Documentation

Install Cerberus

Self-hosted website scanner · Version 0.2.2 · Updated September 28, 2026

Recommended: use the standard Docker Compose installation. It keeps the Docker socket out of the application stack and binds Cerberus only to localhost by default.

Before you begin

Standard Docker Compose Recommended

Clone the public release repository and run its setup script:

git clone https://github.com/vaxman14/cerberus-selfhost.git
cd cerberus-selfhost
./scripts/setup.sh

What each line does

The script generates local secrets, pulls the versioned public images, starts the isolated stack, waits for health, and prints the local URL.

Finish setup

  1. Open http://127.0.0.1:8099 on the Docker host.
  2. Create the first local owner with a password of at least 12 characters.
  3. Leave active scans disabled until you deliberately configure them and confirm authorization for each target.

Verify the stack:

docker compose ps
curl http://127.0.0.1:8099/health

Installing on another machine

Keep the safe localhost bind and tunnel the port from your computer:

ssh -L 8099:127.0.0.1:8099 user@docker-host

This opens an SSH session and forwards port 8099 on your computer to the localhost-only Cerberus port on the Docker host. Replace user@docker-host with your real SSH username and hostname or IP address.

Keep that terminal open, then visit http://127.0.0.1:8099 locally. For permanent remote access, use an HTTPS reverse proxy with restricted access. Never publish the tools or ZAP worker ports.

Docker Hub AIO alternative

Security warning: the AIO launcher mounts /var/run/docker.sock, giving it effective control of the Docker host. Use the standard Compose installation unless you specifically need the one-container launcher.
docker volume create cerberus-aio-config

docker run -d \
  --name cerberus-aio \
  --restart unless-stopped \
  -p 8099:8099 \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v cerberus-aio-config:/config \
  -e CERBERUS_AIO_CONFIG_VOLUME=cerberus-aio-config \
  -e CERBERUS_ENABLE_ACTIVE_SCANS=false \
  romanvaxman/cerberus-aio:0.2.2

What every AIO line does

Open Cerberus after installation

The AIO command publishes port 8099 on the Docker host so a browser on your LAN can reach it. Do not expose or port-forward this port to the public internet. If the host has a public interface, restrict the port with its firewall or bind it to a specific private address, for example -p 192.168.1.50:8099:8099.

Follow startup with docker logs -f cerberus-aio. When the log reports proxy listening on container port 8099, press Ctrl+C; this stops following the logs but leaves Cerberus running.

Open http://DOCKER-HOST-IP:8099 in your browser and create the first owner immediately. On the Docker host itself, http://127.0.0.1:8099 also works. To keep AIO localhost-only, use -p 127.0.0.1:8099:8099 and the SSH tunnel above.

docker restart cerberus-aio restarts the launcher, pulls the configured child images, and reconciles the child stack while preserving named configuration and data volumes.

Standard Compose data, updates, and removal

./scripts/backup.sh
./scripts/update.sh
docker compose down

Ordinary docker compose down preserves local volumes. docker compose down --volumes permanently deletes them. Back up secrets/cerberus_master_key separately from database archives or saved provider credentials cannot be decrypted after recovery.

Next steps

Read Help and operations for backup, restore, password recovery, updates, and troubleshooting. Review the Terms and authorization disclaimer before scanning. Report security vulnerabilities privately through the public repository's Security tab.