> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanoss.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Self-hosting requirements

> The hardware, software, and network access you need to run Earnie on your own servers.

This page applies when you host Earnie yourself, in the self-hosted Earnie or fully on-premises option. If SCANOSS hosts Earnie for you, you don't need any of it. See [Deployment options](/en/latest/earnie/deployment#deployment-options).

Earnie runs on one Linux server with Docker Compose. A PostgreSQL database holds its data. You can run the database as a container on the same server, or use a PostgreSQL server you already have.

In the fully on-premises option you also run the SCANOSS API and knowledge base. They have their own, much larger, [hardware requirements](/en/latest/installation/on-prem/deployment-guide/hardware-requirements). Run them on a separate server.

## Hardware

### CPU and memory

The scanners your organisation has decide how much CPU and memory Earnie needs. Open-source matching is light. Cryptography detection builds your dependencies in a sandbox and needs the most CPU. AI provenance needs the most memory, because it loads model files.

| Scanners | Minimum | Recommended |
| - | - | - |
| Open source | 2 vCPU, 4 GB RAM | 2 vCPU, 8 GB RAM |
| Open source and cryptography | 16 vCPU, 32 GB RAM | 16 vCPU, 32 GB RAM |
| Open source and AI provenance | 4 vCPU, 20 GB RAM | 8 vCPU, 32 GB RAM |
| Open source, cryptography, and AI provenance | 16 vCPU, 48 GB RAM | 16 vCPU, 64 GB RAM |

In the fully on-premises option, AI provenance still sends model fingerprints to `api.scanoss.com`. See [Fully on-premises](/en/latest/earnie/deployment#fully-on-premises).

These figures are for Earnie alone. If you run the database on the same server, add the database's CPU and memory from [Database](#database).

Cryptography scans also run on fewer cores, but more slowly. In SCANOSS's measurements, the first scan of a Java project with 131 dependencies took about 10 minutes on 14 cores, 15 minutes on 8 cores, and 25 minutes on 4 cores. Memory peaked near 7.5 GB at every core count. Later scans of the same project reuse cached dependencies and are faster.

### Disk

Use SSD storage, preferably NVMe.

| What | Size |
| - | - |
| **Data volume** | 50 GB minimum. 200 GB for larger organisations or many repositories. |
| **Container images** | About 6 GB, or about 12 GB with AI provenance. |
| **Operating system** | As your operating system needs. |

The data volume holds the scan archives, scan results, dependency caches for cryptography, and uploaded AI model files. Earnie mounts it at `/var/lib/earnie` by default. Back it up, along with the database. If you run the database as a container, its data is on this volume too.

### Database

Earnie needs PostgreSQL 16. It doesn't need any PostgreSQL extensions, and it doesn't need any other data store, message broker, or object storage.

| Organisation size | Database CPU and memory | Notes |
| - | - | - |
| Small | 1–2 vCPU, 4 GB RAM | A single server is enough |
| Medium and large | 2–4 vCPU, 7–15 GB RAM | Consider a high-availability pair |

Earnie opens up to 25 database connections by default.

## Software

* **Operating system:** a 64-bit Linux distribution on x86-64 (amd64). SCANOSS runs Earnie on Ubuntu 24.04. Earnie's server images aren't available for ARM.
* **Docker:** Docker Engine with the Docker Compose v2 plugin, version 2.20 or later.
* **A DNS name** for Earnie, such as `earnie.example.com`, that your users, CI pipelines, and Git provider can reach.

SCANOSS gives you the Earnie installation bundle for each release. Its installer, `install.sh`, pulls the container images, or loads them from an offline image archive if your server can't reach the container registry.

## Network access

### Inbound

| Port | Purpose |
| - | - |
| 443 (TCP) | The web app, the API, the CLI, MCP clients, and webhooks from GitHub or GitLab. |
| 80 (TCP) | Redirects to HTTPS, and Let's Encrypt certificate checks. |

Earnie gets its TLS certificate from Let's Encrypt by default, which needs the DNS name to be publicly resolvable. You can instead run Earnie behind your own load balancer and terminate TLS there.

### Outbound

| Destination | When it's needed |
| - | - |
| **SCANOSS API** | Always. This is `api.scanoss.com`, or your own SCANOSS API in the fully on-premises option. |
| **`api.scanoss.com`, fully on-premises** | When AI provenance is enabled, to identify AI models by their fingerprints. |
| **Container registry (`ghcr.io`)** | To install and upgrade, unless you use the offline image archive. |
| **Let's Encrypt** | Unless you terminate TLS on your own load balancer. |
| **CISA (`www.cisa.gov`)** | To download the Known Exploited Vulnerabilities feed, once a day by default. |
| **Public package registries** | When cryptography is enabled, to download your dependencies. See below. |
| **Your GitHub or GitLab** | When you connect repositories. GitHub Enterprise Server and self-managed GitLab are supported. |
| **Your identity provider** | When your organisation signs in with single sign-on. |
| **Your metrics system** | Only if you turn on telemetry. |

Cryptography scans build your dependencies in a sandbox. The sandbox can reach only package registries, such as Maven Central, npm, PyPI, crates.io, and the Go module proxy, over ports 80 and 443. It can't reach your network, the Earnie server, or anything else. If you use private registry mirrors, add their addresses to Earnie's sandbox allowlist with the `SCANS_SANDBOX_MIRROR_CIDRS` setting.

<Note>
  Earnie doesn't support fully air-gapped networks yet. Even in the fully on-premises option, it needs to reach the CISA feed, and, for cryptography scans, your dependencies' package registries or your mirrors of them.
</Note>

## What's next

* [Deployment & data flow](/en/latest/earnie/deployment) explains exactly what Earnie sends to SCANOSS and to other services.
* [Workspace setup](/en/latest/earnie/getting-started/workspace-setup) covers the first steps after Earnie is running.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.