Install on Linux
One command installs Nifty as a service and asks how you'll reach it.
On this page
On a Linux machine with systemd (x86_64 or arm64), run:
curl -fsSL https://releases.niftyware.io/beta/install.sh | sudo sh
It asks how you'll reach Nifty, shows its plan and asks Continue? before changing anything. When Nifty is up, it
prints a one-time setup link: open it and choose your name, username and password. Nifty then offers a 14-day free
trial or a place to paste your licence key (Your licence).
What the machine needs: Requirements.
Choose how you'll reach Nifty
| Answer | Flag | More |
|---|---|---|
| Over Tailscale | --tailscale |
Tailscale |
| At a domain, with a free Let's Encrypt certificate | --letsencrypt DOMAIN |
HTTPS |
| … when the internet can't reach this machine | --letsencrypt DOMAIN --dns cloudflare |
HTTPS |
| At a domain, with a certificate I already have | --tls-cert FILE --tls-key FILE --origin URL |
HTTPS |
| Through my own proxy | --origin URL |
Behind a proxy |
| Only from this machine | --local |
http://127.0.0.1:4000 |
Tailscale is offered first when it's up on the machine.
Install without questions
Pass the answer as flags, plus --yes to skip Continue?. With no terminal (a provisioning script), flags are
required:
curl -fsSL https://releases.niftyware.io/beta/install.sh | sudo sh -s -- --letsencrypt notes.example.com --yes
| Flag | Does |
|---|---|
--no-tailscale-operator |
With --tailscale: run tailscale serve once instead of letting Nifty manage it (why) |
--letsencrypt-staging |
With --letsencrypt: use Let's Encrypt's staging server, for trials (browsers won't trust it) |
--listen HOST:PORT |
With your own proxy: where Nifty listens (default 127.0.0.1:4000) |
--trusted-proxies LIST |
With your own proxy: proxies whose X-Forwarded-For to believe (default 127.0.0.1) |
--yes |
Don't ask Continue? |
curl -fsSL https://releases.niftyware.io/beta/install.sh | sh -s -- --help lists them all. For Cloudflare, pass the API token in CLOUDFLARE_API_TOKEN, never as a flag:
curl … | sudo --preserve-env=CLOUDFLARE_API_TOKEN sh -s -- …. Without it, the script asks for it, unseen.
What it installs
| Path | What |
|---|---|
/usr/local/bin/nifty |
The program |
/var/lib/nifty |
Your data: back it up |
/etc/nifty.env |
Settings (root:nifty, mode 640) |
nifty.service |
The service, run as the nifty user |
/etc/systemd/system/nifty.service.d/ports.conf |
Only when Nifty serves HTTPS itself: lets it use ports 443 and 80 |
It checks the download against SHA256SUMS, and that file's signature too if minisign is installed.
Change a setting
Edit /etc/nifty.env, then restart:
sudo systemctl restart nifty
Every setting is in Configuration. Running install.sh again keeps the program, settings and
data, and ignores any flags you pass.
The beta channel
Install from https://releases.niftyware.io/beta/install.sh to get betas. The server stays on beta until you
change it: see Updates and channels.
Check on it
systemctl status nifty
journalctl -u nifty -f
The setup link is in the log too. Whoever opens it first owns this Nifty, so set up straight away. A restart before setup logs a new link.
If it doesn't start
Waiting for systemd to report the network online: systemd waits fornetwork-online.targetbefore starting Nifty, which takes minutes on some machines. Nifty starts once it's done.- Let's Encrypt fails: the script stops with the reason and when Nifty tries again. See HTTPS.
- Anything else:
journalctl -u nifty -n 50says why. Fix/etc/nifty.env, thensudo systemctl restart nifty.