> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sesameterminal.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy and run sesame

# Deploy and run sesame

> **In short.** These pages put sesame on a server that you rent, at an address such as
> `https://trade.example.com`. At the end, the app runs with HTTPS and makes a backup every
> 6 hours. An encrypted copy of each backup goes to a second machine. One command installs
> each new release. Read this page. Then do pages 1 to 4 once, in order.

## The pages

| # | Page | What you do | Time |
| - | - | - | - |
| 1 | [Prepare the server](1-prepare-server.md) | Install the software, lock the server, create your keys | About 1 to 2 hours |
| 2 | [First deploy](2-first-deploy.md) | Build the app, create its settings file, log in | About 30 minutes |
| 3 | [Backups](3-backups.md) | Send encrypted backups to a second machine, test a restore | About 30 minutes |
| 4 | [Go live](4-go-live.md) | Connect Polymarket, do the live verification, turn trading on | About 3 hours |
| | [Day to day](day-to-day.md) | Install updates, roll back, restore a backup, set up Telegram | Reference |
| | [Troubleshooting](troubleshooting.md) | Find what a message means and what to do | When necessary |
| | [Advanced](advanced.md) | How the deploy is protected, rare restores, the security checklist | When necessary |

[configuration.md](../configuration.md) explains each setting that the app reads.

## The three machines

You use three machines. This diagram shows what each one does.

```text theme={null}
+---------------+  one command per touch   +----------------+  HTTPS  +---------+
| Your computer | -----------------------> |     Server     | <------ | Browser |
| keys, tags,   |        (SSH)             | the app, HTTPS |         +---------+
| task commands |                          | backups        |
+---------------+                          +-------+--------+
                                                   |
                                                   | encrypted backups, once a day
                                                   v
                                           +----------------+
                                           | Backup machine |
                                           +----------------+
```

## Words used in these pages

| Word | Meaning here |
| - | - |
| Server | The computer that you rent from a hosting provider. Another name is VPS. It runs the app all the time |
| Your computer | The machine that you deploy from. No AI coding agent can run on it |
| Backup machine | A second Linux computer that keeps encrypted copies of the backups |
| Terminal | The window where you type commands. On Windows, use Git Bash. Do not use PowerShell or cmd |
| SSH | The method that you use to log in to the server's terminal from your computer |
| SSH key | A pair of files that you use for SSH in place of a password. The private file stays with you. The public file (`.pub`) goes on the server |
| Security key | A small USB device (FIDO2, for example a YubiKey) that holds the deploy key. You touch it for each command |
| Fingerprint | A short code that identifies the server. You compare it once, so that you know you connect to the correct server |
| Domain and DNS record | The name of the site (`trade.example.com`), and the entry that points that name to the server's IP address |
| Environment file | A text file of `NAME=value` lines. The app reads it when it starts. The app's file is `sesame.env` |
| Release tag | A name that you give to one version of the code, with your signature, for example `release-2026-10-01`. The server installs only tags that you signed |
| Docker and containers | The software that runs the app on the server, isolated from the rest of the system |
| `sudo` | Put this word before a command to run it as the server's administrator (root) |
| Task | The tool that runs the `task ...` commands on your computer ([taskfile.dev](https://taskfile.dev)) |

## Placeholders

The commands show the values that you must replace in angle brackets. Type your value
without the brackets.

| Placeholder | Replace with | Example |
| - | - | - |
| `<your-domain>` | The name of the site | `trade.example.com` |
| `<your-email>` | Your email address | `alex@example.com` |
| `<server-ip>` | The server's IP address, from the provider | `203.0.113.10` |
| `<your-ip>` | The public IP address of your computer | `198.51.100.7` |
| `<backup-ip>` | The public IP address of the backup machine | `198.51.100.8` |
| `<admin>` | Your own user name on the server | `alex` |
| `<tag>` | A release tag | `release-2026-10-01` |
| `<commit>` | The commit that a release tag marks | `7f2ae12` |
| `<repo-url>` | The address of the repository | `https://github.com/franco-bianco/sesame-bun.git` |
| `<repo-folder>` | The folder of your copy of the repository on the backup machine | `/home/alex/sesame-bun` |

## Before you start

You need:

* **A server** with Debian 12 or Ubuntu 24.04, 2 CPUs, 2 GB of memory and 20 GB of disk
  space as a minimum. It must be in a country where Polymarket permits trading.
* **A domain** that you control, and an email address for the HTTPS certificate.
* **Your computer**, with no AI coding agent on it. It must have bash, git, ssh and
  [Task](https://taskfile.dev). Use Linux, or Git Bash on Windows.
* **A backup machine.** This is a second Linux computer. It must not be the server, and it
  must not be a machine that agents use. It must have git, rsync, ssh and Task.
* **A security key** (FIDO2, for example a YubiKey) for the deploy key. On a computer
  without agents, a key file with a passphrase is also permitted.

Polymarket must permit you to trade where you are, each time that you use the app. The app
does not go around Polymarket's location check. Do not use a proxy, a VPN or a similar
service.

Coding agents do not run deploys. They do not connect to the server. They do not touch a
key, a password or a secret on these pages. You do all of these tasks yourself.

Next: [1. Prepare the server](1-prepare-server.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.