The installer, step by step
One command sets up everything. It takes ten to twenty minutes, most of it spent building
the server image, and it prints every step as it goes.
This page lists those steps in order, says what each one is doing, and tells you what to
do when one of them stops. **You do not need to read it before installing.** It is here
for when something does not look right and you want to know whether that matters.
---
Running it
From a terminal on your GeekStream machine:
```
sudo bash /opt/geekstream/installer/linux/install.sh
```
It is safe to run again. It is written to be re-run: it picks up where things already
exist and does not redo work that is done. If an install fails halfway, fix what it
complained about and run the same command again.
Answer its questions as they come. It will ask you to choose an address and to set an
owner password, and nothing else.
---
The steps
### 1 — Checking this machine
Reads how much memory, disk and how many processor cores you have, and prints them.
**If it warns about memory or disk**, it is a warning and not a refusal. Under 3 GB of
memory or under 40 GB free, it says so and carries on. A small machine works; it fills up
sooner and builds more slowly.
### 1b — Checking what is already installed
Looks for anything already using the ports GeekStream needs, and for other media servers
running on the same machine.
**If it names something**, decide which you want on this machine. Two things cannot share
one port. It tells you what is holding it.
### 2 — Docker
Installs Docker if it is not there. This is the longest step on a fresh machine after the
image build.
**If this fails**, it is almost always the system being out of date. Run
`sudo apt-get update && sudo apt-get upgrade -y`, reboot, and run the installer again.
### 3 — Server files
Puts the server under `/opt/geekstream` and records which version it is.
### 4 — Secrets
Generates the keys this server uses to encrypt what it stores. They live in
`/etc/geekstream/secrets`, readable only by root.
**These are not recoverable.** If you lose them, everything the server has saved —
accounts, pairings, your library index — cannot be read again. They are included in
GeekStream's own backups; see [Updates, backups, migration](updates-backups-migration.md).
### 5 — Media route certificate
Creates the certificate your television uses to talk to the server over your own network.
### 5b — Your GeekStream address
**The one decision that needs thought.** This is how your television and your browser
reach the server.
- **The built-in address** — GeekStream gives you a name that works from anywhere, with no
router changes, no port forwarding and nothing to renew. This is the right answer for
almost everyone, and the only workable one if your router will not forward a port.
- **Your own domain** — if you already run a domain through your own tunnel, keep it. The
installer recognises this and leaves it alone.
**If it says it could not reach the address service**, your address is unchanged and
nothing is broken. Check the machine has working internet (`ping -c3 1.1.1.1`) and run the
installer again.
### 6 — Settings
Writes the configuration the services start from. Nothing to do.
### 7 — Server image
Builds the server. **This is the slow step** — several minutes on a fast machine, longer
on a small VPS or an ARM board. It looks like nothing is happening. It is working.
### 7b — Media tools
Checks the tools that read media files are present and runnable.
### 8 — Starting
Starts the services: the manager, the workers, the client gateway, the downloader and the
streaming engine.
### 8a — Checking the engines match this machine
Confirms the pieces built for your processor are the ones that got installed. This catches
an x86 image on an ARM machine, which otherwise fails later in a confusing way.
### 8b — Checking each engine can read its own secrets
Each service is handed only the credentials it needs. This proves each one can actually
read what it was given, rather than discovering it at two in the morning when something
tries to run.
### 8c — Opening the media route
Makes the path your television uses to fetch media.
### 8d — Checking the downloader accepts its credential
Confirms the downloader is reachable and takes the credential the server generated for it.
---
When it finishes
It prints the address of your dashboard and asks you to set an **owner password**. Type
it twice. It is not shown as you type — that is normal, and the cursor does not move.
Then open the address it printed in a browser, sign in as the owner, and continue at
[Your account, and pairing a television](account-pairing.md).
---
When something goes wrong
**Read the step number it stopped on.** It prints `STEP` with a number and a short name,
and that tells you which of the sections above to look at.
**Run it again.** Genuinely — most failures are transient: a package mirror was busy, the
network blinked, the address service was slow. The installer is built to be re-run and
will not repeat work that succeeded.
**If it stops in the same place twice**, collect this and it will usually be obvious:
```
sudo docker ps -a
sudo docker compose -f /opt/geekstream/canonical-runtime/compose.runtime.yaml logs --tail 80
df -h /
```
The first shows which services exist and whether they are running. The second shows what
the failing one said. The third shows whether you have simply run out of disk, which
produces a remarkable variety of unrelated-looking errors.
**Specific failures** — certificate problems, an address that will not resolve, services
that start and immediately stop — are listed with their fixes in
[Troubleshooting](troubleshooting.md).
---
Uninstalling
The same script removes everything, including your data, if you ask it to. See
[Uninstall](uninstall.md) before you do, because the secrets from step 4 go with it.