Linux
The central service and the node run on any 64-bit Linux that .NET 10 supports (Ubuntu, Debian, RHEL and its rebuilds, SUSE). On Linux the central service uses PostgreSQL and signs console users in with its own local accounts by default. Docker is the quickest way to run both; this page is for running them as ordinary services.
Get the programs
Section titled “Get the programs”Download the packages for your servers from the download page:
routes-central-<version>-linux-x64.tar.gz and routes-node-<version>-linux-x64.tar.gz (or linux-arm64). They are
self-contained: the servers need no .NET runtime.
sudo mkdir -p /opt/routessudo tar -xzf routes-central-<version>-linux-x64.tar.gz -C /opt/routes && sudo mv /opt/routes/routes-central /opt/routes/centralsudo tar -xzf routes-node-<version>-linux-x64.tar.gz -C /opt/routes && sudo mv /opt/routes/routes-node /opt/routes/nodeAccounts and folders
Section titled “Accounts and folders”-
Create a user for the services, without a login shell:
Terminal window sudo useradd --system --no-create-home --shell /usr/sbin/nologin routes -
Create the data and log folders and give them to that user. The services make them readable by their own user only (mode 700) when they start.
Terminal window sudo mkdir -p /var/lib/routes/central /var/lib/routes/node /var/log/routes/central /var/log/routes/node /etc/routessudo chown -R routes: /var/lib/routes /var/log/routes
| Central service | Node | |
|---|---|---|
| Program | /opt/routes/central/Routes.Central |
/opt/routes/node/Routes.Node |
| Data | /var/lib/routes/central |
/var/lib/routes/node |
| Logs | /var/log/routes/central |
/var/log/routes/node |
The log also goes to standard output, so it appears in the journal (journalctl -u routes-central).
Settings
Section titled “Settings”On Linux, settings come from environment variables (Routes__Central__… and Routes__Node__…), from
appsettings.json next to the program, or from the command line (--Central:…, --Node:…), in that order of
precedence. An environment file per service, readable by root only, keeps secrets out of the unit file.
/etc/routes/central.env:
Routes__Central__DatabaseProvider=PostgreSqlRoutes__Central__ConnectionString=Host=db01;Database=routes;Username=routes;Password=<password># Optional: a certificate browsers and nodes trust (otherwise a self-signed one is made)Routes__Central__CertificatePath=/etc/routes/central.pfxRoutes__Central__CertificatePassword=<password>/etc/routes/node.env:
Routes__Node__CentralUrl=https://central01.contoso.local:5080/Routes__Node__ApiKey=<enrollment key># For a self-signed central certificate: its thumbprint, from Configuration › Node enrollmentRoutes__Node__CentralCertificateThumbprints=<thumbprint>sudo chmod 600 /etc/routes/*.envsystemd services
Section titled “systemd services”/etc/systemd/system/routes-central.service:
[Unit]Description=Symmetricare Routes Central ServiceAfter=network-online.target postgresql.serviceWants=network-online.target
[Service]ExecStart=/opt/routes/central/Routes.CentralWorkingDirectory=/opt/routes/centralUser=routesEnvironmentFile=/etc/routes/central.envRestart=alwaysRestartSec=5
[Install]WantedBy=multi-user.target/etc/systemd/system/routes-node.service is the same with Routes.Node, /opt/routes/node and
/etc/routes/node.env. Then:
sudo systemctl daemon-reloadsudo systemctl enable --now routes-central routes-nodeFirst sign-in
Section titled “First sign-in”On first start the central service creates its database and an admin account, with a random password in
/var/lib/routes/central/initial-admin-password.txt (readable by the service only; never written to the log):
sudo cat /var/lib/routes/central/initial-admin-password.txtOpen https://<server>:5080/, sign in as admin and choose your own password. Then add accounts for your team under
Configuration › Users. See Console sign-in.
DICOM’s port 104
Section titled “DICOM’s port 104”Ports below 1024 need a privilege an ordinary user does not have. Either give the node program the capability:
sudo setcap 'cap_net_bind_service=+ep' /opt/routes/node/Routes.Nodeor let the node listen on a higher port (such as 11112) and forward 104 to it in the firewall.
Stored secrets
Section titled “Stored secrets”On Windows, secrets are protected with Windows’ own data protection. On Linux:
-
The central service protects them with a certificate,
secret-protection.pfx, which it makes in its data folder on first start (or the file named byRoutes__Central__SecretProtectionCertificatePath). -
A node protects its own key and secrets with
protection.keyin its data folder, or with a 32-byte key (base64) in the environment variableROUTES_PROTECTION_KEY. With Encrypt traffic kept on nodes on, setROUTES_PROTECTION_KEY(from a secret store, not a file beside the data): otherwise the key that unlocks the data is on the same disk as the data.
DICOM TLS
Section titled “DICOM TLS”A node uses a certificate file on Linux: Routes__Node__TlsCertificatePath (PKCS#12, or PEM with
Routes__Node__TlsCertificateKeyPath), with Routes__Node__TlsCertificatePassword if it has one. It is read again
every hour, so renewed certificates are picked up without a restart. See DICOM TLS.
