PoC Installation Requirements¶
1. Introduction¶
- This document describes the requirements for the Proof of Concept (PoC) installation of Data Focus, developed by Kafein Technology Solutions.
- Meeting the requirements listed below is essential for ensuring smooth and efficient operation of Data Focus.
2. System Requirements¶
| Environment | Server Type | OS | CPU | RAM | Disk |
|---|---|---|---|---|---|
| POC | Application + Middleware | Linux based (e.g. Ubuntu, RHEL) | 16 | 64GB | 500GB |
The server must be dedicated to Data Focus
Scan workers monitor system-wide memory usage. If total memory usage on the server stays above 85%, a worker shuts itself down and the scan stops progressing — even if the cause is unrelated software such as a monitoring agent, a backup job or a log collector. Do not place other workloads on this server.
About the disk figure
500 GB covers the installation and a PoC-sized scan. Disk usage grows with the number of findings produced, not with the size of the data that was scanned — scanned files are not copied to the server. For scans beyond the PoC scope, see Disk Sizing.
3. Network Requirements¶
The following ports must be open during installation and operation:
| Port | Purpose | Required For |
|---|---|---|
| 22 | SSH access | Linux-based systems (e.g. Ubuntu) |
| 80 | HTTP (initial setup / redirect) | All systems |
| 443 | HTTPS (secure communication) | All systems |
Note
- Port 22 is required only for remote SSH access to the server.
- All HTTP (80) traffic is automatically redirected to HTTPS (443) after installation.
Access to Data Sources (Optional)¶
The ports above cover access to Data Focus. Scanning also needs access from the Data Focus server to the systems that hold the data.
Only the sources you plan to scan are relevant. If a source is not part of the PoC, its row can be ignored.
| Source to be scanned | Port | Note |
|---|---|---|
| File share over SMB | 445 | Required only if the server to be scanned shares its data over SMB (Samba) |
| File share over SFTP | 22 | Required only if the data is reached over SFTP |
| Cloud and SaaS sources (SharePoint, OneDrive, Google Drive, Box, Dropbox, S3, Azure Blob, GCS) | 443 | Outbound HTTPS to the provider endpoints |
| Databases (structured scanning) | Varies | The listening port of each database, for example 1433, 1521, 3306, 5432 |
Name resolution is required for cloud and SaaS sources
Opening outbound 443 is not sufficient on its own. The server must also be able to resolve the provider's endpoints through DNS, and those endpoints must not be blocked by an outbound proxy or a URL filter. In a closed corporate network this is the most common reason a scan fails on the first day.
Each provider is reached over more than one endpoint — typically a sign-in endpoint and an API endpoint. Confirm with the customer's network team that the endpoints of the providers in scope are both resolvable and reachable from the server before the PoC starts.
Read access is also needed
Alongside the network route, each source needs an account that can read the data to be scanned:
- File shares (SMB, SFTP): a service account with read permission on the paths in scope.
- Cloud and SaaS sources: usually an application registration whose read permission is granted at application level rather than on behalf of a signed-in user, and approved by the customer's own administrator.
Administrator approval is a separate request process in most organizations and can take days. Preparing these accounts before the PoC starts avoids delays on the first day.
4. Internal Requirements¶
- There should be no network restrictions within the server so that applications can communicate with each other.
5. External Requirements¶
- Since software such as Docker and OpenSSL must be installed during setup, the provided servers must have access to the external network.
- Additionally, the installation user must have access to the system package manager (e.g.,
apt,yum,dnf) to install these dependencies.
Package Manager Access
Ensure that the repository configurations are valid and the package manager is not blocked by any internal policies.
- If internet access is not available, the required software packages will be provided and must be manually placed on the servers.
6. Operating System Requirements¶
Data Focus is installed on a Linux server running Docker and Docker Compose.
Tested and Supported Platforms:
- Ubuntu 20.04
- Ubuntu 22.04
- Ubuntu 24.04
- Red Hat Enterprise Linux (RHEL) 8 and above
Windows is not supported
Windows is not supported as an installation platform. Data Focus must be installed on one of the Linux distributions listed above.
Installing Docker
Supported versions and the installation steps are covered in Docker Installation.
Server Preparation¶
A few host-level settings are expected before installation and are not applied by the installation scripts:
| Setting | Requirement |
|---|---|
| Dedicated server | No other workload on the server — see the note under System Requirements |
| Time synchronization | An NTP client installed, enabled and synchronized (timedatectl status) |
| Shared memory | At least 2 GB for the database container; already set in the provided Compose file |
Full details are in Operating System Prerequisites.
7. DNS Requirements (Optional)¶
DNS usage is recommended for a clearer and more manageable installation.
Example DNS configuration:
datafocus-poc.kafein.com
8. SSL / HTTPS Requirements¶
Starting from the current version, HTTPS is mandatory for all Data Focus installations to ensure secure communication between services.
Certificate Options¶
- If no certificate is provided, the installation process will automatically generate a self-signed SSL certificate for the specified domain or hostname.
- For production environments, CA-signed certificates are strongly recommended to avoid browser trust warnings.
Info
The installation script automatically configures HTTPS redirection and updates the NGINX or reverse-proxy settings to enforce secure access.