> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sesameterminal.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 2. First deploy

# 2. First deploy

> **In short.** You tell your computer where the server is. You build the app on the server,
> create the app's settings file with your login password, and start the app. At the end,
> the app answers at `https://<your-domain>` and you can log in. Trading stays off until
> [4. Go live](4-go-live.md).

Each command block says where to type it: on **the server** or on **your computer**.

## Step 1. Fill in your computer's deploy settings

1. On **your computer**, go to the folder of your copy of the repository.

2. Copy the template of the deploy settings. Git ignores the new file:

   ```sh theme={null}
   cp deploy/deploy.env.example deploy/.deploy.env
   ```

3. Open `deploy/.deploy.env` in a text editor. Fill in these three lines:

   ```dotenv theme={null}
   SESAME_DEPLOY_HOST=<your-domain>
   SESAME_DEPLOY_KEY=~/.ssh/sesame_deploy
   SESAME_ALLOWED_SIGNERS=~/.config/sesame/allowed_signers
   ```

4. Do not change the other lines. Save the file.

| Line | What it is |
| - | - |
| `SESAME_DEPLOY_HOST` | The server. Use the same name as in [Step 12 of Prepare the server](1-prepare-server.md#step-12-record-the-servers-fingerprint) |
| `SESAME_DEPLOY_KEY` | The deploy key from Step 7 of Prepare the server |
| `SESAME_ALLOWED_SIGNERS` | Your list of allowed signers from Step 8 of Prepare the server. Each `task deploy` command checks the tag's signature against it |
| `SESAME_DEPLOY_USER` | Keep `deploy` |
| `SESAME_DEPLOY_PORT` | Keep `22` |

## Step 2. Build the app on the server

1. On **your computer**, in the repository folder, start the deploy:

   ```sh theme={null}
   task deploy -- <tag>
   ```

2. When ssh asks, type the PIN of the security key and touch the key. For a key file, type
   the passphrase.

3. Wait. The server gets the tag, checks it and builds the app. The first build takes some
   minutes.

The command stops with this message:

```text theme={null}
sesamectl: missing /opt/sesame/sesame.env; create it as root:root 0600 (docs/guides/deploy/2-first-deploy.md)
```

This result is correct. The app needs its settings file. You create it in Step 3.

## Step 3. Create the settings file

1. On **the server**, make the hash of your login password:

   ```sh theme={null}
   sudo docker run --rm -it --network none sesame:<tag> hash-password
   ```

2. At `Password:`, type the password that you will use to log in to the app. The screen
   does not show it.

3. Copy the line that the command shows. It starts with `$argon2id$`.

4. On **the server**, make a random session secret:

   ```sh theme={null}
   openssl rand -hex 32
   ```

5. Copy the line that the command shows. Also keep a copy in your password manager.

   WARNING: Do not lose the session secret. A backup restores only with the session
   secret that was set when the app wrote the backup.

6. On **the server**, create the settings file and open it:

   ```sh theme={null}
   sudo install -o root -g root -m 0600 /dev/null /opt/sesame/sesame.env
   sudoedit /opt/sesame/sesame.env
   ```

7. Write these three lines. Put the hash between single quotes.

   ```dotenv theme={null}
   UI_PASSWORD_HASH='<the hash from item 3>'
   SESSION_SECRET=<the secret from item 5>
   LIVE_TRADING=false
   ```

8. Save the file and close the editor.

[configuration.md](../configuration.md) lists the other settings that you can add.

## Step 4. Deploy again

1. On **your computer**, start the deploy again:

   ```sh theme={null}
   task deploy -- <tag>
   ```

2. Type the PIN and touch the security key, or type the passphrase.

The server uses the build from Step 2 again and starts the app. The command ends with this
message:

```text theme={null}
sesamectl: <tag> is running at https://<your-domain> (previous tag: none)
```

## Is it working?

| Check | How | Expected result |
| - | - | - |
| The app runs | On your computer: `curl -s https://<your-domain>/api/health` | `{"status":"ok"}`. If you see `degraded`, the location check failed. See [Troubleshooting](troubleshooting.md#the-app-runs-but-trading-stays-off) |
| HTTPS works | Open `http://<your-domain>` in a browser | The address changes to `https://` and the browser shows a padlock |
| You can log in | Log in with the password from Step 3 | The app opens |
| Polymarket permits the location | Log in, then open `https://<your-domain>/api/status` in the same browser | Under `geoblock`, `"blocked":false` |
| The correct release runs | On your computer: `task deploy:status` | `SESAME_IMAGE_TAG=<tag>`, and the containers `sesame` and `caddy` are up |

On the `/api/status` page, `trading_enabled` is `false` at this time. This is correct. You
turn trading on in [4. Go live](4-go-live.md).

If a check fails, see [Troubleshooting](troubleshooting.md).

Previous: [1. Prepare the server](1-prepare-server.md) · Next: [3. Backups](3-backups.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.