TL;DR / SOME ASSEMBLY AUTOMATED

The server
shortcut department.

Three scripts. Two services. One place to find out exactly what happens when you hit Enter.

Run the install commands inside your server's SSH session. Installers need root; diagnostics do not. These scripts do not buy a VPS, set DNS, open your provider firewall, or install the Strife desktop client. For the full order of operations, start with the getting-started checklist.

A pipe executes the downloaded script with the privileges you give Bash. You can also download, read, and verify the same files below. The scripts fail on errors, keep credentials out of their normal output, and perform platform checks before installation. Run --help to inspect requirements.

01 / Mumble voice server

Target: Linux x86_64 or ARM64 with a local Docker Engine and Compose v2, OpenSSL, iproute2, and coreutils. Follow the per-OS Docker instructions first. This is a fresh-install script.

set -o pipefail
curl --proto '=https' --tlsv1.2 -fsSL https://strife.zip/scripts/mumble.sh | sudo bash

Downloads the official Mumble 1.5.915 image pinned by digest. Creates /opt/strife-mumble, a Compose file, persistent data, and separate random join/admin passwords. Publishes 64738/TCP and 64738/UDP on all interfaces, starts the container with restart enabled, and checks local TLS readiness. Docker-published ports can bypass UFW; use a provider firewall or Docker-aware packet filtering. No SSH or firewall rules are edited.

An existing install directory, project, or occupied port causes a stop before replacement. A failed first run retains its files for inspection and recovery. Re-running does not reset passwords. Read them privately with sudo cat /opt/strife-mumble/mumble.env; share only the server password with friends.

02 / Helltube + nginx + HTTPS

Target: dedicated Ubuntu 26.04 x86_64 or ARM64 with systemd and an interactive SSH terminal. The upstream installer was designed for an Ubuntu LXC; a VPS must provide the same systemd/network prerequisites. A fresh full VM is the simplest host. Ubuntu 24.04, Debian, Fedora, Windows and macOS use the manual route.

set -o pipefail
curl --proto '=https' --tlsv1.2 -fsSL https://strife.zip/scripts/helltube.sh | sudo bash

Have a DNS-only backend hostname, Let's Encrypt email, and a Cloudflare token scoped to your zone with DNS:Edit and Zone:Read ready. DNS must be hosted on Cloudflare for this installer's DNS-01 flow. The manual Caddy route works with other DNS providers.

The launcher downloads Helltube revision b8edab6a0faca32fdddadc1ccfbba74444f7d8bf, verifies archive SHA-256 c17e3e90309fb1843d331d2bd43dc6e68e33a464c114fe5bb0289fc3310efc38, then runs that checkout's installer with input from /dev/tty. Interactive answers never come from the pipe.

The upstream script installs Node/media dependencies, nginx, Certbot, an unprivileged Helltube service, persistent storage, protected credentials, and TLS renewal. It replaces seeded passwords before startup. It offers optional YouTube cookies, WireGuard routing, and automatic updates; leave these unused for the first deployment. Opting into updates later follows upstream main, outside this initial pin.

Reruns replace managed nginx, service and environment configuration. Back up first. The launcher does not roll back a failed upstream install. Retrieve the initial admin password privately with sudo cat /etc/helltube/.secrets/admin-password. Public desktop media still needs the 44444/TCP+UDP configuration.

03 / Is it actually reachable?

Target: Linux or macOS, from your laptop or server. Replace both hostnames. Requires curl; the voice check also needs OpenSSL and timeout (macOS: brew install coreutils supplies gtimeout).

set -o pipefail
curl --proto '=https' --tlsv1.2 -fsSL https://strife.zip/scripts/doctor.sh | bash -s -- voice.example.com watch.example.com

Reads relevant listeners and DNS; probes Mumble TLS, Helltube HTTPS health, and the external internal-route block. Failed probes exit nonzero; unavailable optional tools are labeled SKIP. It changes no files or settings and reads no credential files. TLS reachability does not verify the Mumble certificate or UDP delivery. Finish with the two-client acceptance test.

Download, inspect, then run

This downloads all three files and checks them against the published SHA256SUMS. Checksums fetched from the same website detect corrupt or mismatched downloads; they are not an independent signature or a substitute for trusting the publisher. The first two scripts are intended to run as root only on their supported server platforms.

mkdir strife-scripts
cd strife-scripts
for file in mumble.sh helltube.sh doctor.sh SHA256SUMS; do
  curl --proto '=https' --tlsv1.2 -fSLO "https://strife.zip/scripts/$file" || exit 1
done
sha256sum -c SHA256SUMS || exit 1  # macOS: shasum -a 256 -c SHA256SUMS || exit 1
less mumble.sh
bash mumble.sh --help
# After reading it, on your Linux server:
sudo bash mumble.sh

All bootstrap scripts are versioned alongside this website in strife-web source. Downloads become available when this site revision is deployed. Infrastructure provisioning, real certificates, and remote media playback must be verified on your own host.