Deployment

SSL/TLS Setup

Serve the ScanSuite console over a custom certificate, or behind a web server the host already runs.

Serve the ScanSuite console over a custom certificate. If you also run the DefectDojo integration, it is a separate installation with its own domain and certificate — see Set up DefectDojo (Optional).

1. Register a domain name

Register a domain for the console in DNS, for example scansuite.yourdomain.com.

2. Stop the server

Before applying the certificate, stop ScanSuite:

Shell
cd /opt/scansuite && ./scansuite stop

3. Obtain a certificate

Obtain a certificate from the local Certificate Authority. If the ScanSuite server is publicly accessible, you can use Let's Encrypt instead.

Install Certbot

Shell
sudo snap install certbot --classic

Generate the certificate

Shell
sudo certbot certonly --register-unsafely-without-email --agree-tos -d scansuite.yourdomain.com

4. Replace the key and certificate

Copy the newly generated certificate and key to /opt/scansuite/services/nginx/certs/. Ensure the file names cert.pem and key.pem are preserved.

ScanSuite certs directory listing
The ScanSuite certificate directory

5. Start the server

Shell
cd /opt/scansuite && ./scansuite restart

6. Verify the certificate loaded

Check the nginx logs to confirm the certificate loaded correctly:

Shell
cd /opt/scansuite && docker compose logs nginx

If any errors appear, double-check the certificate paths and permissions. A certificate managed by certbot lives outside the certs directory, so the nginx configuration has to point at it — see Setup parameters and services.

Behind a web server the host already runs

When the host already serves ports 80 and 443 — its own nginx or Apache, or a proxy in front of several sites — keep the certificate there and let that server forward to ScanSuite. Publish the console on the loopback address and switch off ScanSuite's own nginx in docker-compose.local.yml, next to docker-compose.yml:

docker-compose.local.yml
services:
  web:
    ports:
      - "127.0.0.1:5000:5000"
  ai_docs:
    ports:
      - "127.0.0.1:4000:4000"
  nginx:
    profiles: ["bundled-nginx"]

The file belongs to the host: updates never change it, and install, update and start always include it. Apply it with a restart; ./scansuite doctor then reports that ports 80 and 443 are left to the host.

Shell
cd /opt/scansuite && ./scansuite restart

Point the host's web server at those ports. For nginx:

nginx
server {
    listen 443 ssl;
    server_name scansuite.yourdomain.com;
    ssl_certificate     /etc/letsencrypt/live/scansuite.yourdomain.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/scansuite.yourdomain.com/privkey.pem;
    client_max_body_size 2000M;
    proxy_read_timeout 600;
    proxy_send_timeout 600;

    location / {
        proxy_pass http://127.0.0.1:5000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
    location /aidocs/ {
        proxy_pass http://127.0.0.1:4000;
        proxy_set_header Host $host;
    }
}

Keep the body size and the timeouts, which are the ones ScanSuite's own nginx uses: code archives and reports are uploaded through the console, and without them the proxy cuts large uploads and long requests short with 413 and 504 errors.

Last reviewed 2026-09-27