# Deploy on Docker

Learn how to deploy a TrapEye instance using **Docker**. This guide covers deployment using the standard Docker CLI as well as Docker Compose.

The Docker image allows for rapid deployment on any Linux host, but requires specific network configurations to enable full detection capabilities.

---

## Deployment Steps

1.  **Retrieve Configuration**

   Navigate to **Management → Installation** in the **TrapEye Platform**. Select the **Docker** tab to view your specific installation command. This command is pre-populated with the necessary authentication tokens and UUIDs for your entity.

2.  **Run with Docker CLI**

   Execute the command retrieved from the platform in your terminal. Below is an example of the command structure:

    ```bash
    docker run -d \
       --restart unless-stopped \
       --network host \
       -e INGESTION_URL="INGESTION-URL" \
       -e ENTITY_UUID="YOUR-ENTITY-UUID" \
       -e ENTITY_TOKEN="YOUR-ENTITY-TOKEN" \
       -e TRAPEYE_UUID="YOUR-TRAPEYE-UUID" \
       ghcr.io/anantis-security/trapeye:x.x.x
    ```

    :::caution[Network Mode Requirement]
    We strongly recommend using `--network host`. 
    
    If you choose not to use the host network driver and instead rely on standard port mapping (e.g., `-p 80:80`), the instance will not be attached directly to the physical network interface. Consequently, **Network Scan Detection** which relies on Layer 2 packet analysis **will not function**.
    
    All other application-layer deception services will continue to work normally with standard port mapping.
    :::

    :::caution[OS Deception]
    By default, the container does not perform OS deception (no TCP/IP fingerprint emulation is applied).

    To enable it, add the following options to the command:

    ```bash
    docker run -d \
       --cap-add=NET_ADMIN \
       --user root \
       ...
    ```

    `NET_ADMIN` grants the container the right to modify the network stack, and running as `root` is required to apply those changes.
    :::

3.  **Alternative: Docker Compose**

   If you prefer to manage your deployment via **Docker Compose**, you can use the configuration below. Create a `docker-compose.yml` file and paste the following content, replacing the environment variables with the values from **Step 1**.

    ```yaml
    services:
      trapeye:
        image: ghcr.io/anantis-security/trapeye:x.x.x
        container_name: trapeye-sensor
        network_mode: host
        restart: unless-stopped
        # Uncomment both lines to enable OS deception
        # cap_add:
        #   - NET_ADMIN
        # user: root
        environment:
          - INGESTION_URL=INGESTION-URL
          - ENTITY_UUID=YOUR-ENTITY-UUID
          - ENTITY_TOKEN=YOUR-ENTITY-TOKEN
          - TRAPEYE_UUID=YOUR-TRAPEYE-UUID
    ```

    Run the container using:
    
    ```bash
    docker-compose up -d
    ```

:::caution[Keep `TRAPEYE_UUID` fixed]
`TRAPEYE_UUID` identifies the decoy. Reuse the same value whenever you recreate the
container for that decoy: after an upgrade or a restart.

A new UUID is registered as a **new device** and consumes an additional license. The
variable is also mandatory: without it the container exits at startup.
:::

## Important Limitations

When deploying via Docker, please be aware of the following limitation regarding service availability:

:::note
The **SSH Sandbox** feature is currently **not available** when using the Docker image deployment method. This feature requires a full virtual machine environment to function securely.
:::

## Setup complete

Your TrapEye container is now running. It will appear in the **Devices** section of the TrapEye Deception Platform, and you will begin receiving real-time alerts as soon as activity is detected.