Skip to content

Deployment

CBOM deploys as three Docker containers: MongoDB, the CBOM application (API + embedded UI), and Nginx for TLS termination.


  • Docker Engine 24+ with Docker Compose v2
  • 2 GB RAM minimum (4 GB recommended)
  • 10 GB disk for database storage
  • A valid license.json file (contact QCecuring for trial licenses)
  • TLS certificate and key for HTTPS (self-signed acceptable for evaluation)

Terminal window
git clone https://github.com/qcecuring/cbom.git
cd cbom
cp .env.example .env

Edit .env with your values:

# Required
MONGODB_ROOT_PASSWORD=your-secure-password-here
MONGODB_DATABASE=cbom
CBOM_JWT_SECRET=generate-with-openssl-rand-base64-32
CBOM_VERSION=latest
CBOM_CORS_ORIGINS=https://cbom.yourcompany.com
# Optional — Email alerts
CBOM_ALERT_EMAIL_ENABLED=false
CBOM_SMTP_HOST=
CBOM_SMTP_PORT=587
CBOM_SMTP_USERNAME=
CBOM_SMTP_PASSWORD=
CBOM_ALERT_EMAIL_TO=
CBOM_ALERT_EMAIL_FROM=cbom-alerts@yourcompany.com

Generate a JWT secret:

Terminal window
openssl rand -base64 32
Terminal window
# License
cp /path/to/license.json ./config/
# TLS certificates for Nginx
cp /path/to/server.pem ./config/nginx/certs/
cp /path/to/server-key.pem ./config/nginx/certs/
Terminal window
docker compose up -d

Wait for health checks to pass:

Terminal window
docker compose ps

All three services should show healthy status. The platform is now available at https://localhost (or your configured domain).

On first access, you’ll be prompted to create the initial admin account. This only works once — subsequent users are created from the admin panel.

Navigate to the platform URL and follow the setup wizard, or use the API directly:

Terminal window
curl -X POST https://localhost/api/v1/auth/register-admin \
-H "Content-Type: application/json" \
-d '{"username": "admin", "password": "your-password", "displayName": "Admin"}'

ServicePortPurpose
cbom-mongodb27017 (localhost only)Data storage
cbom-app9090 (localhost only)API + embedded UI
cbom-nginx80, 443HTTPS reverse proxy

Only Nginx is exposed externally. MongoDB and the application bind to localhost only.


Terminal window
curl https://localhost/api/v1/health

Returns platform status and component health.


Terminal window
# Pull new version
docker compose pull
# Restart with new image
docker compose up -d

MongoDB data persists in ./data/mongodb. The application is stateless — upgrades are safe to apply without migration steps.


MongoDB won’t start: Check that ./data/mongodb is writable and no other process binds port 27017.

License errors: Verify license.json is in ./config/ and the file hasn’t been modified (signature validation will fail).

TLS certificate issues: Ensure server.pem contains the full chain (leaf + intermediate) and server-key.pem is the matching private key.

App container unhealthy: Check logs with docker compose logs cbom-app. Common issues: wrong MongoDB password, missing JWT secret, or license file not found.