Getting started

You need a supported OS, Docker Engine with Compose, UDP from your exporters, and BGP to the edge. See Requirements.

A fresh install needs a license key before protection starts. Email [email protected] for a time-limited demo key, or buy on Pricing.

  1. Unpack the offline bundle. Check the signed checksum, then:

    sudo ./install.sh --yes \
      --operator-email [email protected] \
      --operator-password-file /root/op.pass \
      --license /path/license.tpl
    

    Useful flags:

    • --license /path/license.tpl to install a license at setup
    • --tls acme|files|selfsigned
    • --public to bind the dashboard and API beyond localhost

    The installer writes /opt/templass and /opt/templass/.env (mode 600). Check with systemctl status templass.

    Dashboard: http://127.0.0.1:9411. API: http://127.0.0.1:9410.

  2. To load a key later, paste it on System, or run templassctl license install. Details: License.

  3. For a public dashboard, use --tls acme (needs ports 80/443) or put a reverse proxy in front. On System, set Public URL. Customer invites and some webhooks use that URL.

  4. In the operator dashboard, add each exporter under Flow sources. Listeners default to UDP 2055 (NetFlow/IPFIX) and UDP 6343 (sFlow). Confirm packets in System metrics or templassctl status.

  5. Edit /opt/templass/config.yaml:

    bgp:
      asn: 64500
      router_id: 192.0.2.1
      peers:
        - address: 192.0.2.2
          asn: 64501
          families: [ipv4-unicast, ipv6-unicast, ipv4-flowspec, ipv6-flowspec]
    

    Restart the controller so the speaker picks up ASN, router-id and peers. The GUI BGP peers page shows session state.

    On the edge, import RTBH (community 65535:666, NO_EXPORT) and FlowSpec if you use them.

  6. Create an organization, a group, and prefixes in the GUI. Set pps, bps and flow-rate thresholds (global or per vector). Set host mode and subnet mode (rtbh, flowspec, both, scrub, none). Prefix and threshold changes apply within 5 seconds.

    For a first test, use Mitigations to announce and withdraw by hand on a prefix you can afford to blackhole.

    1. Create an enrollment token on Scrub nodes.
    2. Install the templass-scrub package (.deb, .rpm, static binary, or container).
    3. Set enroll_token in /etc/templass/scrub.yaml.
    4. Start templass-scrub. The node stores a per-node token after enrollment.
    5. Build the clean-return path (VLAN or GRE) and policy routing.
    6. Set the group's host mode to scrub.

    Full notes: Scrub node.

  7. After Public URL is set, invite from Users by password or one-time link. Preview their panel from the operator UI. They see only their prefixes.