For the complete documentation index, see llms.txt. This page is also available as Markdown.

Docker + Custom Domain

OpenAlgo Docker Installation Script

Quick Start

This script provides a simplified, automated installation of OpenAlgo using Docker on Ubuntu/Debian systems with custom domain and SSL.

One-Line Installation

wget https://raw.githubusercontent.com/marketcalls/openalgo/refs/heads/main/install/install-docker.sh && chmod +x install-docker.sh && ./install-docker.sh

Prerequisites

  • Fresh Ubuntu 22.04 LTS or later, or Debian 12 or later. install-docker.sh refuses to run on any other distribution: it checks the OS ID and exits unless it is ubuntu or debian.

  • Root access OR non-root user with sudo privileges

  • Domain name pointed to your server IP

  • Server with at least 1GB RAM (2GB recommended)

Installation Steps

Option 1: As Non-Root User (Recommended)

Option 2: As Root User

Note: While the script works as root, using a non-root user is recommended for better security in production environments.

Follow the Prompts

The script will ask you for:

  • Domain name (e.g., demo.openalgo.in)

  • Broker name from the supported list

  • Broker API credentials (key and secret)

  • Market data credentials (for XTS brokers only)

  • Email for SSL certificate notifications

  • Confirmation to proceed

What the Script Does

  1. Updates system packages

  2. Installs Docker and Docker Compose v2

  3. Installs Nginx web server

  4. Installs Certbot for SSL

  5. Clones OpenAlgo repository to /opt/openalgo

  6. Configures environment variables, generating a fresh APP_KEY and API_KEY_PEPPER, setting HOST_SERVER and WEBSOCKET_URL to your domain, and switching WEBSOCKET_HOST and FLASK_HOST_IP to 0.0.0.0 so the published container ports are reachable. ZMQ_HOST is deliberately left on 127.0.0.1.

  7. Sets up firewall (UFW)

  8. Obtains SSL certificate from Let's Encrypt

  9. Configures Nginx with SSL and WebSocket support

  10. Builds and starts the Docker container

  11. Creates management helper scripts

Installation typically takes 5-10 minutes.

After Installation

  1. Visit https://yourdomain.com in your browser

  2. Create your admin account

  3. Login to OpenAlgo

  4. Complete broker authentication using OAuth

Management Commands

The installation creates these helper commands:

Docker Commands

File Locations

Item
Location

Installation

/opt/openalgo

Configuration

/opt/openalgo/.env (bind-mounted to /app/.env)

Database

Docker volume openalgo_db

Application Logs

Docker volume openalgo_log

Strategies

Docker volume openalgo_strategies

Keys

Docker volume openalgo_keys

Nginx Config

/etc/nginx/sites-available/yourdomain.com

SSL Certificates

/etc/letsencrypt/live/yourdomain.com/

Backups

/opt/openalgo-backups/

Everything except .env is a Docker named volume, not a host directory, which is what keeps your data safe across docker compose build --no-cache. Docker Compose prefixes the real volume name with the project name (taken from the directory), so an install in /opt/openalgo produces openalgo_openalgo_db. Read the actual name rather than assuming it:

To reach the files themselves, copy them out of the running container:

Updating OpenAlgo

Troubleshooting

Container not starting:

Permission errors on .env:

The container runs as UID/GID 1000. If the bind-mounted .env is owned by another user, the first-run secret rotation cannot write to it and the worker restarts in a loop:

The log, db, strategies, keys and tmp paths are Docker named volumes owned by the container, so they need no host-side permission fixing.

WebSocket connection issues:

Nginx issues:

SSL certificate issues:

Docker issues:

Firewall Configuration

The script automatically configures UFW:

  • Port 22 (SSH) - Open

  • Port 80 (HTTP) - Open (for SSL renewal)

  • Port 443 (HTTPS) - Open

  • Ports 5000, 8765 - Only accessible via localhost (Docker ports)

Security Best Practices

  1. Change default credentials immediately after first login

  2. Keep system updated:

  3. Monitor logs regularly:

  4. Setup automated backups: Create a cron job

  5. Use strong passwords for your OpenAlgo account

  6. Never share broker credentials with anyone

  7. Review firewall rules periodically:

Cloudflare Setup (Optional)

For additional security and CDN benefits:

  1. Add domain to Cloudflare

    • Sign up at cloudflare.com

    • Add your domain

  2. Update DNS

    • In Cloudflare DNS settings:

    • Create A record pointing to your server IP

    • Enable proxy (orange cloud icon)

  3. Configure SSL/TLS

    • Go to SSL/TLS settings

    • Set mode to "Full (strict)"

    • Enable "Always Use HTTPS"

  4. Enable WebSockets

    • Go to Network settings

    • Enable "WebSockets"

    • Enable "HTTP/2"

  5. Security Settings (Optional)

    • Enable "Under Attack Mode" if needed

    • Set up Page Rules for caching

    • Configure Firewall Rules

Backup and Restore

Create Backup:

Backups are stored in /opt/openalgo-backups/ and include:

  • .env (your configuration, stored as a plain file)

  • db.tar.gz (an archive of the database volume's contents)

  • strategies.tar.gz (an archive of the strategies volume, when present)

  • The last 7 backups are kept automatically

The script stops the stack, resolves the real volume names by inspecting the running container, archives them, verifies the database archive is not empty, and restarts the stack whether or not it succeeded.

Restore from Backup:

The archive holds nested tarballs of volume contents, so extracting it into /opt/openalgo does not restore anything. Unpack the outer archive first, then write each inner archive back into its volume:

Complete Uninstallation

Getting Help

  • Documentation: https://docs.openalgo.in

  • Discord Community: https://discord.com/invite/UPh7QPsNhP

  • GitHub Issues: https://github.com/marketcalls/openalgo/issues

  • YouTube Tutorials: https://youtube.com/@openalgoHQ

  • Website: https://openalgo.in

Supported Brokers

All 36 broker plugins in VALID_BROKERS are selectable during installation:

Broker
Code
XTS API

5paisa

fivepaisa

No

5paisa XTS

fivepaisaxts

Yes

AliceBlue

aliceblue

No

Angel One

angel

No

Arrow

arrow

No

Compositedge

compositedge

Yes

Definedge

definedge

No

Delta Exchange

deltaexchange

No

Dhan

dhan

No

Dhan Sandbox

dhan_sandbox

No

Firstock

firstock

No

Flattrade

flattrade

No

Fyers

fyers

No

Groww

groww

No

HDFC Securities

hdfcsecurities

No

HDFC Sky

hdfcsky

No

IBulls

ibulls

Yes

IIFL

iifl

Yes

Iiflcapital

iiflcapital

No

IndMoney

indmoney

No

JainamXTS

jainamxts

Yes

Kotak Neo

kotak

No

Motilal Oswal

motilal

No

Mstock

mstock

No

Nubra

nubra

No

Paytm Money

paytm

No

Pocketful

pocketful

No

RMoney

rmoney

Yes

Samco

samco

No

Shoonya

shoonya

No

Tradejini

tradejini

No

TradeSmart

tradesmart

No

Upstox

upstox

No

Wisdom Capital

wisdom

Yes

Zebu

zebu

No

Zerodha

zerodha

No

Note: XTS API brokers require additional market data API credentials during installation.

Note: Delta Exchange is a 24/7 crypto venue. The installer detects it and sets DISABLE_SESSION_EXPIRY = 'true' so the daily 03:00 IST auto-logout does not apply.

System Requirements

Minimum:

  • 1 vCPU

  • 1GB RAM

  • 10GB disk space

  • Ubuntu 22.04 LTS or later, or Debian 12 or later

  • Internet connection

Recommended:

  • 2 vCPU

  • 2GB RAM

  • 20GB SSD storage

  • Ubuntu 22.04 LTS

  • Stable internet connection

Architecture

FAQ

Q: Can I use this on a server with existing Nginx? A: Yes, but you may need to manually merge configurations to avoid conflicts.

Q: Can I use a different port instead of 443? A: Yes, but you'll need to modify the Nginx configuration manually.

Q: Will this work with a subdomain? A: Yes, the script supports both root domains and subdomains.

Q: Can I run multiple OpenAlgo instances? A: Not with this script. Each installation assumes it's the only instance.

Q: How do I change my broker after installation? A: Edit /opt/openalgo/.env, update broker credentials, then run sudo docker compose restart.

Q: Is my broker data secure? A: Yes, all data is encrypted in transit (HTTPS/WSS) and stored locally on your server.

Q: Can I use this in production? A: Yes, this script is designed for production use with SSL, security headers, and proper firewall configuration.

Q: What if my domain doesn't have an A record yet? A: Wait for DNS propagation (usually 5-60 minutes) before running the script.

Changelog

Version 1.1.0 (October 19, 2024)

  • Added support for running as root user (with warning)

  • Fixed permission issues with docker-compose.yaml creation

  • Improved error handling

  • Enhanced management scripts

Version 1.0.0 (Initial Release)

  • Complete automated installation

  • SSL certificate automation

  • Docker containerization

  • Management helper scripts

License

OpenAlgo is released under the AGPL V3.0 License.

Contributing

Contributions are welcome! Please see our Contributing Guide.


Note: This script is designed for fresh server installations. If you have an existing OpenAlgo installation or other applications on the server, please review the script and make necessary adjustments to avoid conflicts.

For production deployments, we strongly recommend:

  1. Using a non-root user

  2. Setting up automated backups

  3. Monitoring logs regularly

  4. Keeping the system updated

  5. Using Cloudflare or similar CDN/DDoS protection

Last updated