env-municipio-docker-vm

Quick start

On a fresh Ubuntu Server 22.04/24.04/26.04 LTS or Debian 12/13 amd64 VM, run:

curl -fL https://install.getmunicipio.com/installer.sh -o installer.sh
sudo sh installer.sh

The wizard runs on the VM, shows numbered choices, and suggests an answer in [brackets] that Enter accepts. For a single server it asks:

  1. How many servers? Press Enter for this server only.
  2. The website: its web address (a pasted https://…/ is trimmed to the hostname), who takes care of the HTTPS certificate (press Enter to let this server do it), and the WordPress administrator’s email.
  3. Passwords: the WordPress login password, or Enter to create one. The database passwords are always generated.

Finally it asks whether to change advanced settings (Enter for no), shows a summary, and installs. The server name and address are detected automatically. Under advanced settings you can choose Docker Swarm, the administrator user name, the database name and user, and type your own database passwords.

When it finishes, the application, MariaDB and Caddy containers and the health timer are started and enabled for reboot. Docker and small host utilities were installed as packages. Open the site hostname in a browser. Check the server with:

sudo /scripts/status.municipio.sh
sudo /scripts/refresh-sites.municipio.sh

The refresh command registers WordPress site hostnames with Caddy and runs automatically every minute. See WordPress site discovery.

If setup stops after saving the configuration, run sudo sh installer.sh again and choose yes to resume. The installer first checks that the saved settings are complete. The same command updates a server installed by an older installer version: it lists the settings that are new since then, asks only the questions they need (such as the ACME DNS-01 challenge), keeps every existing value, saves the previous file next to it as municipio.env.<timestamp>.bak, and runs the installation again. A missing Docker socket usually means the Engine service did not start; check sudo systemctl status docker.service and sudo journalctl -u docker.service if the retry cannot start it.

The generated settings are at /etc/municipio/municipio.env, readable only by root. Generated passwords are not printed. If the WordPress password was generated, the wizard ends by showing the sudo grep WP_ADMIN_PASSWORD … command that reveals it. Values are written single-quoted, because the file is read both by bash and by Docker Compose’s dotenv parser — keep that form if you edit it. To update the application image later, use /scripts/update.municipio.sh with an exact image digest; the MariaDB and Caddy images have their own deliberate procedure in the runbook.

The documentation is published at https://install.getmunicipio.com/. The custom domain serves the installer and uninstaller from this repository. If the HTTPS certificate is still provisioning, use GitHub HTTPS for the installer or uninstaller download instead. The bootstrap script downloads the source bundle from the GitHub main branch over HTTPS.

To test a branch before it is merged, download that branch’s installer.sh and point it at the branch archive. Put the variable after sudo, which does not pass on variables set before it:

BRANCH=feat/my-branch
curl -fL "https://raw.githubusercontent.com/helsingborg-stad/env-municipio-docker-vm/$BRANCH/installer.sh" -o installer.sh
sudo MUNICIPIO_SOURCE_URL="https://github.com/helsingborg-stad/env-municipio-docker-vm/archive/refs/heads/$BRANCH.tar.gz" sh installer.sh

To remove the installation, download and run the uninstaller the same way. It deletes the database, uploads and backups, and removes Docker Engine; see Uninstalling.

curl -fL https://install.getmunicipio.com/uninstaller.sh -o uninstaller.sh
sudo sh uninstaller.sh

For a two-VM cluster, choose two servers (cluster-manual) or two servers plus a tie-breaker (cluster-arbitrator) in step 1, then say which server this is and give the name and internal IP address of each server. On both website servers, type the same cluster password (at least 16 characters) and the same WordPress password. The database passwords are derived from the cluster password, so both data VMs end up with identical ones in whatever order they are installed. They must match because a Galera state transfer replicates the privilege tables. The first install prepares services but cannot start a cluster alone. Once peers are ready, the wizard can bootstrap or join a node; Swarm workers also need a join token and a manager-side enable-node command. Follow the cluster runbook for the safe order, including cluster.municipio.sh clear-bootstrap-flag once the peer has joined. Swarm is available under the wizard’s advanced settings.