Hardware
CPU and memory
The scanners your organisation has decide how much CPU and memory Earnie needs. Open-source matching is light. Cryptography detection builds your dependencies in a sandbox and needs the most CPU. AI provenance needs the most memory, because it loads model files.
In the fully on-premises option, AI provenance still sends model fingerprints to
api.scanoss.com. See Fully on-premises.
These figures are for Earnie alone. If you run the database on the same server, add the database’s CPU and memory from Database.
Cryptography scans also run on fewer cores, but more slowly. In SCANOSS’s measurements, the first scan of a Java project with 131 dependencies took about 10 minutes on 14 cores, 15 minutes on 8 cores, and 25 minutes on 4 cores. Memory peaked near 7.5 GB at every core count. Later scans of the same project reuse cached dependencies and are faster.
Disk
Use SSD storage, preferably NVMe.
The data volume holds the scan archives, scan results, dependency caches for cryptography, and uploaded AI model files. Earnie mounts it at
/var/lib/earnie by default. Back it up, along with the database. If you run the database as a container, its data is on this volume too.
Database
Earnie needs PostgreSQL 16. It doesn’t need any PostgreSQL extensions, and it doesn’t need any other data store, message broker, or object storage.
Earnie opens up to 25 database connections by default.
Software
- Operating system: a 64-bit Linux distribution on x86-64 (amd64). SCANOSS runs Earnie on Ubuntu 24.04. Earnie’s server images aren’t available for ARM.
- Docker: Docker Engine with the Docker Compose v2 plugin, version 2.20 or later.
- A DNS name for Earnie, such as
earnie.example.com, that your users, CI pipelines, and Git provider can reach.
install.sh, pulls the container images, or loads them from an offline image archive if your server can’t reach the container registry.
Network access
Inbound
Earnie gets its TLS certificate from Let’s Encrypt by default, which needs the DNS name to be publicly resolvable. You can instead run Earnie behind your own load balancer and terminate TLS there.
Outbound
Cryptography scans build your dependencies in a sandbox. The sandbox can reach only package registries, such as Maven Central, npm, PyPI, crates.io, and the Go module proxy, over ports 80 and 443. It can’t reach your network, the Earnie server, or anything else. If you use private registry mirrors, add their addresses to Earnie’s sandbox allowlist with the
SCANS_SANDBOX_MIRROR_CIDRS setting.
Earnie doesn’t support fully air-gapped networks yet. Even in the fully on-premises option, it needs to reach the CISA feed, and, for cryptography scans, your dependencies’ package registries or your mirrors of them.
What’s next
- Deployment & data flow explains exactly what Earnie sends to SCANOSS and to other services.
- Workspace setup covers the first steps after Earnie is running.