Deployment
CBOM deploys as three Docker containers: MongoDB, the CBOM application (API + embedded UI), and Nginx for TLS termination.
Requirements
Section titled “Requirements”- Docker Engine 24+ with Docker Compose v2
- 2 GB RAM minimum (4 GB recommended)
- 10 GB disk for database storage
- A valid
license.jsonfile (contact QCecuring for trial licenses) - TLS certificate and key for HTTPS (self-signed acceptable for evaluation)
Quick Start
Section titled “Quick Start”1. Clone and configure
Section titled “1. Clone and configure”git clone https://github.com/qcecuring/cbom.gitcd cbomcp .env.example .envEdit .env with your values:
# RequiredMONGODB_ROOT_PASSWORD=your-secure-password-hereMONGODB_DATABASE=cbomCBOM_JWT_SECRET=generate-with-openssl-rand-base64-32CBOM_VERSION=latestCBOM_CORS_ORIGINS=https://cbom.yourcompany.com
# Optional — Email alertsCBOM_ALERT_EMAIL_ENABLED=falseCBOM_SMTP_HOST=CBOM_SMTP_PORT=587CBOM_SMTP_USERNAME=CBOM_SMTP_PASSWORD=CBOM_ALERT_EMAIL_TO=CBOM_ALERT_EMAIL_FROM=cbom-alerts@yourcompany.comGenerate a JWT secret:
openssl rand -base64 322. Place license and TLS certificates
Section titled “2. Place license and TLS certificates”# Licensecp /path/to/license.json ./config/
# TLS certificates for Nginxcp /path/to/server.pem ./config/nginx/certs/cp /path/to/server-key.pem ./config/nginx/certs/3. Start the platform
Section titled “3. Start the platform”docker compose up -dWait for health checks to pass:
docker compose psAll three services should show healthy status. The platform is now available at https://localhost (or your configured domain).
4. Create the admin user
Section titled “4. Create the admin user”On first access, you’ll be prompted to create the initial admin account. This only works once — subsequent users are created from the admin panel.
Navigate to the platform URL and follow the setup wizard, or use the API directly:
curl -X POST https://localhost/api/v1/auth/register-admin \ -H "Content-Type: application/json" \ -d '{"username": "admin", "password": "your-password", "displayName": "Admin"}'Services
Section titled “Services”| Service | Port | Purpose |
|---|---|---|
cbom-mongodb | 27017 (localhost only) | Data storage |
cbom-app | 9090 (localhost only) | API + embedded UI |
cbom-nginx | 80, 443 | HTTPS reverse proxy |
Only Nginx is exposed externally. MongoDB and the application bind to localhost only.
Health Check
Section titled “Health Check”curl https://localhost/api/v1/healthReturns platform status and component health.
Upgrading
Section titled “Upgrading”# Pull new versiondocker compose pull
# Restart with new imagedocker compose up -dMongoDB data persists in ./data/mongodb. The application is stateless — upgrades are safe to apply without migration steps.
Troubleshooting
Section titled “Troubleshooting”MongoDB won’t start: Check that ./data/mongodb is writable and no other process binds port 27017.
License errors: Verify license.json is in ./config/ and the file hasn’t been modified (signature validation will fail).
TLS certificate issues: Ensure server.pem contains the full chain (leaf + intermediate) and server-key.pem is the matching private key.
App container unhealthy: Check logs with docker compose logs cbom-app. Common issues: wrong MongoDB password, missing JWT secret, or license file not found.