Free to runDocker

Your server. Your consent platform. One command.

ZenoCookieConsent ships as containers: the web app (dashboard, public API and zeno.js), PostgreSQL, MinIO for S3 storage and Caddy for automatic HTTPS. One installer sets it all up on any Linux server with Docker, behind your own domain.

Install

Pick your path.

The installer checks Docker, writes deploy/.env with freshly generated secrets, builds the image, starts the stack and waits until the app is healthy. Re-running it is safe: an existing .env is kept.

1

Point DNS

Create a DNS record for your consent hostname, e.g. consent.example.com, pointing at the server.

2

Run the installer

From a clone of the repository, or with the one-liner, which fetches the source into ./zenocookieconsent first. Read the script before you pipe it into a shell.

3

Create the first account

Open the setup URL the installer prints (https://consent.example.com/setup), create the administrator and add a domain.

$ git clone <repository> && cd zenocookieconsent && ./install.sh --domain consent.example.com

Trying it locally? ./install.sh --domain localhost --port 3000 --yes runs everything on http://localhost:3000 without TLS. Then add the script tag to your site: <script src="https://consent.example.com/zeno.js"></script>

Installer options

Run ./install.sh --help for the same list. Without options the installer asks for the hostname, whether to run Caddy and whether to run MinIO; with curl … | bash it asks on your terminal.

OptionEffect
--domain HOSTPublic hostname of the consent service, e.g. consent.example.com. With localhost, Caddy is skipped and the app runs on plain HTTP.
--no-caddyDon't run the built-in HTTPS proxy. Put your own reverse proxy in front of the app port.
--external-s3Don't run the built-in MinIO. Edit the S3_* values in deploy/.env afterwards and re-run.
--port NHost port for the app when not using Caddy (default 3000).
--yesAccept the defaults and ask no questions (unattended installs).
--forceOverwrite an existing deploy/.env with newly generated secrets.

Before you start

What you need.

A Linux server

x86_64 or arm64, at least 1 vCPU, 1 GB RAM and 10 GB disk. Docker Engine 24+ with the Compose v2 plugin, and git.

A hostname

For example consent.example.com, with a DNS record pointing at the server.

TLS

The built-in Caddy gets certificates automatically: keep ports 80 and 443 open. Or use your own proxy with --no-caddy.

Storage

PostgreSQL and MinIO are included. Prefer your own S3-compatible bucket? Use --external-s3. SMTP for invitation e-mails is optional.

What runs where

A deliberately boring architecture.

One web app, one database, one bucket, one proxy. Every request from a visitor's browser goes to your hostname and nowhere else.

  • Web app. Admin dashboard at /app, public API at /api/v1, and zeno.js.
  • PostgreSQL. Organizations, users, domains, published snapshots, consent receipts and the audit trail.
  • S3 or MinIO. Logos, consent-log exports, archives and database backups.
  • Caddy. Terminates TLS with automatic certificates, or bring your own reverse proxy.
Architecture Your customers' websites load zeno.js and call GET /api/v1/config and POST /api/v1/log on your ZenoCookieConsent server, which stores data in PostgreSQL and an S3 or MinIO bucket. Websites you manage <script src="…/zeno.js"> GET /api/v1/config · POST /api/v1/log Your server · consent.your-domain.com ZenoCookieConsent web app Dashboard /app · Public API /api/v1 · zeno.js PostgreSQL receipts, domains, users S3 / MinIO exports, archives, backups

Day two

Running it is your job. We make it easy.

Updates

Pull the new source and rebuild. Database migrations run automatically on start. Check the release notes first.

git pull
cd deploy
docker compose up -d --build

Backups

Nightly pg_dump backups go to object storage by default. Consent receipts are legal evidence: test your restores.

Operations manual

Reverse proxy examples, environment variables, monitoring and upgrades, step by step.

Open the manual

You become the operator. Self-hosting means the consent data never leaves your infrastructure, and also that availability, security updates and backups are in your hands. Plan for them like any other production service.

Ready when you are.

Read the operations manual, or look at the source before you install anything.