Download and install ServerSecretVault

ssv is a single, self-contained program. It needs no runtime, libraries or other software to run.

$ curl -fsSL https://serversecretvault.com/install.sh | sudo sh
ssv 0.2.0 · Linux packages SHA256SUMS
x86_64 amd64ssv-0.2.0-linux-amd64.tar.gz 1.1 MB ↓ ARM64 aarch64ssv-0.2.0-linux-arm64.tar.gz 1.0 MB ↓

ssv is proprietary software. Downloading or installing it means accepting its license.

Requirements

  • A Linux server with an x86_64 (amd64) or ARM64 (aarch64) processor. Run uname -m to see which.
  • Root access (sudo) to scan files that belong to other users. Without root, ssv only sees the files your own account can read.
  • The age encryption tool, but only for ssv backup. Scanning and auditing don't need it. See Install age.

Quick install

curl -fsSL https://serversecretvault.com/install.sh | sudo sh
Downloading ssv 0.2.0 for linux/amd64...
Checksum verified.
Installed ssv 0.2.0 to /usr/local/bin/ssv

Get started:  sudo ssv audit      (ssv help lists all commands)

The installer:

  1. picks the right package for the server's processor,
  2. downloads the latest version from serversecretvault.com over HTTPS,
  3. checks its SHA-256 checksum and stops if it doesn't match,
  4. installs ssv as /usr/local/bin/ssv.

On RHEL, Rocky, AlmaLinux and CloudLinux, sudo doesn't look in /usr/local/bin, so sudo ssv would fail with "command not found". There the installer also creates a link, /usr/bin/ssv, pointing to /usr/local/bin/ssv, and says so. It never replaces an existing /usr/bin/ssv that it didn't create. Apart from that, it changes nothing else on the system.

If curl isn't installed, use wget -qO- https://serversecretvault.com/install.sh | sudo sh.

Options go after sh -s --:

# a specific version
curl -fsSL https://serversecretvault.com/install.sh | sudo sh -s -- --version 0.2.0
# another directory; no sudo needed if you can write to it
curl -fsSL https://serversecretvault.com/install.sh | sh -s -- --dir "$HOME/bin"

To read the installer before running it:

curl -fsSLO https://serversecretvault.com/install.sh
less install.sh
sudo sh install.sh

Manual installation

Install manually if you want to check each step yourself, or if the server has no internet access. In that case, download the files elsewhere and copy them over with scp or similar.

1. Download the package for your server

uname -m prints Package
x86_64 ssv-<version>-linux-amd64.tar.gz
aarch64 or arm64 ssv-<version>-linux-arm64.tar.gz

Packages are at https://serversecretvault.com/download/<version>/, together with a SHA256SUMS file. https://serversecretvault.com/download/latest.txt contains the latest version number. Other architectures, such as 32-bit ARM, are not packaged.

The examples below use version 0.2.0 on an x86_64 server; substitute your version and architecture.

curl -fLO https://serversecretvault.com/download/0.2.0/ssv-0.2.0-linux-amd64.tar.gz
curl -fLO https://serversecretvault.com/download/0.2.0/SHA256SUMS

2. Verify the download

sha256sum -c --ignore-missing SHA256SUMS

You should see:

ssv-0.2.0-linux-amd64.tar.gz: OK

Don't install the package if the result is FAILED. On BusyBox-based systems such as Alpine, which lack --ignore-missing, use grep linux-amd64 SHA256SUMS | sha256sum -c - instead.

3. Extract the package

tar -xzf ssv-0.2.0-linux-amd64.tar.gz
cd ssv-0.2.0-linux-amd64

The package contains:

File Purpose
ssv the program
install.sh copies ssv into place
INSTALL.md this guide, as Markdown
USAGE.md how to use ssv (the documentation, as Markdown)
LICENSE the license agreement
THIRD_PARTY_NOTICES licenses of third-party code built into ssv

4. Run it directly, or install it

To try it without installing anything, run it from the extracted directory:

sudo ./ssv scan

To install it for everyone as /usr/local/bin/ssv:

sudo ./install.sh
Installed ssv 0.2.0 to /usr/local/bin/ssv

To install somewhere else, for example without root: ./install.sh --dir "$HOME/bin". This script copies the binary from the package and, like the quick installer, adds the /usr/bin/ssv link where sudo needs it. It doesn't download anything. Doing it by hand is equivalent:

sudo install -m 0755 ssv /usr/local/bin/ssv
# only on RHEL, Rocky, AlmaLinux and CloudLinux:
sudo ln -s /usr/local/bin/ssv /usr/bin/ssv

Install age (needed for backups)

If age is missing, ssv backup stops before it starts and prints the install commands for your server's Linux distribution. You can also install it in advance:

System Commands
AlmaLinux, Rocky, CloudLinux, CentOS Stream 9 and newer sudo dnf install epel-release then sudo dnf install age
RHEL 9 and newer sudo dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-9.noarch.rpm then sudo dnf install age (use your major version number)
Oracle Linux 9 and newer sudo dnf install oracle-epel-release-el9 then sudo dnf install age
Fedora sudo dnf install age
Debian 11+, Ubuntu 22.04+ sudo apt install age
Alpine sudo apk add age
Arch sudo pacman -S age
AlmaLinux, Rocky, CloudLinux, RHEL or CentOS 8 and older, and anything else the official prebuilt release, below

There is no age package for version 8 and older of the RHEL family. On those servers, and on any other Linux, install the official prebuilt release of age. For ARM servers, replace amd64 with arm64:

cd "$(mktemp -d)"
curl -fsSL "https://dl.filippo.io/age/latest?for=linux/amd64" | tar -xz
sudo install -m 0755 age/age age/age-keygen /usr/local/bin/

Check it with age --version. ssv finds age in /usr/local/bin even when sudo doesn't search that directory.

Check that it works

ssv version
sudo ssv audit

The first command prints ssv 0.2.0. See ssv audit for what the audit report means and encrypted backups for how to make backups.

Upgrading

Run the quick install command again, or repeat the manual steps with the new package. Either way the old binary is replaced, and an ssv that is running at that moment, for example from cron, isn't disturbed. Backups made by any version are restored with standard age and tar, so old backups stay readable.

Uninstalling

sudo rm /usr/local/bin/ssv

If the installer created the /usr/bin/ssv link, remove that too: sudo rm /usr/bin/ssv.

ssv creates no configuration files, services or caches. The only things to remove are ones you set up yourself, such as backup files, a recipients file, or cron entries.

License

ssv is proprietary software. Downloading, installing or using it means accepting its license agreement, which is also in the LICENSE file of every package and shown by ssv license. The licenses of third-party code built into ssv are in THIRD_PARTY_NOTICES.

Last updated 2026-10-08 · for ssv 0.2.0