Download and install ServerSecretVault
ssv is a single, self-contained program. It needs no runtime, libraries or other software to run.
ssv is proprietary software. Downloading or installing it means accepting its license.
Requirements
- A Linux server with an x86_64 (amd64) or ARM64 (aarch64) processor. Run
uname -mto see which. - Root access (
sudo) to scan files that belong to other users. Without root,ssvonly sees the files your own account can read. - The
ageencryption tool, but only forssv backup. Scanning and auditing don't need it. See Install age.
Quick install
curl -fsSL https://serversecretvault.com/install.sh | sudo sh
Downloading ssv 0.2.0 for linux/amd64...
Checksum verified.
Installed ssv 0.2.0 to /usr/local/bin/ssv
Get started: sudo ssv audit (ssv help lists all commands)
The installer:
- picks the right package for the server's processor,
- downloads the latest version from
serversecretvault.comover HTTPS, - checks its SHA-256 checksum and stops if it doesn't match,
- installs
ssvas/usr/local/bin/ssv.
On RHEL, Rocky, AlmaLinux and CloudLinux, sudo doesn't look in /usr/local/bin, so sudo ssv would fail with "command not found". There the installer also creates a link, /usr/bin/ssv, pointing to /usr/local/bin/ssv, and says so. It never replaces an existing /usr/bin/ssv that it didn't create. Apart from that, it changes nothing else on the system.
If curl isn't installed, use wget -qO- https://serversecretvault.com/install.sh | sudo sh.
Options go after sh -s --:
# a specific version
curl -fsSL https://serversecretvault.com/install.sh | sudo sh -s -- --version 0.2.0
# another directory; no sudo needed if you can write to it
curl -fsSL https://serversecretvault.com/install.sh | sh -s -- --dir "$HOME/bin"
To read the installer before running it:
curl -fsSLO https://serversecretvault.com/install.sh
less install.sh
sudo sh install.sh
Manual installation
Install manually if you want to check each step yourself, or if the server has no internet access. In that case, download the files elsewhere and copy them over with scp or similar.
1. Download the package for your server
uname -m prints |
Package |
|---|---|
x86_64 |
ssv-<version>-linux-amd64.tar.gz |
aarch64 or arm64 |
ssv-<version>-linux-arm64.tar.gz |
Packages are at https://serversecretvault.com/download/<version>/, together with a SHA256SUMS file. https://serversecretvault.com/download/latest.txt contains the latest version number. Other architectures, such as 32-bit ARM, are not packaged.
The examples below use version 0.2.0 on an x86_64 server; substitute your version and architecture.
curl -fLO https://serversecretvault.com/download/0.2.0/ssv-0.2.0-linux-amd64.tar.gz
curl -fLO https://serversecretvault.com/download/0.2.0/SHA256SUMS
2. Verify the download
sha256sum -c --ignore-missing SHA256SUMS
You should see:
ssv-0.2.0-linux-amd64.tar.gz: OK
Don't install the package if the result is FAILED. On BusyBox-based systems such as Alpine, which lack --ignore-missing, use grep linux-amd64 SHA256SUMS | sha256sum -c - instead.
3. Extract the package
tar -xzf ssv-0.2.0-linux-amd64.tar.gz
cd ssv-0.2.0-linux-amd64
The package contains:
| File | Purpose |
|---|---|
ssv |
the program |
install.sh |
copies ssv into place |
INSTALL.md |
this guide, as Markdown |
USAGE.md |
how to use ssv (the documentation, as Markdown) |
LICENSE |
the license agreement |
THIRD_PARTY_NOTICES |
licenses of third-party code built into ssv |
4. Run it directly, or install it
To try it without installing anything, run it from the extracted directory:
sudo ./ssv scan
To install it for everyone as /usr/local/bin/ssv:
sudo ./install.sh
Installed ssv 0.2.0 to /usr/local/bin/ssv
To install somewhere else, for example without root: ./install.sh --dir "$HOME/bin". This script copies the binary from the package and, like the quick installer, adds the /usr/bin/ssv link where sudo needs it. It doesn't download anything. Doing it by hand is equivalent:
sudo install -m 0755 ssv /usr/local/bin/ssv
# only on RHEL, Rocky, AlmaLinux and CloudLinux:
sudo ln -s /usr/local/bin/ssv /usr/bin/ssv
Install age (needed for backups)
If age is missing, ssv backup stops before it starts and prints the install commands for your server's Linux distribution. You can also install it in advance:
| System | Commands |
|---|---|
| AlmaLinux, Rocky, CloudLinux, CentOS Stream 9 and newer | sudo dnf install epel-release then sudo dnf install age |
| RHEL 9 and newer | sudo dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-9.noarch.rpm then sudo dnf install age (use your major version number) |
| Oracle Linux 9 and newer | sudo dnf install oracle-epel-release-el9 then sudo dnf install age |
| Fedora | sudo dnf install age |
| Debian 11+, Ubuntu 22.04+ | sudo apt install age |
| Alpine | sudo apk add age |
| Arch | sudo pacman -S age |
| AlmaLinux, Rocky, CloudLinux, RHEL or CentOS 8 and older, and anything else | the official prebuilt release, below |
There is no age package for version 8 and older of the RHEL family. On those servers, and on any other Linux, install the official prebuilt release of age. For ARM servers, replace amd64 with arm64:
cd "$(mktemp -d)"
curl -fsSL "https://dl.filippo.io/age/latest?for=linux/amd64" | tar -xz
sudo install -m 0755 age/age age/age-keygen /usr/local/bin/
Check it with age --version. ssv finds age in /usr/local/bin even when sudo doesn't search that directory.
Check that it works
ssv version
sudo ssv audit
The first command prints ssv 0.2.0. See ssv audit for what the audit report means and encrypted backups for how to make backups.
Upgrading
Run the quick install command again, or repeat the manual steps with the new package. Either way the old binary is replaced, and an ssv that is running at that moment, for example from cron, isn't disturbed. Backups made by any version are restored with standard age and tar, so old backups stay readable.
Uninstalling
sudo rm /usr/local/bin/ssv
If the installer created the /usr/bin/ssv link, remove that too: sudo rm /usr/bin/ssv.
ssv creates no configuration files, services or caches. The only things to remove are ones you set up yourself, such as backup files, a recipients file, or cron entries.
License
ssv is proprietary software. Downloading, installing or using it means accepting its license agreement, which is also in the LICENSE file of every package and shown by ssv license. The licenses of third-party code built into ssv are in THIRD_PARTY_NOTICES.
Last updated 2026-10-08 · for ssv 0.2.0