Skip to content

Linux

The central service and the node run on any 64-bit Linux that .NET 10 supports (Ubuntu, Debian, RHEL and its rebuilds, SUSE). On Linux the central service uses PostgreSQL and signs console users in with its own local accounts by default. Docker is the quickest way to run both; this page is for running them as ordinary services.

Download the packages for your servers from the download page: routes-central-<version>-linux-x64.tar.gz and routes-node-<version>-linux-x64.tar.gz (or linux-arm64). They are self-contained: the servers need no .NET runtime.

Terminal window
sudo mkdir -p /opt/routes
sudo tar -xzf routes-central-<version>-linux-x64.tar.gz -C /opt/routes && sudo mv /opt/routes/routes-central /opt/routes/central
sudo tar -xzf routes-node-<version>-linux-x64.tar.gz -C /opt/routes && sudo mv /opt/routes/routes-node /opt/routes/node
  1. Create a user for the services, without a login shell:

    Terminal window
    sudo useradd --system --no-create-home --shell /usr/sbin/nologin routes
  2. Create the data and log folders and give them to that user. The services make them readable by their own user only (mode 700) when they start.

    Terminal window
    sudo mkdir -p /var/lib/routes/central /var/lib/routes/node /var/log/routes/central /var/log/routes/node /etc/routes
    sudo chown -R routes: /var/lib/routes /var/log/routes
Central service Node
Program /opt/routes/central/Routes.Central /opt/routes/node/Routes.Node
Data /var/lib/routes/central /var/lib/routes/node
Logs /var/log/routes/central /var/log/routes/node

The log also goes to standard output, so it appears in the journal (journalctl -u routes-central).

On Linux, settings come from environment variables (Routes__Central__… and Routes__Node__…), from appsettings.json next to the program, or from the command line (--Central:…, --Node:…), in that order of precedence. An environment file per service, readable by root only, keeps secrets out of the unit file.

/etc/routes/central.env:

Routes__Central__DatabaseProvider=PostgreSql
Routes__Central__ConnectionString=Host=db01;Database=routes;Username=routes;Password=<password>
# Optional: a certificate browsers and nodes trust (otherwise a self-signed one is made)
Routes__Central__CertificatePath=/etc/routes/central.pfx
Routes__Central__CertificatePassword=<password>

/etc/routes/node.env:

Routes__Node__CentralUrl=https://central01.contoso.local:5080/
Routes__Node__ApiKey=<enrollment key>
# For a self-signed central certificate: its thumbprint, from Configuration › Node enrollment
Routes__Node__CentralCertificateThumbprints=<thumbprint>
Terminal window
sudo chmod 600 /etc/routes/*.env

/etc/systemd/system/routes-central.service:

[Unit]
Description=Symmetricare Routes Central Service
After=network-online.target postgresql.service
Wants=network-online.target
[Service]
ExecStart=/opt/routes/central/Routes.Central
WorkingDirectory=/opt/routes/central
User=routes
EnvironmentFile=/etc/routes/central.env
Restart=always
RestartSec=5
[Install]
WantedBy=multi-user.target

/etc/systemd/system/routes-node.service is the same with Routes.Node, /opt/routes/node and /etc/routes/node.env. Then:

Terminal window
sudo systemctl daemon-reload
sudo systemctl enable --now routes-central routes-node

On first start the central service creates its database and an admin account, with a random password in /var/lib/routes/central/initial-admin-password.txt (readable by the service only; never written to the log):

Terminal window
sudo cat /var/lib/routes/central/initial-admin-password.txt

Open https://<server>:5080/, sign in as admin and choose your own password. Then add accounts for your team under Configuration › Users. See Console sign-in.

Ports below 1024 need a privilege an ordinary user does not have. Either give the node program the capability:

Terminal window
sudo setcap 'cap_net_bind_service=+ep' /opt/routes/node/Routes.Node

or let the node listen on a higher port (such as 11112) and forward 104 to it in the firewall.

On Windows, secrets are protected with Windows’ own data protection. On Linux:

  • The central service protects them with a certificate, secret-protection.pfx, which it makes in its data folder on first start (or the file named by Routes__Central__SecretProtectionCertificatePath).

  • A node protects its own key and secrets with protection.key in its data folder, or with a 32-byte key (base64) in the environment variable ROUTES_PROTECTION_KEY. With Encrypt traffic kept on nodes on, set ROUTES_PROTECTION_KEY (from a secret store, not a file beside the data): otherwise the key that unlocks the data is on the same disk as the data.

A node uses a certificate file on Linux: Routes__Node__TlsCertificatePath (PKCS#12, or PEM with Routes__Node__TlsCertificateKeyPath), with Routes__Node__TlsCertificatePassword if it has one. It is read again every hour, so renewed certificates are picked up without a restart. See DICOM TLS.