Install Cerberus
Before you begin
- Docker Engine with Docker Compose v2
- Git and OpenSSL
- Approximately 8 GB of free disk space
- Recommended: 4 CPU cores and 8 GB RAM
Standard Docker Compose Recommended
Clone the public release repository and run its setup script:
git clone https://github.com/vaxman14/cerberus-selfhost.git cd cerberus-selfhost ./scripts/setup.sh
What each line does
git clone ...downloads the public Cerberus source and Compose files into a newcerberus-selfhostdirectory.cd cerberus-selfhostenters that directory so the remaining commands use its files../scripts/setup.shgenerates local secrets, pulls the pinned public images, starts the isolated stack, waits for health, and prints the URL.
The script generates local secrets, pulls the versioned public images, starts the isolated stack, waits for health, and prints the local URL.
Finish setup
- Open http://127.0.0.1:8099 on the Docker host.
- Create the first local owner with a password of at least 12 characters.
- Leave active scans disabled until you deliberately configure them and confirm authorization for each target.
Verify the stack:
docker compose ps curl http://127.0.0.1:8099/health
docker compose psshows every service and whether it is running and healthy.curl .../healthasks the local health endpoint to confirm that the web application is responding.
Installing on another machine
Keep the safe localhost bind and tunnel the port from your computer:
ssh -L 8099:127.0.0.1:8099 user@docker-host
This opens an SSH session and forwards port 8099 on your computer to the localhost-only Cerberus port on the Docker host. Replace user@docker-host with your real SSH username and hostname or IP address.
Keep that terminal open, then visit http://127.0.0.1:8099 locally. For permanent remote access, use an HTTPS reverse proxy with restricted access. Never publish the tools or ZAP worker ports.
Docker Hub AIO alternative
/var/run/docker.sock, giving it effective control of the Docker host. Use the standard Compose installation unless you specifically need the one-container launcher.docker volume create cerberus-aio-config docker run -d \ --name cerberus-aio \ --restart unless-stopped \ -p 8099:8099 \ -v /var/run/docker.sock:/var/run/docker.sock \ -v cerberus-aio-config:/config \ -e CERBERUS_AIO_CONFIG_VOLUME=cerberus-aio-config \ -e CERBERUS_ENABLE_ACTIVE_SCANS=false \ romanvaxman/cerberus-aio:0.2.2
What every AIO line does
docker volume create cerberus-aio-configcreates persistent storage for generated secrets and AIO configuration. Replacing the launcher does not delete it.docker run -dcreates and starts the launcher in the background. A trailing\continues the same command on the next line.--name cerberus-aiogives the launcher a predictable name for later log, restart, and replacement commands.--restart unless-stoppedstarts it after a host reboot unless you manually stopped it.-p 8099:8099publishes the web interface on port8099of every host interface for LAN access. Do not expose or port-forward it to the internet.-v /var/run/docker.sock:/var/run/docker.socklets AIO create the child app, tools, and ZAP containers through the host Docker daemon. It is required and grants effective control of the Docker host.-v cerberus-aio-config:/configmounts the persistent configuration volume inside the launcher.-e CERBERUS_AIO_CONFIG_VOLUME=cerberus-aio-configtells AIO which exact named volume its child containers must use. It must match the volume mounted at/config.-e CERBERUS_ENABLE_ACTIVE_SCANS=falsekeeps Nuclei, ZAP, and sqlmap disabled while leaving passive checks available.romanvaxman/cerberus-aio:0.2.2selects the exact immutable AIO release image instead of accepting an unexpected launcher upgrade.
Open Cerberus after installation
The AIO command publishes port 8099 on the Docker host so a browser on your LAN can reach it. Do not expose or port-forward this port to the public internet. If the host has a public interface, restrict the port with its firewall or bind it to a specific private address, for example -p 192.168.1.50:8099:8099.
Follow startup with docker logs -f cerberus-aio. When the log reports proxy listening on container port 8099, press Ctrl+C; this stops following the logs but leaves Cerberus running.
Open http://DOCKER-HOST-IP:8099 in your browser and create the first owner immediately. On the Docker host itself, http://127.0.0.1:8099 also works. To keep AIO localhost-only, use -p 127.0.0.1:8099:8099 and the SSH tunnel above.
docker restart cerberus-aio restarts the launcher, pulls the configured child images, and reconciles the child stack while preserving named configuration and data volumes.
Standard Compose data, updates, and removal
./scripts/backup.sh ./scripts/update.sh docker compose down
./scripts/backup.shcreates and verifies a timestamped backup archive../scripts/update.shcreates a safety backup, pulls the configured images, restarts the stack, and waits for health.docker compose downstops and removes the Compose containers and network but preserves named volumes and their data.
Ordinary docker compose down preserves local volumes. docker compose down --volumes permanently deletes them. Back up secrets/cerberus_master_key separately from database archives or saved provider credentials cannot be decrypted after recovery.
Next steps
Read Help and operations for backup, restore, password recovery, updates, and troubleshooting. Review the Terms and authorization disclaimer before scanning. Report security vulnerabilities privately through the public repository's Security tab.