Skip to main content
This page applies when you host Earnie yourself, in the self-hosted Earnie or fully on-premises option. If SCANOSS hosts Earnie for you, you don’t need any of it. See Deployment options. Earnie runs on one Linux server with Docker Compose. A PostgreSQL database holds its data. You can run the database as a container on the same server, or use a PostgreSQL server you already have. In the fully on-premises option you also run the SCANOSS API and knowledge base. They have their own, much larger, hardware requirements. Run them on a separate server.

Hardware

CPU and memory

The scanners your organisation has decide how much CPU and memory Earnie needs. Open-source matching is light. Cryptography detection builds your dependencies in a sandbox and needs the most CPU. AI provenance needs the most memory, because it loads model files. In the fully on-premises option, AI provenance still sends model fingerprints to api.scanoss.com. See Fully on-premises. These figures are for Earnie alone. If you run the database on the same server, add the database’s CPU and memory from Database. Cryptography scans also run on fewer cores, but more slowly. In SCANOSS’s measurements, the first scan of a Java project with 131 dependencies took about 10 minutes on 14 cores, 15 minutes on 8 cores, and 25 minutes on 4 cores. Memory peaked near 7.5 GB at every core count. Later scans of the same project reuse cached dependencies and are faster.

Disk

Use SSD storage, preferably NVMe. The data volume holds the scan archives, scan results, dependency caches for cryptography, and uploaded AI model files. Earnie mounts it at /var/lib/earnie by default. Back it up, along with the database. If you run the database as a container, its data is on this volume too.

Database

Earnie needs PostgreSQL 16. It doesn’t need any PostgreSQL extensions, and it doesn’t need any other data store, message broker, or object storage. Earnie opens up to 25 database connections by default.

Software

  • Operating system: a 64-bit Linux distribution on x86-64 (amd64). SCANOSS runs Earnie on Ubuntu 24.04. Earnie’s server images aren’t available for ARM.
  • Docker: Docker Engine with the Docker Compose v2 plugin, version 2.20 or later.
  • A DNS name for Earnie, such as earnie.example.com, that your users, CI pipelines, and Git provider can reach.
SCANOSS gives you the Earnie installation bundle for each release. Its installer, install.sh, pulls the container images, or loads them from an offline image archive if your server can’t reach the container registry.

Network access

Inbound

Earnie gets its TLS certificate from Let’s Encrypt by default, which needs the DNS name to be publicly resolvable. You can instead run Earnie behind your own load balancer and terminate TLS there.

Outbound

Cryptography scans build your dependencies in a sandbox. The sandbox can reach only package registries, such as Maven Central, npm, PyPI, crates.io, and the Go module proxy, over ports 80 and 443. It can’t reach your network, the Earnie server, or anything else. If you use private registry mirrors, add their addresses to Earnie’s sandbox allowlist with the SCANS_SANDBOX_MIRROR_CIDRS setting.
Earnie doesn’t support fully air-gapped networks yet. Even in the fully on-premises option, it needs to reach the CISA feed, and, for cryptography scans, your dependencies’ package registries or your mirrors of them.

What’s next