Getting started

Rent and prepare a server

Libris Translate runs on a rented Linux server. Follow this guide to choose one, prepare it, and open it on your computer.

Rent and prepare a server for Libris Translate · 1 min 52 Real, silent screen capture of server preparation on a test Ubuntu 24.04.5 LTS server; it is not a rented VPS.
What the video shows
  • Benchmarks for choosing the server: x86-64 (AMD64) processor, Ubuntu 24.04 LTS, at least 2 GB of memory (4 GB recommended), at least 20 GB of disk (40 GB recommended).
  • Create an Ed25519 SSH key with ssh-keygen -t ed25519; only the public key (.pub) is given to the provider.
  • Connect over SSH for the first time: compare the fingerprint shown by ssh with the one in the server console before answering yes.
  • Update Ubuntu, create the libris account, copy the public key, and enable UFW while allowing only OpenSSH.
  • In a second window, sign in with the libris account and check sudo whoami (answer: root); the first session stays open.
  • Install Docker Engine and Compose from Docker’s official repository, then verify: sudo docker compose version (v2 or later) and sudo docker run hello-world.
  • The tutorial stops before installing Libris Translate: follow the guide to continue.

The video was recorded from a Linux workstation, with Ubuntu output in English, on a temporary Ubuntu Server 24.04.5 LTS test server with 4 vCPUs, 4 GB RAM and 40 GB disk—not on a rented VPS. No hosting control panel is shown: the public key is displayed in the terminal and the fingerprint is checked against the server console. The SSH commands are shared with macOS, but the recording was not made on a Mac.

Video transcript

  1. Benchmarks for choosing the server: x86-64 (AMD64) processor, Ubuntu 24.04 LTS, at least 2 GB of memory (4 GB recommended), at least 20 GB of disk (40 GB recommended).
  2. Create an Ed25519 SSH key with ssh-keygen -t ed25519; only the public key (.pub) is given to the provider.
  3. Connect over SSH for the first time: compare the fingerprint shown by ssh with the one in the server console before answering yes.
  4. Update Ubuntu, create the libris account, copy the public key, and enable UFW while allowing only OpenSSH.
  5. In a second window, sign in with the libris account and check sudo whoami (answer: root); the first session stays open.
  6. Install Docker Engine and Compose from Docker’s official repository, then verify: sudo docker compose version (v2 or later) and sudo docker run hello-world.
  7. The tutorial stops before installing Libris Translate: follow the guide to continue.

Why a server?

Libris Translate does not run directly on macOS or Windows. It runs on Linux, on a machine you rent from a hosting provider. Your books, glossaries, and translations stay on that server. During translation, passages sent to the model go to the provider you chose; hosting Libris yourself does not make that model open-source. The model and its cost are separate choices: models and costs.

Choose a VPS

Pick an x86-64 (AMD64) machine, never ARM: Libris images are published for AMD64. Docker supports Ubuntu 22.04, 24.04, and 26.04 LTS and Debian 12 and 13 (checked 5 October 2026). If data residency matters to you, choose a data centre in the required region; otherwise, choose one nearby to reduce latency. Also check backups and snapshots.

Measured memory: 2 GB is enough to start; we recommend 4 GB. Libris at rest used 288 MiB in its containers and 659 MiB total on a 2 GB VM. During translation, containers peaked at about 1,016 MiB (measured on preproduction). Disk: 20 GB minimum, 40 GB recommended; a measured installation used 4.6 GB before your books and backups. Measurements taken 5 October 2026 on the version deployed at that time; the Ubuntu test machine was a full emulated VM, not a rented VPS.

Examples and prices

These examples are neither a ranking nor an endorsement; we are not affiliated with any provider. Prices checked 5 October 2026 and may change: Scaleway DEV1-S (2 vCPU, 2 GB RAM, x86-64), about €6.55/month before tax, excluding storage and IPv4; OVHcloud VPS-1 (2 vCores, 4 GB RAM, 40 GB NVMe), from €3.81/month before VAT on its France site. Check architecture, region, fees, and options before ordering. Scaleway prices · OVHcloud prices.

Create an SSH key

Open Terminal on Mac or PowerShell on Windows and enter the command below. At the file path prompt, press Enter to keep the suggested path. Choose a passphrase and remember it; to leave it empty, press Enter twice. The file without .pub is private and must never be shared.

ssh-keygen -t ed25519

Display the public key to copy into your provider’s control panel:

Mac: cat ~/.ssh/id_ed25519.pub
Windows: type $env:USERPROFILE\.ssh\id_ed25519.pub

Connect for the first time

In your hosting control panel, copy the public IP address and add your public key. Replace USER with the initial account (often root or ubuntu), and SERVER_IP with your server address. On the first connection, check the server fingerprint and type yes to accept it. Mac: these OpenSSH commands have not been tested on a physical Mac.

ssh USER@SERVER_IP

On Windows, PowerShell uses the OpenSSH client and the same commands. If ssh is not found on an older Windows 10 PC, install “OpenSSH Client” in Settings > Apps > Optional features. These steps were checked against Microsoft’s OpenSSH key documentation, but not tested on a Windows PC.

Prepare Ubuntu

The commands below were replayed end to end on a clean Ubuntu Server 24.04 LTS on 5 October 2026. If the upgrade installs a new kernel and asks for a reboot, restart from your provider’s control panel and reconnect. If your provider gives you the ubuntu account, connect with that name and prefix each administrative command with sudo. If you start as root, use the commands below to create a personal account:

Give the libris account a long, unique password: it protects sudo. Do not add it to the docker group (that grants root access) or configure passwordless sudo.

sudo apt update && sudo apt upgrade -y
sudo adduser libris
sudo usermod -aG sudo libris
sudo rsync --archive --chown=libris:libris ~/.ssh /home/libris
sudo ufw allow OpenSSH
sudo ufw enable
sudo ufw status verbose

rsync copies the public key already installed by your provider into the libris account. Allow SSH with ufw allow OpenSSH before enabling the firewall. After adduser, set the password, then press Enter for each optional field. UFW asks you to confirm enabling it: answer y. If your provider uses an SSH port other than 22, do not continue until you have adjusted the rule. If your provider offers a separate firewall, allow only port 22 there.

Strongly recommended: after creating the account, test it before hardening SSH. Keep this window open and open a second one:

ssh libris@SERVER_IP

In the second window, verify sudo with:

sudo whoami

The expected answer is root. If login or sudo fails, stop here. Harden SSH only after this test succeeds.

sudo tee /etc/ssh/sshd_config.d/00-libris.conf <<'EOF'
PasswordAuthentication no
PermitRootLogin no
EOF
sudo sshd -t && sudo systemctl reload ssh
sudo sshd -T | grep -Ei '^(passwordauthentication|permitrootlogin)'

The 00-libris.conf name matters: sshd keeps the first value it reads; a 99- file may be ignored. Check for passwordauthentication no and permitrootlogin no, then in the second window test ssh root@SERVER_IP (should be refused) and ssh libris@SERVER_IP (should connect). Keep the first window open. If you lose access, use your provider’s web console and remove the file: sudo rm /etc/ssh/sshd_config.d/00-libris.conf && sudo systemctl reload ssh.

Automatic security updates do not always reboot the server and do not cover Docker. Once a month, run sudo apt update && sudo apt upgrade -y and reboot if Ubuntu asks. Update Libris with its installer.

Install Docker Engine and Compose

Use Docker’s official apt repository, not Ubuntu’s docker.io package. Follow “Install using the apt repository” in Docker’s Ubuntu instructions, then verify:

Install Docker Engine, CLI, containerd, Buildx, and the Compose plugin from the official repository. Docker’s page keeps the steps current.

sudo docker compose version

Compose must report version v2 or later. Then check the engine:

sudo docker run hello-world

On tested Ubuntu 24.04, unattended-upgrades was already enabled. A kernel update may require a reboot.

Install Libris Translate

Request a free trial or choose a plan on the home page. The installer will ask for the registry username and token; copy them from your email. Never put the token in a command or shared file:

Tested command:

curl --fail --location --silent --show-error https://libris-translate.com/install.sh | sudo bash

The installer prints the initial username admin and the command sudo grep "^BOOTSTRAP_" /opt/libris/.env to retrieve the temporary password. Sign in as admin, run the command on the server, and change the password. Never share this password, the command’s output, /opt/libris/.env, or docker compose config output.

Never add -k or --insecure. To read the script before running it:

curl --fail --location --silent --show-error -o install-libris.sh https://libris-translate.com/install.sh
less install-libris.sh
sudo bash install-libris.sh

Open Libris from Mac or Windows

Libris runs on your server, and you use it in the browser on your computer. One command connects the two; run it again each time you want to work.

  1. On your computer, open a new Terminal window (Mac) or PowerShell window (Windows).
  2. Copy this command, replace SERVER_IP with your server’s address, and press Enter:
    ssh -N -L 8088:127.0.0.1:8088 libris@SERVER_IP
  3. Enter your key’s passphrase if asked; nothing appears as you type. The window then shows nothing more: that is normal, the connection is open. Leave this window open.
  4. In your browser, open http://localhost:8088: the Libris sign-in page appears.
  5. When you finish, go back to the window and press Ctrl+C. Your books and translations stay on the server.

What does this command do? It creates a private, encrypted connection between your computer and your server (known as an “SSH tunnel”). While the window stays open, http://localhost:8088 in your browser shows the Libris running on your server. There is nothing else to open or configure on the server: Libris is not visible on the internet, and only you can reach it, with your key.

On a shared computer, close the window when you leave.

To share Libris with other people or open it at an https address, see “Open Libris to your network”; you do not need it to get started.

Cost and shutdown

The server costs the plan’s monthly price, sometimes billed by the hour, plus any storage, backup, or IP options. The model may cost extra. To stop charges, export your books and verify your backups, then delete the VPS in your provider’s control panel. Deleting the server removes the books and translations stored on it.

Troubleshooting

Connection refused / timed out
Check the IP address, that the server is running, and that its network rule allows SSH (port 22) from your connection.
http://localhost:8088 does not open
Open this address in your computer’s browser, not on the server. Check that the window where you ran the ssh -N -L command is open and that Libris is installed. If ssh is not found on an older Windows 10 PC, install the optional OpenSSH Client feature in Settings > Apps > Optional features.
Permission denied (publickey)
Check the account name from your provider, that the right public key was added to the VPS, and that you are using its matching private key.
ARM server
The image does not run on ARM. Recreate the server with x86-64 / AMD64 architecture; changing the operating system does not change the processor.
Not enough memory
Choose 4 GB RAM. Stop other workloads and avoid 1 GB plans: installation and a translation need memory in addition to the operating system.

Continue with the Libris Translate installation