# Recommended way of installing DataSHIELD

**URL:** <https://datashield.discourse.group/t/recommended-way-of-installing-datashield/602>\
**Category:** Beginner Support\
**Created:** [16 August 2022 14:52 UTC](https://datashield.discourse.group/t/recommended-way-of-installing-datashield/602 "2022-08-16T14:52:10Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![wilmar.igl](https://avatars.discourse-cdn.com/v4/letter/w/7993a0/32.png) [@wilmar.igl](https://datashield.discourse.group/u/wilmar.igl)\
**Post date:** [16 August 2022 14:52 UTC](https://datashield.discourse.group/t/recommended-way-of-installing-datashield/602/1 "2022-08-16T14:52:10Z")

</div>

Dear all,

I came across various ways of installing DataSHIELD and wonder what the recommend is for newcomers:

1. Barebone: installing each component separately helping to understand how all components work together
2. Separate Docker images
3. The complete CORAL docker swarm
4. Other …?

Any advice?

Wilmar

---

<div class="post-metadata">

**Author:** ![swheater](https://yyz2.discourse-cdn.com/free1/user_avatar/datashield.discourse.group/swheater/32/182_2.png) [@swheater](https://datashield.discourse.group/u/swheater)\
**Post date:** [16 August 2022 15:38 UTC](https://datashield.discourse.group/t/recommended-way-of-installing-datashield/602/2 "2022-08-16T15:38:15Z")

</div>

Hi Wilmar,

Personally I have been transitioning from “Barebones” (automated by puppet) to docker compose based deployments (both Opal and Armadillo), also I am also experimenting with a CORAL deployment. Given I am mostly interesting in quality assurance I feel I need to cover both “Barebones” and “Docker” based deployments.

If a full deployment of all the Obiba (Opal, Mica, Agate, +) tools is your aim, then CORAL appears to be a good choice [my investigation is stalled due to a deployment issue].

Also it would be worth checking it Docker based deployment is supported by your IT department. We had to persuade our IT department to make some changes to their infrastructure to cope with Docker.

Stuart

---

<div class="post-metadata">

**Author:** ![tombishop](https://yyz2.discourse-cdn.com/free1/user_avatar/datashield.discourse.group/tombishop/32/23_2.png) [@tombishop](https://datashield.discourse.group/u/tombishop)\
**Post date:** [16 August 2022 21:01 UTC](https://datashield.discourse.group/t/recommended-way-of-installing-datashield/602/3 "2022-08-16T21:01:27Z")

</div>

Also there is [Armadillo](https://github.com/molgenis/molgenis-service-armadillo), but the documentation is under development.

For just getting to understand how DataSHIELD works I would recommend the Docker approach described here:

[https://opaldoc.obiba.org/en/latest/admin/installation.html#docker-image-installation](https://opaldoc.obiba.org/en/latest/admin/installation.html#docker-image-installation)

---

<div class="post-metadata">

**Author:** ![yannick](https://yyz2.discourse-cdn.com/free1/user_avatar/datashield.discourse.group/yannick/32/19_2.png) [@yannick](https://datashield.discourse.group/u/yannick)\
**Post date:** [17 August 2022 09:06 UTC](https://datashield.discourse.group/t/recommended-way-of-installing-datashield/602/4 "2022-08-17T09:06:29Z")

</div>

Agreed with Stuart, Coral is nice for a full stack deployment, including studies and dataset documentation. A simple docker approach is enough for Datashield and is straightforward (that is how [opal-demo](https://opal-demo.obiba.org/) has been deployed daily, for years).

---

<div class="post-metadata">

**Author:** ![wilmar.igl](https://avatars.discourse-cdn.com/v4/letter/w/7993a0/32.png) [@wilmar.igl](https://datashield.discourse.group/u/wilmar.igl)\
**Post date:** [17 August 2022 22:03 UTC](https://datashield.discourse.group/t/recommended-way-of-installing-datashield/602/5 "2022-08-17T22:03:01Z")

</div>

Hi, I installed DataShield on [srv3.stats-con.com](http://srv3.stats-con.com) and followed the instructions for the docker image installation [1] until: docker-compose -f docker-compose.yml up -d

What next?

1. How can I login to OPAL/Webamin, start Rock, set Rock URL?
2. Add ROCK on [srv3.stats-con.com](http://srv3.stats-con.com) to default R Cluster on [srv1.stats-con.com](http://srv1.stats-con.com)?

Thanks, Wilmar

[1] [Installation — Opal documentation](https://opaldoc.obiba.org/en/latest/admin/installation.html#docker-image-installation)

---

<div class="post-metadata">

**Author:** ![yannick](https://yyz2.discourse-cdn.com/free1/user_avatar/datashield.discourse.group/yannick/32/19_2.png) [@yannick](https://datashield.discourse.group/u/yannick)\
**Post date:** [18 August 2022 11:15 UTC](https://datashield.discourse.group/t/recommended-way-of-installing-datashield/602/6 "2022-08-18T11:15:06Z")

</div>

The `docker-compose up` command starts all the declared services (i.e. opal, rock and database(s)). You do not need to start Rock specifically, you do not need to access Rock (because opal does it in the docker’s internal network). Again, you should not link a R server to several opal servers. There is no benefit to this and it can be confusing in terms of resource management.

---

<div class="post-metadata">

**Author:** ![wilmar.igl](https://avatars.discourse-cdn.com/v4/letter/w/7993a0/32.png) [@wilmar.igl](https://datashield.discourse.group/u/wilmar.igl)\
**Post date:** [19 August 2022 08:37 UTC](https://datashield.discourse.group/t/recommended-way-of-installing-datashield/602/8 "2022-08-19T08:37:03Z")

</div>

Dear Yannick,

got it, if OPAL and ROCK are installed on the same server, ROCK is automatically registered and this ROCK installation should NOT be registered with other OPAL servers to avoid inconsistencies.

On [srv3.stats-con.com](http://srv3.stats-con.com), after opening the ports 8843 and 8880 I can now login using OPAL on [https://srv3.stats-con.com:8843](https://srv3.stats-con.com:8843).

Login via [srv3.stats-con.com:8880](http://srv3.stats-con.com:8880) shows “Authentication failed” when entering default credentials (as in docker yml) presumably because of a block of “Cross Site Request Forgery (CSRF)”

Thanks for your support,

Wilmar

---

<div class="post-metadata">

**Author:** ![wilmar.igl](https://avatars.discourse-cdn.com/v4/letter/w/7993a0/32.png) [@wilmar.igl](https://datashield.discourse.group/u/wilmar.igl)\
**Post date:** [19 August 2022 10:58 UTC](https://datashield.discourse.group/t/recommended-way-of-installing-datashield/602/9 "2022-08-19T10:58:42Z")

</div>

Hi,

I am trying to login to the opal server with:

# Method 1:

con.opal \<-·opal.login(username·=·“administrator”,·password·=·“password”, url·=·“[https://srv2.stats-con.com](https://srv2.stats-con.com)”)

> R console Error: Error in curl::curl\_fetch\_memory(url, handle = handle) :  
> Failed to connect to [srv2.stats-con.com](http://srv2.stats-con.com) port 443: Connection refused

# Method 2:

con.opal·\<-·opal.login(username·=·“administrator”,·password·=·“password”, url·=·“[https://srv2.stats-con.com:8843](https://srv2.stats-con.com:8843)”)

> R console Error: curl::curl\_fetch\_memory(url, handle = handle) :  
> SSL certificate problem: self signed certificate

How do I login to an OPAL server running in Docker from an R analysis server (here on the same server, but not in Docker)?

Best, Wilmar

---

<div class="post-metadata">

**Author:** ![yannick](https://yyz2.discourse-cdn.com/free1/user_avatar/datashield.discourse.group/yannick/32/19_2.png) [@yannick](https://datashield.discourse.group/u/yannick)\
**Post date:** [19 August 2022 13:00 UTC](https://datashield.discourse.group/t/recommended-way-of-installing-datashield/602/10 "2022-08-19T13:00:56Z")

</div>

See recommended [reverse proxy configuration](https://opaldoc.obiba.org/en/latest/admin/configuration.html#reverse-proxy-configuration) (example is apache but it could also be nginx). If your institution does not provide a certificate, you can get one from [Let’s encrypt](https://letsencrypt.org/).

Yannick

---

<div class="post-metadata">

**Author:** ![wilmar.igl](https://avatars.discourse-cdn.com/v4/letter/w/7993a0/32.png) [@wilmar.igl](https://datashield.discourse.group/u/wilmar.igl)\
**Post date:** [19 August 2022 21:01 UTC](https://datashield.discourse.group/t/recommended-way-of-installing-datashield/602/11 "2022-08-19T21:01:04Z")

</div>

Hi,

I have installed and configured an nginx server with certbot to be able to use https now. I manually added the reverse proxy: location / {  
proxy\_pass [http://127.0.0.1:8843/](http://127.0.0.1:8843/);  
}

# Error in R

However, R gives me this error: con.opal ← opal.login(username = “administrator”, password = “password”, url = “[https://srv2.stats-con.com](https://srv2.stats-con.com)”)

> Error in curl::curl\_fetch\_memory(url, handle = handle) :  
> **\> Received HTTP/0.9 when not allowed**

## Error with curl

However, curl gives me the same strange “Received HTTP/0.9 when not allowed” error.

root@fedsrv2:/var/www/html# curl --verbose -I [https://srv2.stats-con.com](https://srv2.stats-con.com)

- Trying 116.203.185.16:443…
- Connected to [srv2.stats-con.com](http://srv2.stats-con.com) (116.203.185.16) port 443 (#0)
- ALPN, offering h2
- ALPN, offering http/1.1
- successfully set certificate verify locations:
- CAfile: /etc/ssl/certs/ca-certificates.crt
- CApath: /etc/ssl/certs
- TLSv1.3 (OUT), TLS handshake, Client hello (1):
- TLSv1.3 (IN), TLS handshake, Server hello (2):
- TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
- TLSv1.3 (IN), TLS handshake, Certificate (11):
- TLSv1.3 (IN), TLS handshake, CERT verify (15):
- TLSv1.3 (IN), TLS handshake, Finished (20):
- TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
- TLSv1.3 (OUT), TLS handshake, Finished (20):
- SSL connection using TLSv1.3 / TLS\_AES\_256\_GCM\_SHA384
- ALPN, server accepted to use http/1.1
- Server certificate:
- subject: [CN=srv2.stats-con.com](http://CN=srv2.stats-con.com)
- start date: Aug 19 13:44:54 2022 GMT
- expire date: Nov 17 13:44:53 2022 GMT
- subjectAltName: host “[srv2.stats-con.com](http://srv2.stats-con.com)” matched cert’s “[srv2.stats-con.com](http://srv2.stats-con.com)”
- issuer: C=US; O=Let’s Encrypt; CN=R3
- SSL certificate verify ok.

> HEAD / HTTP/1.1  
> Host: [srv2.stats-con.com](http://srv2.stats-con.com)  
> User-Agent: curl/7.74.0  
> Accept: _/_

- TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):

- TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):

- old SSL session ID is stale, removing

- **Received HTTP/0.9 when not allowed**

- Closing connection 0

- TLSv1.3 (OUT), TLS alert, close notify (256):  
curl: (1) Received HTTP/0.9 when not allowed

The NGINX config file is updated as follows: default %\>% certbot %\>% added reverse proxy manually

# Questions:

How do I connect with curl and/or R/opalr to OPAL?

Best, Wilmar

---

<div class="post-metadata">

**Author:** ![yannick](https://yyz2.discourse-cdn.com/free1/user_avatar/datashield.discourse.group/yannick/32/19_2.png) [@yannick](https://datashield.discourse.group/u/yannick)\
**Post date:** [20 August 2022 07:51 UTC](https://datashield.discourse.group/t/recommended-way-of-installing-datashield/602/12 "2022-08-20T07:51:18Z")

</div>

nginx does not set the `Host` header by default (like Apache does). To avoid a CSRF check issue, you must specify it as follows:

```auto
location / {
    proxy_pass http://127.0.0.1:8843/;
    proxy_set_header Host $host;
}

```

Also, I think the proxied opal url is wrong as I suspect the port 8843 to be the one of the `https` entry point. Just use 8880 (or whatever you set in docker) to access via `http`.

---

<div class="post-metadata">

**Author:** ![wilmar.igl](https://avatars.discourse-cdn.com/v4/letter/w/7993a0/32.png) [@wilmar.igl](https://datashield.discourse.group/u/wilmar.igl)\
**Post date:** [20 August 2022 08:19 UTC](https://datashield.discourse.group/t/recommended-way-of-installing-datashield/602/13 "2022-08-20T08:19:44Z")

</div>

Dear Yannick,

thanks! Seems to work now.

I have added to my NGINX default conf (see port mapping of docker image):

> ```
> location / {                                                                                                                                                                                               
> proxy_pass http://127.0.0.1:8880/;                                                                                                                                                                 
> proxy_set_header Host $host;                                                                                                                                                                       
> }     
> 
> ```

# CURL log:

> /sudo:root@fedsrv2:/etc/nginx/sites-available/ #$ curl --verbose -I \>[https://srv2.stats-con.com](https://srv2.stats-con.com)
> 
> - Trying 116.203.185.16:443…
> 
> - Connected to [srv2.stats-con.com](http://srv2.stats-con.com) (116.203.185.16) port 443 (#0)
> 
> - ALPN, offering h2
> 
> - ALPN, offering http/1.1
> 
> - successfully set certificate verify locations:
> 
> - CAfile: /etc/ssl/certs/ca-certificates.crt
> 
> - CApath: /etc/ssl/certs
> 
> - TLSv1.3 (OUT), TLS handshake, Client hello (1):
> 
> - TLSv1.3 (IN), TLS handshake, Server hello (2):
> 
> - TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
> 
> - TLSv1.3 (IN), TLS handshake, Certificate (11):
> 
> - TLSv1.3 (IN), TLS handshake, CERT verify (15):
> 
> - TLSv1.3 (IN), TLS handshake, Finished (20):
> 
> - TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
> 
> - TLSv1.3 (OUT), TLS handshake, Finished (20):
> 
> - SSL connection using TLSv1.3 / TLS\_AES\_256\_GCM\_SHA384
> 
> - ALPN, server accepted to use http/1.1
> 
> - Server certificate:
> 
> - subject: [CN=srv2.stats-con.com](http://CN=srv2.stats-con.com)
> 
> - start date: Aug 19 13:44:54 2022 GMT
> 
> - expire date: Nov 17 13:44:53 2022 GMT
> 
> - subjectAltName: host “[srv2.stats-con.com](http://srv2.stats-con.com)” matched cert’s “[srv2.stats-con.com](http://srv2.stats-con.com)”
> 
> - issuer: C=US; O=Let’s Encrypt; CN=R3
> 
> - SSL certificate verify ok.  
> HEAD / HTTP/1.1  
> Host: [srv2.stats-con.com](http://srv2.stats-con.com)  
> User-Agent: curl/7.74.0  
> Accept: _/_
> 
> - TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
> 
> - TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
> 
> - old SSL session ID is stale, removing
> 
> - Mark bundle as not supporting multiuse  
> \< HTTP/1.1 302 Found  
> HTTP/1.1 302 Found  
> \< Server: nginx/1.18.0  
> Server: nginx/1.18.0  
> \< Date: Sat, 20 Aug 2022 08:20:12 GMT  
> Date: Sat, 20 Aug 2022 08:20:12 GMT  
> \< Content-Length: 0  
> Content-Length: 0  
> \< Connection: keep-alive  
> Connection: keep-alive  
> \< Location: [http://srv2.stats-con.com/index.html](http://srv2.stats-con.com/index.html)  
> Location: [http://srv2.stats-con.com/index.html](http://srv2.stats-con.com/index.html)

# R script (works!):

con.opal ← opal.login(username = “###”, password = “###”,  
url = “[https://srv2.stats-con.com](https://srv2.stats-con.com)”)

Thank you so much, Wilmar
