Appearance
Host Commands
These commands run on the machine that runs Docker — the console cannot run them for you, so there is no button in the UI for most of them. Run nikto-launcher <command> from anywhere; the launcher finds its own install folder.
In the examples on this page, nikto-launcher stands for whichever launcher binary you downloaded (for example ./nikto-launcher-linux-amd64).
Run nikto-launcher help (or --help, -h) for the full list of commands and options, and nikto-launcher version (or --version, -v) to see which release the launcher is. Every release uses the same file name, so if your browser saved a new download as nikto-launcher-macos-arm64 (1), check which file you are running.
--home PATH (or NIKTO_HOME=PATH) works on every command and points the whole deployment at a folder you choose instead of the default one. The path must be absolute, and you must pass it to every command — see Putting the install folder somewhere else.
Quick reference
| Task | Command |
|---|---|
| Start the stack | nikto-launcher up |
| Stop the stack | nikto-launcher down |
| Stop and delete all data | nikto-launcher down --volumes |
| Uninstall (offers a final backup, then deletes everything) | nikto-launcher uninstall |
| Show container status | nikto-launcher status |
| View logs | nikto-launcher logs [service] |
| Update to the latest release | nikto-launcher update |
| Back up the database now | nikto-launcher backup |
| Restore a backup | nikto-launcher restore <file> |
| Create a support bundle | nikto-launcher support-bundle |
| Show diagnostics as text | nikto-launcher admin diag |
| Show login status / which admin exists | nikto-launcher admin status |
| Get a first-login setup code | nikto-launcher admin setup-code |
| Reset the admin password | nikto-launcher admin reset-password |
| Sign in with a one-time link | nikto-launcher admin login-link |
| Reset the database password | nikto-launcher reset-db-password |
| Show the license text | nikto-launcher license |
| Show the launcher version and pinned images | nikto-launcher version (also --version, -v) |
| List every command and option | nikto-launcher help (also --help, -h) |
Advanced: docker compose
The launcher writes a normal docker-compose.yml and .env into its install folder. If you know Docker Compose, you can run docker compose commands from that folder (the Compose project name is nikto-platform):
bash
docker compose -f docker-compose.yml --env-file .env ps
docker compose -f docker-compose.yml --env-file .env logs -f apiUse the launcher for updates, backups, and restores. nikto-launcher update checks that the images are pinned and backs up the database before it changes anything; plain docker compose does neither. Every launcher command rewrites docker-compose.yml from its own copy before it runs, so edits to it do not last.
Start & stop
up
nikto-launcher up [--dev] [--no-browser] [--no-update-check] [--ghcr-user NAME] [--ghcr-token TOKEN]
Creates the install folder on first run, checks that the compose file's images are pinned to a digest, writes GHCR_USER/GHCR_TOKEN to .env when passed, generates the database credentials on first start, logs in to ghcr.io and pulls the pinned images, starts the stack, waits for the console to answer, then opens it in your browser.
Before pulling, it warns (without stopping) if Docker has less than 6 GB of memory (8 GB with the headless browser enabled) or the install folder has less than 10 GB free. update runs the same checks.
--dev— use the locally built images instead of GHCR, and skip the pin and login/pull steps. Development use only.--no-browser— do not open a browser window.--ghcr-user/--ghcr-token— saved to.envso later runs need onlyup.
On first run it prints where LICENSE.txt and SETUP.md were written, and if no admin account exists yet, a boxed first-login setup code (see Operator Login).
Last, it checks whether a newer launcher has been released (see Newer-launcher check); --no-update-check skips this.
down
nikto-launcher down [--volumes]
Stops and removes the containers.
--volumes deletes all scan data
--volumes also deletes the database volume nikto-platform_pgdata — every project, scan, finding, log, and installed license. It cannot be undone. The command prints a warning before it runs.
To remove everything — containers, data, the install folder, and the images — use uninstall, which offers a final backup first.
status
nikto-launcher status
Runs docker compose ps and prints the console's URL.
logs
nikto-launcher logs [service]
Follows logs for every service, or for one named service (for example logs api). Press Ctrl-C to stop following.
Updates
nikto-launcher update [--no-backup] [--no-update-check]
Pulls the pinned images, backs up the database, then recreates the changed containers. The backup runs after the pull but before anything is recreated, so it captures the database still running the old version. If the backup fails, the update stops before any container is recreated. On success it waits for the console to come back and prints a first-login setup code if no admin account exists yet.
--no-backup— update without a pre-update backup. Use only if you must; the update prints a warning.--no-update-check— do not check for a newer launcher at the end (see Newer-launcher check).
update pulls the images pinned by this launcher. To move to a newer release, download the newer launcher first, then run its update. The launcher tells you when one exists.
If the stack was previously taken down (down, or docker compose down) so no database container exists at all, the update refuses rather than create one from the freshly pulled images — it tells you to run backup first (that creates the container), then update again.
Full detail, including what a failed pull, a failed backup, or a fresh install do: Backups.
Backups
nikto-launcher backup
Writes a verified manual backup (backups/manual-<timestamp>.dump) and prints its path and size. Starts the database container if it is not running; nothing else is touched. Manual backups are never deleted automatically.
nikto-launcher restore <file> [--yes] [--no-backup]
Replaces all current data
A restore replaces every project, scan, finding, setting, and the operator login with the contents of the backup. Verify the backup first; if you are not sure, take a manual backup before restoring.
<file> can be a full path or just a file name from the backups folder. Run the command with no file to see the available backups. The restore verifies the file, asks for confirmation (--yes skips this), stops the api and ui services, takes a safety backup of the current data unless --no-backup, loads the backup in one transaction, then restarts the stack. A failed load leaves api/ui stopped on purpose and names where the safety backup is.
Full walkthrough: Backups.
Sign-in & accounts
These are subcommands of nikto-launcher admin, which runs /api admin ... inside the running api container. It requires the api container to already be running — it refuses with a message telling you to start the stack first if it is not. Exit code 0 means the subcommand succeeded, 1 means it ran and failed, 2 means the command line itself was wrong (unknown subcommand or missing --user value) — worth checking if you call these from a script.
| Subcommand | What it does |
|---|---|
status | Shows whether login is enabled and lists the admin account(s), or reports setup required if none exists yet |
setup-code | Issues a new 24-hour, one-time first-login setup code. Fails if an admin account already exists |
reset-password [--user NAME] | Prints a new random password for the account, signs out every session for it, and clears any login lock |
login-link [--user NAME] | Prints a one-time sign-in link, valid 10 minutes and usable once, that works even while the account is locked and clears the lock |
--user NAME selects which account to act on and is required only when more than one admin account exists.
login-link prints the full URL (http://localhost:<port>/#login=...), using UI_PORT from .env.
Full walkthrough for each of these, including what to do when locked out or you have forgotten your password or username: Operator Login.
Diagnostics & support
nikto-launcher admin diag
Prints the same information as the Status page (/nikto-diag) as plain text, without needing to sign in. Read-only.
nikto-launcher support-bundle [--no-logs] [--tail N] [--out DIR]
Writes a single diagnostics file (support-bundle-<timestamp>.zip) to your Downloads folder, or to the current directory if you have no Downloads folder, and prints its full path, size, and contents. It contains the Docker and Compose versions, docker compose ps -a, the diagnostics above, .env with secret values replaced, and the last log lines of each running service. Nothing uploads anywhere; nothing includes database contents, backups, the database password file (secrets/db_password), or the license file. A step that fails (for example, the api container not running) is recorded inside the bundle rather than skipped silently.
--no-logs— leave out container logs.--tail N— log lines per service (default 2000).--out DIR— write the bundle intoDIRinstead (it must already exist). Default:$XDG_DOWNLOAD_DIRif set (Linux), else~/Downloads, else the current directory. The bundle is not written into the install folder.
Full contents and redaction rules: Support bundle.
Database password
nikto-launcher reset-db-password [--random | --password VALUE]
Fixes a mismatch between .env's POSTGRES_PASSWORD and the password the database was actually created with (a lost or hand-edited .env, or an old data volume restored under a newer one). With no flag, it re-syncs the database role to whatever .env already says and leaves .env unchanged. --random generates a new password and writes it to .env; --password VALUE sets a specific one and writes it to .env (it refuses a value that starts or ends with a space or contains a line break). Either way it rewrites secrets/db_password from .env and then restarts the API so it reconnects with the correct credentials.
The command does not ask for confirmation.
Info
nikto-launcher license
Prints the full proprietary license text. The launcher also writes it as LICENSE.txt into its install folder. For the end-user terms that apply to using the product, see the End User License Agreement.
nikto-launcher help (also --help, -h)
Lists every launcher command with its options, grouped as on this page.
nikto-launcher version (also --version, -v)
Prints the launcher's own version followed by the exact, digest-pinned image references it runs, then checks for a newer launcher: it prints either the newer-launcher line below or This is the newest release.--no-update-check skips the check.
Newer-launcher check
After a successful up or update, and on version, the launcher looks up the newest release. When a newer one exists it prints:
text
A newer launcher is available: v0.1.0-beta.3 (this is v0.1.0-beta.2). Download it from https://github.com/hackllc/nikto-platform-support/releases/latest — then run `update` with the new launcher.What it contacts: only ghcr.io, the same registry the images are pulled from, with the same GHCR_USER/GHCR_TOKEN from .env. It exchanges them for a read-only pull token and reads the tag list of hackllc/nikto-platform-api. Nothing about your install or scans is sent.
It never stops or fails the command. It gives up after 5 seconds, with no retry. If anything goes wrong (no network, a rejected token, a timeout), it prints one line naming the step that failed, for example Could not check for a newer launcher: token exchange with ghcr.io: HTTP 401 Unauthorized (...). If .env has no GitHub credentials, it says so and skips the check.
To turn it off (for example on an air-gapped host), pass --no-update-check or set NIKTO_NO_UPDATE_CHECK=1 in the environment. Dev builds (--dev, or a launcher built without a release version) never check.
Uninstall
nikto-launcher uninstall [--yes] [--backup-to PATH | --no-backup] [--keep-images]
Deletes all data on this machine
Uninstall deletes the database volume nikto-platform_pgdata (every project, scan, finding, log, setting, and installed license), the install folder (including .env and every backup in its backups folder), and the images. It cannot be undone. Keep the final backup it offers if you may want the data again.
It runs in this order and stops at the first step that fails:
Shows what it will delete — the containers and networks, the database volume, the install folder by full path, and how many backups are in its
backupsfolder — then asks:textAre you sure? This permanently deletes all Nikto Platform data on this machine. [y/N]:Only
yoryescontinues. Anything else, including just Enter, printsUninstall canceled; nothing was changed.Offers a final backup, suggesting a file in your Downloads folder:
textBack up existing data to [/Users/you/Downloads/nikto-platform-final-20260930-120000.dump] (Enter to accept, type a path to change it, or "no" to skip):Press Enter to accept, type a folder (the suggested file name is used inside it) or a full file path (
~is your home folder), or typenoto skip. The backup must be outside the install folder, because that folder is deleted; a path inside it is refused and you are asked again. The backup is verified the same way asbackupand saved readable only by you. If it fails, the uninstall stops and nothing is deleted. When there is no database volume, there is nothing to back up and the question is skipped.Deletes the containers, networks and database volume, then the install folder, then the images the launcher's compose file names (the platform's own images plus
postgres,chromedp/headless-shellandnginxinc/nginx-unprivileged). If removing the containers or the folder fails, it stops and says what was and was not removed. An image it cannot remove — for example one another container on this machine still uses — is only a warning naming the image, because your data is already gone.Prints a summary: what was removed, where the final backup is, the path of the launcher binary to delete by hand, and a reminder that Docker may still hold the
ghcr.iologin (docker logout ghcr.ioclears it).
To restore the final backup later, install again with nikto-launcher up, then run nikto-launcher restore <file> with the backup's full path.
--yes— do not ask for confirmation.--backup-to PATH— write the final backup to this file or folder without asking.--no-backup— skip the final backup. Cannot be combined with--backup-to.--keep-images— leave the images in Docker (for example to reinstall later without downloading them again).
When nothing can be typed in (input is not a terminal, as in a script), the command refuses to start unless it gets --yes and exactly one of --backup-to PATH or --no-backup:
bash
nikto-launcher uninstall --yes --backup-to ~/nikto-final.dumpTo stop the platform but keep everything for later, use down instead.
Next steps
- Docker Deployment — install, update, and uninstall
- Backups — what is backed up and how restore works
- Operator Login — first login, lockouts, and password recovery
- Status and diagnostics — the
/nikto-diagpage these commands read