Deployment

Technical Requirements

Hardware, operating system and network requirements for the server.

ScanSuite Teams and its associated components are fully containerized, making it compatible with any Linux-based operating system that supports Docker. For optimal performance and stability, Ubuntu 22.04+ is the recommended OS.

Hardware requirements

The required system resources depend on the number of parallel scans and the specific scanners used. The following configuration is recommended for optimal performance:

ResourceRecommended
CPU4 cores
Memory16 GB RAM
Storage100 GB SSD

This setup supports local storage of all scanners and allows execution of 3–4 parallel scans, including resource-intensive ones.

Most of the disk goes on scanner images: a full installation downloads about 40 GB of them. A host installed without the external scanners and DefectDojo needs about 7 GB for images — see Install ScanSuite Teams for choosing what is installed. Scans, their work files and the logs need room on top of that, in /var/tmp and in Docker's volumes.

Software dependencies

Docker is the only prerequisite. The ScanSuite installer will automatically install Docker on the following Linux distributions:

  • Ubuntu
  • CentOS
  • Debian Bookworm / Kali

For other distributions, Docker must be installed manually before proceeding with the ScanSuite installation.

Install as an ordinary account with sudo rights. The installer uses sudo to install Docker, to register the systemd service that starts ScanSuite at boot, and to create /opt/scansuite. After that the installation belongs to that account and is managed without sudo.

Ports

ScanSuite serves the console on ports 80 and 443 through its own nginx. If the host already runs a web server on them, ScanSuite can sit behind it instead — see SSL/TLS Setup.

DefectDojo integration

ScanSuite manages findings — including every AI-driven scan — in its own Vulnerabilities section, so DefectDojo is only needed if the team already uses it for classic-scanner findings. See Set up DefectDojo (Optional) if you want it.

  • By default the installer deploys DefectDojo on the same host as ScanSuite; pass --no-dojo to skip it.
  • It can also run on a separate server, provided it is reachable over HTTPS by ScanSuite.

Installation requirements

To install and run ScanSuite, the following credentials and files are required:

  • License key file: company_name_keyID.lic
  • Authentication credentials: the password for downloading and updating ScanSuite containers

Network and firewall configuration

If the installation is performed in an environment with restricted internet access, ensure that the following URLs are whitelisted in the firewall:

Allow-list
https://raw.githubusercontent.com
https://github.com
https://get.docker.com
https://download.docker.com
https://registry-1.docker.io
https://auth.docker.io
https://production.cloudflare.docker.com
https://production.cloudfront.docker.com

Docker Hub serves image layers from more than one content delivery network, so allow both of its production.*.docker.com hosts. A pull that stops once with TLS handshake timeout is usually passing trouble — run the install again. If it fails the same way every time, a firewall or proxy is letting the registry through but not the layer downloads.

Last reviewed 2026-09-27