Install Scana on your own servers
Scana runs on your servers, with your own domain and your own Clerk application for sign-in. One installer sets it up with Docker Compose or Helm. It checks your settings before it starts anything.
Downloads aren't available yet
1Choose where Scana runs
2Check what you need
- A Linux server with Docker Engine 24 or later and Docker Compose 2.24 or later.
- Bash, curl, jq and OpenSSL on that server. The installer checks them but doesn't install them.
- A domain for Scana, such as scana.example.com, with its DNS pointing at the server.
- Ports 80 and 443 open to the internet, so Let's Encrypt can issue the HTTPS certificate.
- An email address for certificate notices from Let's Encrypt.
- Network access from Scana to the systems you'll test.
The Enterprise endpoint relay is optional. With it, your managed devices must reach port 3020.
3Set up sign-in with Clerk
Scana signs people in with Clerk. Each install has its own Clerk application, which you create and own. Clerk's free plan is enough for many installs.
- Create an application at dashboard.clerk.com, and choose how your team signs in.
- Create a production instance on Scana's domain, or on its parent domain.
- Add the DNS records Clerk lists, and wait until Clerk shows them as verified.
- Give Clerk your own OAuth credentials for Google, Microsoft or any other social sign-in.
- Turn on Organizations. Every Scana team is a Clerk organization.
- Copy the production keys. They start with pk_live_ and sk_live_.
The installer asks for both keys and checks them with Clerk. They stay on your server, and this portal never sees them.
4Choose a licence
Community is free and needs no licence key. Leave the installer's licence question blank to run it.
For Team or Enterprise, copy the licence key from your licences page when the installer asks for it. You can also paste it later, in Scana under Settings, then Plan & licence. Each key lasts 35 days. Your install renews it every day through this portal, sending only usage counts.
5Run the installer
It asks for Scana's domain, your Clerk keys, your licence key and whether to run the Enterprise relay. It also asks for an email address for certificate notices.
It checks your tools and your Clerk application, and shows what it will do before it starts anything. It writes its settings to /opt/scana/.env, with a new database password, encryption key and setup code.
6Open Scana and claim it
When Scana is running, the installer prints its address and a setup code.
- Open the /setup address it prints, such as https://scana.example.com/setup.
- Enter the setup code. The setup screen then checks your Clerk application and fixes what it can.
- Sign up. The first account to sign up claims the install and becomes its admin.
- Create your team, then add a target you're authorised to test.
7Finish setting up
- In Clerk, open Restrictions and set sign-up to Restricted, so only people you invite can join.
- Invite your team. Viewers are free, and only admins and operators use seats.
- Back up /opt/scana/.env, which holds the encryption key. The database is dumped every night to /opt/scana/backups. Copy those dumps to another disk too.