Skip to content

PoC Installation Requirements

1. Introduction

  • This document describes the requirements for the Proof of Concept (PoC) installation of Data Focus, developed by Kafein Technology Solutions.
  • Meeting the requirements listed below is essential for ensuring smooth and efficient operation of Data Focus.

2. System Requirements

Environment Server Type OS CPU RAM Disk
POC Application + Middleware Linux based (e.g. Ubuntu, RHEL) 16 64GB 500GB

The server must be dedicated to Data Focus

Scan workers monitor system-wide memory usage. If total memory usage on the server stays above 85%, a worker shuts itself down and the scan stops progressing — even if the cause is unrelated software such as a monitoring agent, a backup job or a log collector. Do not place other workloads on this server.

About the disk figure

500 GB covers the installation and a PoC-sized scan. Disk usage grows with the number of findings produced, not with the size of the data that was scanned — scanned files are not copied to the server. For scans beyond the PoC scope, see Disk Sizing.


3. Network Requirements

The following ports must be open during installation and operation:

Port Purpose Required For
22 SSH access Linux-based systems (e.g. Ubuntu)
80 HTTP (initial setup / redirect) All systems
443 HTTPS (secure communication) All systems

Note

  • Port 22 is required only for remote SSH access to the server.
  • All HTTP (80) traffic is automatically redirected to HTTPS (443) after installation.

Access to Data Sources (Optional)

The ports above cover access to Data Focus. Scanning also needs access from the Data Focus server to the systems that hold the data.

Only the sources you plan to scan are relevant. If a source is not part of the PoC, its row can be ignored.

Source to be scanned Port Note
File share over SMB 445 Required only if the server to be scanned shares its data over SMB (Samba)
File share over SFTP 22 Required only if the data is reached over SFTP
Cloud and SaaS sources (SharePoint, OneDrive, Google Drive, Box, Dropbox, S3, Azure Blob, GCS) 443 Outbound HTTPS to the provider endpoints
Databases (structured scanning) Varies The listening port of each database, for example 1433, 1521, 3306, 5432

Name resolution is required for cloud and SaaS sources

Opening outbound 443 is not sufficient on its own. The server must also be able to resolve the provider's endpoints through DNS, and those endpoints must not be blocked by an outbound proxy or a URL filter. In a closed corporate network this is the most common reason a scan fails on the first day.

Each provider is reached over more than one endpoint — typically a sign-in endpoint and an API endpoint. Confirm with the customer's network team that the endpoints of the providers in scope are both resolvable and reachable from the server before the PoC starts.

Read access is also needed

Alongside the network route, each source needs an account that can read the data to be scanned:

  • File shares (SMB, SFTP): a service account with read permission on the paths in scope.
  • Cloud and SaaS sources: usually an application registration whose read permission is granted at application level rather than on behalf of a signed-in user, and approved by the customer's own administrator.

Administrator approval is a separate request process in most organizations and can take days. Preparing these accounts before the PoC starts avoids delays on the first day.


4. Internal Requirements

  • There should be no network restrictions within the server so that applications can communicate with each other.

5. External Requirements

  • Since software such as Docker and OpenSSL must be installed during setup, the provided servers must have access to the external network.
  • Additionally, the installation user must have access to the system package manager (e.g., apt, yum, dnf) to install these dependencies.

Package Manager Access

Ensure that the repository configurations are valid and the package manager is not blocked by any internal policies.

  • If internet access is not available, the required software packages will be provided and must be manually placed on the servers.

6. Operating System Requirements

Data Focus is installed on a Linux server running Docker and Docker Compose.

Tested and Supported Platforms:

  • Ubuntu 20.04
  • Ubuntu 22.04
  • Ubuntu 24.04
  • Red Hat Enterprise Linux (RHEL) 8 and above

Windows is not supported

Windows is not supported as an installation platform. Data Focus must be installed on one of the Linux distributions listed above.

Installing Docker

Supported versions and the installation steps are covered in Docker Installation.

Server Preparation

A few host-level settings are expected before installation and are not applied by the installation scripts:

Setting Requirement
Dedicated server No other workload on the server — see the note under System Requirements
Time synchronization An NTP client installed, enabled and synchronized (timedatectl status)
Shared memory At least 2 GB for the database container; already set in the provided Compose file

Full details are in Operating System Prerequisites.


7. DNS Requirements (Optional)

DNS usage is recommended for a clearer and more manageable installation.

Example DNS configuration:

datafocus-poc.kafein.com


8. SSL / HTTPS Requirements

Starting from the current version, HTTPS is mandatory for all Data Focus installations to ensure secure communication between services.

Certificate Options

  • If no certificate is provided, the installation process will automatically generate a self-signed SSL certificate for the specified domain or hostname.
  • For production environments, CA-signed certificates are strongly recommended to avoid browser trust warnings.

Info

The installation script automatically configures HTTPS redirection and updates the NGINX or reverse-proxy settings to enforce secure access.