# Deploy on Proxmox

This guide will help you deploy TrapEye on your Proxmox environment smoothly, from preparing your VM template to launching your first instance.

---

## Import the TrapEye Proxmox Image

1. Log in to the [TrapEye Portal](https://trapeye.anantis.io), go to **Management → Installation** and download the latest TrapEye Proxmox image (`.qcow2` format).

   ![Download image](~/assets/images/docs/installation/download.webp)

2. Open a Terminal on your Laptop and push the downloaded `.qcow2` image to your Proxmox server via ssh using `scp`:

   ```shell
    scp trapeye-image.qcow2 root@<proxmox-ip>:/var/lib/vz/images/
    ```

## Create a New Proxmox Template

1. Open the **Proxmox Shell** via the web interface or SSH.

   ![Open Shell](~/assets/images/docs/installation/proxmox/shell.webp)

2. Verify the presence of the uploaded image:

   ```shell
    file /var/lib/vz/images/trapeye-image.qcow2
    ```  

    :::tip

    _This command should return the file metadata (QCOW2 format confirmation)._

    :::

3. Create a new VM with the appropriate value in `memory`, `cores` and `bridge`.

   | Resource | Minimum Value | Recommended Value |
    |-----------|-------------------| -------------------|
    | **CPU**   | 1 vCPUs           | 1 vCPUs           |
    | **Memory**| 1024 MiB (1 GB)   | 2048 MiB (2 GB)   |

    ```shell
    qm create 9000 --name trapeye-template --memory <choose memory value in MB> --cores <choose cores number> --net0 virtio,bridge=<your bridge network>
    ```

4. Import the image into your VM:

   ```shell
    qm importdisk 9000 /var/lib/vz/images/trapeye-image.qcow2 local-lvm
    ```

5. Open the **Hardware** tab of your Template, select the **Unused Disk**, and double-click to edit.

   ![Change Disk Settings](~/assets/images/docs/installation/proxmox/edit-disk1.webp)

6. Set **Bus/Device** to `VirtIO Block` and click **Add**.

   ![Select VirtIO block](~/assets/images/docs/installation/proxmox/edit-disk2.webp)

    Once added, the new disk should appear attached as a **VirtIO** device.

7. Adjust the **Boot Order** so that the VM boots from the newly added disk:

   - Go to the **Options** tab of your VM.  
    - Double-click on **Boot Order**.  
    - Enable the `VirtIO` disk and move it to the top of the list.  
    - Click **OK** to confirm.

    ![Change Boot Order](~/assets/images/docs/installation/proxmox/boot-order.webp)

8. Convert your VM into a template

   ```shell
    qm template 9000
    ```

## TrapEye Configuration

_The easiest way to configure TrapEye for mass deployment and to avoid manual configuration of each VM is to use a Cloud Init config in the Proxmox Template._

### Option 1: Cloud Init Configuration

1. Create the cloud init disk in your Proxmox template.

   ```shell
    qm set 9000 --ide2 local-lvm:cloudinit
    ```

2. Change the password for root user.

   ```shell
    qm set 9000 --ciuser root --cipassword CHANGEME
    ```

3. From the TrapEye Platform, go to **Management → Installation** and copy the values for `url`, `entity_uuid`, and `auth_token`.

   ![Config Menu](~/assets/images/docs/installation/config.webp)

4. Create snippets folder if it doesn't exist and create the configuration file with your specific data.

   ```shell
    mkdir -p /var/lib/vz/snippets/

    cat > /var/lib/vz/snippets/trapeye-vendor.yaml <<EOF
    #cloud-config
    write_files:
      - path: /etc/trapeye/auth-config.toml
        permissions: '0600'
        content: |
          entity_uuid = "ENTITY-URL-HERE"
          auth_token = "ENTITY-TOKEN-HERE"
          url = "INGESTION-URL-HERE"
    EOF
    ```

5. Apply that config file into your cloud-init disk:
   
   ```shell
    qm set 9000 --cicustom "vendor=local:snippets/trapeye-vendor.yaml"
    ```

6. Clone your template into a Proxmox VM and start it.

   ```shell
    qm clone 9000 100 --name trapeye-prod-01
    qm start 100
    ```

    :::tip

    You can mass deploy easily by cloning the template.

    :::

### Option 2: Manual Configuration via HTTPS

By default, if Cloud Init does not push the `/etc/trapeye/auth-config.toml` file, TrapEye service boot in Manual Config Mode and allow you to connect to it via its IP Address (DHCP by default).

1. Clone your template into a Proxmox VM and start it.

   ```shell
    qm clone 9000 100 --name trapeye-prod-01
    qm start 100
    ```

2. Get the IP Address of your VM

3. From the TrapEye Platform, go to **Management → Installation** and copy the values for `url`, `entity_uuid`, and `auth_token`.

   ![Config Menu](~/assets/images/docs/installation/config.webp)

4. Connect to the TrapEye Manual Config Web Page by navigating to `https://<your_vm_ip>:8443`

5. Ignore the TLS warning as this is a temporary self-signed certificate and fill the form with your 3 custom value copied earlier:

   ![Config Page](~/assets/images/docs/installation/config_web.webp)

## Setup complete

Your TrapEye virtual machine has been successfully deployed on Proxmox. 

It will now appear in the **Devices** section of the TrapEye Deception Platform, and you will begin receiving real-time alerts as soon as any activity is detected.