Install
evertap runs on one machine: a home server, a VPS, or the computer you develop on. That machine
runs the databases and buckets in Docker. The same evertap command is also the CLI you use on
your laptop and in CI, which needs no Docker (Connect from your laptop).
Requirements
On the machine that runs evertap:
- Linux on x64 or arm64, with Docker Engine 24 or later. Use 28.0 or later (28.3.3 or later with firewalld): older versions let other machines on your network reach what Docker publishes on 127.0.0.1, which includes every database and bucket, without going through evertap. The Doctor warns about it.
- Or macOS on Apple silicon or Intel, with Docker Desktop, OrbStack, or Colima, to use evertap
on that Mac itself (
localmode, see Choose how evertap is reached). - Your user can use Docker without sudo. Add it to the
dockergroup withsudo usermod -aG docker $USER, then log out and back in. Being in that group is as good as being root on that machine, so add only users you would trust with root. - Disk space for the images evertap downloads: about 400 MB for each PostgreSQL version and 800 to 900 MB for each MySQL version you use.
On your laptop and in CI: Linux or macOS on x64 or arm64. On Windows, use the CLI inside WSL.
How Docker was installed
evertap finds Docker's socket in this order: EVERTAP_DOCKER_SOCKET, a unix:// DOCKER_HOST,
then the usual places of Docker Engine, Docker Desktop, OrbStack, Colima, and rootless Docker. Some
installs need more:
- Docker from Snap cannot read files in hidden folders of your home, which includes evertap's
data directory
~/.local/share/evertap, so databases fail to start. Install Docker from docker.com's packages instead, or setEVERTAP_DATA_DIRto a folder that is not hidden, such as~/evertap, wherever you runevertap(see Configuration). - Rootless Docker stops when you log out, and the databases with it. Run
sudo loginctl enable-linger $USERandsystemctl --user enable dockerso it keeps running. The systemd unit below has noXDG_RUNTIME_DIR, so setEVERTAP_DOCKER_SOCKET=/run/user/<your uid>/docker.sockin its environment file.
The Doctor warns about both.
Ports
| Where | What listens | Address |
|---|---|---|
| The machine running evertap | The UI and API | Port 8080 (EVERTAP_PORT) on the address you choose in setup |
Databases and buckets, network mode | 127.0.0.1, ports 6432, 3306, 6379, 9000, 3900 (EVERTAP_*_PORT) | |
Databases and buckets, cloudflare | The same as network | |
Databases, buckets, and UI, local | 127.77.0.1, ports 5432, 3306, 6379, 9000, 3900, and 8080 | |
| Buckets reached from anywhere | Port 9900 (EVERTAP_PUBLIC_S3_PORT) beside the UI, once given an address | |
| Each database and bucket service | 127.0.0.1, on a port Docker picks | |
| The CLI on the same machine | evertap.sock in the data directory, readable by your user alone | |
| Your laptop | evertap connect | 127.77.0.1, ports 5432, 3306, 6379, 9000, 3900 |
Until you run evertap setup, the UI listens on 127.0.0.1 too, so nothing is reachable from other
machines. Databases and buckets never listen anywhere but loopback: other machines reach them
through the UI's address with evertap connect. The one exception is the entry for buckets reached
from anywhere, which listens beside the UI (Security).
Install the binary
To run evertap itself in a container instead, see Run evertap in Docker.
curl -fsSL https://github.com/caru-ini/evertap/releases/latest/download/install.sh | shThe script downloads the build for your system from the latest release, checks it against the
release's SHA256SUMS, and installs it as /usr/local/bin/evertap, asking for sudo if it needs
it. Give it settings on the sh side of the pipe:
EVERTAP_VERSION=0.1.0installs that release instead of the latest.EVERTAP_INSTALL_DIR=$HOME/.local/bininstalls somewhere else.
curl -fsSL https://github.com/caru-ini/evertap/releases/latest/download/install.sh | EVERTAP_VERSION=0.1.0 shOn a first install, the script ends with what to run next: on the machine that runs evertap, start it (Keep evertap running), then set it up; on a laptop, pair it.
By hand
From the releases page, download
evertap-<os>-<arch>.tar.gz for your system and SHA256SUMS, then:
grep evertap-linux-x64.tar.gz SHA256SUMS | sha256sum -c # on macOS: shasum -a 256 -c
tar -xzf evertap-linux-x64.tar.gz
sudo install -m 755 evertap-linux-x64/evertap /usr/local/bin/evertapThe archive also holds the license and the third-party notices. With the GitHub CLI, you can check that GitHub's release workflow built the archive:
gh attestation verify evertap-linux-x64.tar.gz --repo caru-ini/evertapOn macOS, a file downloaded with a browser is quarantined, and macOS refuses to run it. Remove the
quarantine with xattr -d com.apple.quarantine evertap.
Keep evertap running
Every connection to a database or bucket goes through the evertap serve process. While it is
stopped, the databases keep running in Docker but nothing reaches them.
With systemd
The repository has an example unit,
contrib/systemd/evertap@.service,
that runs evertap serve at boot as the user named after the @. Run it as yourself: evertap keeps
its data in that user's ~/.local/share/evertap, where evertap setup and the other commands you
run find it.
curl -fsSLO https://raw.githubusercontent.com/caru-ini/evertap/main/contrib/systemd/evertap@.service
sudo cp evertap@.service /etc/systemd/system/
sudo systemctl daemon-reload
sudo systemctl enable --now evertap@$USER- The unit runs
/usr/local/bin/evertap. If you installed it elsewhere, changeExecStart. - Environment variables for the service go in
/etc/evertap/evertap.env. Start from the examplecontrib/systemd/evertap.env, and set only what you need: a variable fixes its setting, and setup can no longer change it (Configuration). - If you set
EVERTAP_DATA_DIRthere, set it in your shell too, orevertap setupand the other commands on that machine cannot find the running evertap. - Read its log with
journalctl -u evertap@$USER -f. On start, it says where it listens and what to do next.
Without systemd
Run evertap serve in a terminal, or in tmux so it outlives your session. On macOS there is no
example launchd job; run it in a terminal.
Set up and sign in
On the machine running evertap, as the user that runs it, while it runs:
evertap setupSetup asks how other machines reach evertap (see Choose how evertap is reached), asks only what that choice needs, and applies it without a restart. Then it signs in your first browser:
- In
networkandcloudflaremode, it prints a one-time sign-in link and a QR code. Open the link in a browser, or scan the code with your phone. It signs in one browser and expires in 10 minutes. - In
localmode, it opens a signed-in browser on this machine.
Without a terminal, give the answers as flags, and setup asks nothing:
evertap setup --mode local
evertap setup --mode network --listen 0.0.0.0
evertap setup --mode network --url https://evertap.example.com
CLOUDFLARE_API_TOKEN=<token> evertap setup --mode cloudflare --zone example.com
evertap setup --mode cloudflare --url https://evertap.example.comRun evertap setup again to change your answers; it offers to keep the address you gave before.
Once you are signed in, Settings in the UI can make the same changes, as long as they keep your
browser connected.
Signing in later
- A new browser shows a code. On a device that is signed in, open
/device(Clients → Add a device) and enter it. evertap signin-link, on the machine running evertap, prints another one-time link and QR code. Use it when no browser is signed in anymore.evertap open, on the machine running evertap, opens a signed-in browser there.
Check it
evertap doctorThe Doctor, also a page in the UI, shows the Docker version and any warnings about it, the state of each service, whether each database and bucket entry answers, and which of your own Docker containers want the same ports.
Next, choose how evertap is reached if you have not, then connect from your laptop. Upgrading and uninstalling are in Limitations.
The evertap name and logo are not licensed with the code (section 6 of the license). You may use them to refer to evertap, but not to name or brand your own product or service, or in a way that suggests evertap made or endorses it, without permission.
evertap is an independent project. It is not affiliated with, endorsed, sponsored, supported, or certified by the owners of the software it runs, and it uses their names only to say which software that is.
- Postgres, PostgreSQL and the Slonik Logo are trademarks or registered trademarks of the PostgreSQL Community Association of Canada, and used with their permission.
- MySQL is a registered trademark of Oracle and/or its affiliates.
- Redis is a registered trademark of Redis Ltd. Any rights therein are reserved to Redis Ltd.
- RustFS is a trademark of RustFS, Inc.
- Other names, including Garage, may be trademarks of their respective owners.