Skip to content

Host Commands ​

These commands run on the machine that runs Docker — the console cannot run them for you, so there is no button in the UI for most of them. Run nikto-launcher <command> from anywhere; the launcher finds its own install folder.

In the examples on this page, nikto-launcher stands for whichever launcher binary you downloaded (for example ./nikto-launcher-linux-amd64).

Run nikto-launcher help (or --help, -h) for the full list of commands and options, and nikto-launcher version (or --version, -v) to see which release the launcher is. Every release uses the same file name, so if your browser saved a new download as nikto-launcher-macos-arm64 (1), check which file you are running.

--home PATH (or NIKTO_HOME=PATH) works on every command and points the whole deployment at a folder you choose instead of the default one. The path must be absolute, and you must pass it to every command — see Putting the install folder somewhere else.

Quick reference ​

TaskCommand
Start the stacknikto-launcher up
Stop the stacknikto-launcher down
Stop and delete all datanikto-launcher down --volumes
Uninstall (offers a final backup, then deletes everything)nikto-launcher uninstall
Show container statusnikto-launcher status
View logsnikto-launcher logs [service]
Update to the latest releasenikto-launcher update
Back up the database nownikto-launcher backup
Restore a backupnikto-launcher restore <file>
Create a support bundlenikto-launcher support-bundle
Show diagnostics as textnikto-launcher admin diag
Show login status / which admin existsnikto-launcher admin status
Get a first-login setup codenikto-launcher admin setup-code
Reset the admin passwordnikto-launcher admin reset-password
Sign in with a one-time linknikto-launcher admin login-link
Reset the database passwordnikto-launcher reset-db-password
Show the license textnikto-launcher license
Show the launcher version and pinned imagesnikto-launcher version (also --version, -v)
List every command and optionnikto-launcher help (also --help, -h)

Advanced: docker compose ​

The launcher writes a normal docker-compose.yml and .env into its install folder. If you know Docker Compose, you can run docker compose commands from that folder (the Compose project name is nikto-platform):

bash
docker compose -f docker-compose.yml --env-file .env ps
docker compose -f docker-compose.yml --env-file .env logs -f api

Use the launcher for updates, backups, and restores. nikto-launcher update checks that the images are pinned and backs up the database before it changes anything; plain docker compose does neither. Every launcher command rewrites docker-compose.yml from its own copy before it runs, so edits to it do not last.

Start & stop ​

up ​

nikto-launcher up [--dev] [--no-browser] [--no-update-check] [--ghcr-user NAME] [--ghcr-token TOKEN]

Creates the install folder on first run, checks that the compose file's images are pinned to a digest, writes GHCR_USER/GHCR_TOKEN to .env when passed, generates the database credentials on first start, logs in to ghcr.io and pulls the pinned images, starts the stack, waits for the console to answer, then opens it in your browser.

Before pulling, it warns (without stopping) if Docker has less than 6 GB of memory (8 GB with the headless browser enabled) or the install folder has less than 10 GB free. update runs the same checks.

  • --dev — use the locally built images instead of GHCR, and skip the pin and login/pull steps. Development use only.
  • --no-browser — do not open a browser window.
  • --ghcr-user / --ghcr-token — saved to .env so later runs need only up.

On first run it prints where LICENSE.txt and SETUP.md were written, and if no admin account exists yet, a boxed first-login setup code (see Operator Login).

Last, it checks whether a newer launcher has been released (see Newer-launcher check); --no-update-check skips this.

down ​

nikto-launcher down [--volumes]

Stops and removes the containers.

--volumes deletes all scan data

--volumes also deletes the database volume nikto-platform_pgdata — every project, scan, finding, log, and installed license. It cannot be undone. The command prints a warning before it runs.

To remove everything — containers, data, the install folder, and the images — use uninstall, which offers a final backup first.

status ​

nikto-launcher status

Runs docker compose ps and prints the console's URL.

logs ​

nikto-launcher logs [service]

Follows logs for every service, or for one named service (for example logs api). Press Ctrl-C to stop following.

Updates ​

nikto-launcher update [--no-backup] [--no-update-check]

Pulls the pinned images, backs up the database, then recreates the changed containers. The backup runs after the pull but before anything is recreated, so it captures the database still running the old version. If the backup fails, the update stops before any container is recreated. On success it waits for the console to come back and prints a first-login setup code if no admin account exists yet.

  • --no-backup — update without a pre-update backup. Use only if you must; the update prints a warning.
  • --no-update-check — do not check for a newer launcher at the end (see Newer-launcher check).

update pulls the images pinned by this launcher. To move to a newer release, download the newer launcher first, then run its update. The launcher tells you when one exists.

If the stack was previously taken down (down, or docker compose down) so no database container exists at all, the update refuses rather than create one from the freshly pulled images — it tells you to run backup first (that creates the container), then update again.

Full detail, including what a failed pull, a failed backup, or a fresh install do: Backups.

Backups ​

nikto-launcher backup

Writes a verified manual backup (backups/manual-<timestamp>.dump) and prints its path and size. Starts the database container if it is not running; nothing else is touched. Manual backups are never deleted automatically.

nikto-launcher restore <file> [--yes] [--no-backup]

Replaces all current data

A restore replaces every project, scan, finding, setting, and the operator login with the contents of the backup. Verify the backup first; if you are not sure, take a manual backup before restoring.

<file> can be a full path or just a file name from the backups folder. Run the command with no file to see the available backups. The restore verifies the file, asks for confirmation (--yes skips this), stops the api and ui services, takes a safety backup of the current data unless --no-backup, loads the backup in one transaction, then restarts the stack. A failed load leaves api/ui stopped on purpose and names where the safety backup is.

Full walkthrough: Backups.

Sign-in & accounts ​

These are subcommands of nikto-launcher admin, which runs /api admin ... inside the running api container. It requires the api container to already be running — it refuses with a message telling you to start the stack first if it is not. Exit code 0 means the subcommand succeeded, 1 means it ran and failed, 2 means the command line itself was wrong (unknown subcommand or missing --user value) — worth checking if you call these from a script.

SubcommandWhat it does
statusShows whether login is enabled and lists the admin account(s), or reports setup required if none exists yet
setup-codeIssues a new 24-hour, one-time first-login setup code. Fails if an admin account already exists
reset-password [--user NAME]Prints a new random password for the account, signs out every session for it, and clears any login lock
login-link [--user NAME]Prints a one-time sign-in link, valid 10 minutes and usable once, that works even while the account is locked and clears the lock

--user NAME selects which account to act on and is required only when more than one admin account exists.

login-link prints the full URL (http://localhost:<port>/#login=...), using UI_PORT from .env.

Full walkthrough for each of these, including what to do when locked out or you have forgotten your password or username: Operator Login.

Diagnostics & support ​

nikto-launcher admin diag

Prints the same information as the Status page (/nikto-diag) as plain text, without needing to sign in. Read-only.

nikto-launcher support-bundle [--no-logs] [--tail N] [--out DIR]

Writes a single diagnostics file (support-bundle-<timestamp>.zip) to your Downloads folder, or to the current directory if you have no Downloads folder, and prints its full path, size, and contents. It contains the Docker and Compose versions, docker compose ps -a, the diagnostics above, .env with secret values replaced, and the last log lines of each running service. Nothing uploads anywhere; nothing includes database contents, backups, the database password file (secrets/db_password), or the license file. A step that fails (for example, the api container not running) is recorded inside the bundle rather than skipped silently.

  • --no-logs — leave out container logs.
  • --tail N — log lines per service (default 2000).
  • --out DIR — write the bundle into DIR instead (it must already exist). Default: $XDG_DOWNLOAD_DIR if set (Linux), else ~/Downloads, else the current directory. The bundle is not written into the install folder.

Full contents and redaction rules: Support bundle.

Database password ​

nikto-launcher reset-db-password [--random | --password VALUE]

Fixes a mismatch between .env's POSTGRES_PASSWORD and the password the database was actually created with (a lost or hand-edited .env, or an old data volume restored under a newer one). With no flag, it re-syncs the database role to whatever .env already says and leaves .env unchanged. --random generates a new password and writes it to .env; --password VALUE sets a specific one and writes it to .env (it refuses a value that starts or ends with a space or contains a line break). Either way it rewrites secrets/db_password from .env and then restarts the API so it reconnects with the correct credentials.

The command does not ask for confirmation.

Info ​

nikto-launcher license

Prints the full proprietary license text. The launcher also writes it as LICENSE.txt into its install folder. For the end-user terms that apply to using the product, see the End User License Agreement.

nikto-launcher help (also --help, -h)

Lists every launcher command with its options, grouped as on this page.

nikto-launcher version (also --version, -v)

Prints the launcher's own version followed by the exact, digest-pinned image references it runs, then checks for a newer launcher: it prints either the newer-launcher line below or This is the newest release.--no-update-check skips the check.

Newer-launcher check ​

After a successful up or update, and on version, the launcher looks up the newest release. When a newer one exists it prints:

text
A newer launcher is available: v0.1.0-beta.3 (this is v0.1.0-beta.2). Download it from https://github.com/hackllc/nikto-platform-support/releases/latest — then run `update` with the new launcher.

What it contacts: only ghcr.io, the same registry the images are pulled from, with the same GHCR_USER/GHCR_TOKEN from .env. It exchanges them for a read-only pull token and reads the tag list of hackllc/nikto-platform-api. Nothing about your install or scans is sent.

It never stops or fails the command. It gives up after 5 seconds, with no retry. If anything goes wrong (no network, a rejected token, a timeout), it prints one line naming the step that failed, for example Could not check for a newer launcher: token exchange with ghcr.io: HTTP 401 Unauthorized (...). If .env has no GitHub credentials, it says so and skips the check.

To turn it off (for example on an air-gapped host), pass --no-update-check or set NIKTO_NO_UPDATE_CHECK=1 in the environment. Dev builds (--dev, or a launcher built without a release version) never check.

Uninstall ​

nikto-launcher uninstall [--yes] [--backup-to PATH | --no-backup] [--keep-images]

Deletes all data on this machine

Uninstall deletes the database volume nikto-platform_pgdata (every project, scan, finding, log, setting, and installed license), the install folder (including .env and every backup in its backups folder), and the images. It cannot be undone. Keep the final backup it offers if you may want the data again.

It runs in this order and stops at the first step that fails:

  1. Shows what it will delete — the containers and networks, the database volume, the install folder by full path, and how many backups are in its backups folder — then asks:

    text
    Are you sure? This permanently deletes all Nikto Platform data on this machine. [y/N]:

    Only y or yes continues. Anything else, including just Enter, prints Uninstall canceled; nothing was changed.

  2. Offers a final backup, suggesting a file in your Downloads folder:

    text
    Back up existing data to [/Users/you/Downloads/nikto-platform-final-20260930-120000.dump] (Enter to accept, type a path to change it, or "no" to skip):

    Press Enter to accept, type a folder (the suggested file name is used inside it) or a full file path (~ is your home folder), or type no to skip. The backup must be outside the install folder, because that folder is deleted; a path inside it is refused and you are asked again. The backup is verified the same way as backup and saved readable only by you. If it fails, the uninstall stops and nothing is deleted. When there is no database volume, there is nothing to back up and the question is skipped.

  3. Deletes the containers, networks and database volume, then the install folder, then the images the launcher's compose file names (the platform's own images plus postgres, chromedp/headless-shell and nginxinc/nginx-unprivileged). If removing the containers or the folder fails, it stops and says what was and was not removed. An image it cannot remove — for example one another container on this machine still uses — is only a warning naming the image, because your data is already gone.

  4. Prints a summary: what was removed, where the final backup is, the path of the launcher binary to delete by hand, and a reminder that Docker may still hold the ghcr.io login (docker logout ghcr.io clears it).

To restore the final backup later, install again with nikto-launcher up, then run nikto-launcher restore <file> with the backup's full path.

  • --yes — do not ask for confirmation.
  • --backup-to PATH — write the final backup to this file or folder without asking.
  • --no-backup — skip the final backup. Cannot be combined with --backup-to.
  • --keep-images — leave the images in Docker (for example to reinstall later without downloading them again).

When nothing can be typed in (input is not a terminal, as in a script), the command refuses to start unless it gets --yes and exactly one of --backup-to PATH or --no-backup:

bash
nikto-launcher uninstall --yes --backup-to ~/nikto-final.dump

To stop the platform but keep everything for later, use down instead.

Next steps ​

Proprietary software. Licensed for use under the End User License Agreement.