot` command on your PATH.
# Obtain a certificate (standalone mode — stop Nginx first if running on port 80)
certbot certonly --standalone -d your.orbisid.domain.com
# Certificate files are written to:
# C:\Certbot\live\your.orbisid.domain.com\fullchain.pem
# C:\Certbot\live\your.orbisid.domain.com\privkey.pem
Copy the certificate files to the OrbisID ssl/ directory, then configure Nginx as described in the deployment guide.
Option B: Self-Signed Certificate
Use this for internal deployments without a public domain:
- Linux
- macOS
- Windows
# Generate a self-signed certificate valid for 10 years
mkdir -p ssl
openssl req -x509 -nodes -days 3650 -newkey rsa:4096 \
-keyout ssl/privkey.pem \
-out ssl/fullchain.pem \
-subj "/CN=orbisid.internal" \
-addext "subjectAltName=DNS:orbisid.internal,IP:192.168.1.100"
# Generate a self-signed certificate valid for 10 years
mkdir -p ssl
openssl req -x509 -nodes -days 3650 -newkey rsa:4096 \
-keyout ssl/privkey.pem \
-out ssl/fullchain.pem \
-subj "/CN=orbisid.internal" \
-addext "subjectAltName=DNS:orbisid.internal,IP:192.168.1.100"
# OpenSSL isn't built into Windows. Install it first — e.g. via Git for
# Windows (https://git-scm.com/download/win), which bundles an `openssl.exe`
# on its PATH — then run the same command used on Linux/macOS:
New-Item -ItemType Directory -Force -Path ssl | Out-Null
openssl req -x509 -nodes -days 3650 -newkey rsa:4096 `
-keyout ssl/privkey.pem `
-out ssl/fullchain.pem `
-subj "/CN=orbisid.internal" `
-addext "subjectAltName=DNS:orbisid.internal,IP:192.168.1.100"
Replace orbisid.internal and the IP address with your actual hostname and IP. Users will need to trust the certificate in their browser or via a corporate CA.
Option C: Corporate CA Certificate
If your organisation issues certificates internally, request a certificate for the OrbisID hostname and place the resulting fullchain.pem and privkey.pem files in the ssl/ directory before starting the stack.
Browser Support
| Browser | Minimum Version |
|---|---|
| Chrome / Chromium | 100+ |
| Firefox | 100+ |
| Safari | 15+ |
| Microsoft Edge | 100+ |
Database
OrbisID uses PostgreSQL 16. Two deployment options are available:
- All-in-One - PostgreSQL runs as a container alongside OrbisID (simplest setup)
- External Database - connect to your own managed PostgreSQL instance (on-premise, AWS RDS, Azure Database, etc.)
For external databases, the minimum supported version is PostgreSQL 15.