콘텐츠로 건너뛰기

사전 릴리스 문서 사이트를 보고 있습니다여기 콘텐츠는 테스트용이며 실제 문서와 다를 수 있습니다.

실제 문서로 이동

Run your own instance

이 콘텐츠는 아직 귀하의 언어로 제공되지 않습니다.

This guide will get you up and running with a self-hosted Onetime Secret instance in minutes.

  • You’ve decided to self-host — see Hosted or self-hosted? if you haven’t
  • 1GB+ RAM for optimal performance
  • Redis storage note: Depending on your Redis configuration, secrets can be stored entirely in memory without ever being written to disk for enhanced security

The fastest way to get started uses Docker with minimal configuration.

Terminal window
docker run -p 6379:6379 -d redis:bookworm
Terminal window
# Generate and store a persistent secret key
openssl rand -hex 32 > .ots_secret
chmod 600 .ots_secret
echo "Secret key saved to .ots_secret (keep this file secure!)"
Terminal window
# Run the container using the secret key
docker run -p 3000:3000 -d \
-e REDIS_URL=redis://host.docker.internal:6379/0 \
-e SECRET="$(cat .ots_secret)" \
-e HOST=localhost:3000 \
-e SSL=false \
-e RACK_ENV=production \
onetimesecret/onetimesecret:v0.26.2

Open your browser to:

For those who prefer manual setup, you’ll need:

  • Ruby 3.4+ (not available in default system packages — use rbenv or mise to install)
  • Redis 7+ or Valkey (Redis alternative)
  • Node.js 22+ and pnpm (only required for development and building frontend assets)

After cloning the repository, run the initialization script and build frontend assets:

Terminal window
bin/setup --init
cp .env.example .env
pnpm install && pnpm run build:local

To start the application:

Terminal window
source .env.sh # exports .env vars into the current shell
bundle exec puma -C etc/puma.rb

Or using the Procfile runner:

Terminal window
source .env.sh # exports .env vars into the current shell
bundle exec foreman start -f Procfile.production

See README for complete manual installation details.

  1. Navigate to http://localhost:3000
  2. Create a test secret to verify everything works
  3. Check the API status at http://localhost:3000/api/v2/status

With Valkey/Redis running and your .env loaded into the shell (set -a; source .env; set +a), create an admin account directly:

Terminal window
bundle exec bin/ots customers create admin@example.com --role colonel

This creates a verified account and prints a one-time generated password — save it — unless you pass --password. It works in both simple and full authentication modes. To promote an account that already exists:

Terminal window
bundle exec bin/ots customers role promote admin@example.com

Note: The admin area currently has limited functionality - it’s readonly config viewing with no user management. More features are planned for future releases.

Now that your instance is running:

  1. Reverse proxy and TLS for production use
  2. Review configuration options for customization