TL;DR / SOME ASSEMBLY AUTOMATED
The server
shortcut department.
Three scripts. Two services. One place to find out exactly what happens when you hit Enter.
Run the install commands inside your server's SSH session. Installers need root; diagnostics do not. These scripts do not buy a VPS, set DNS, open your provider firewall, or install the Strife desktop client. For the full order of operations, start with the getting-started checklist.
A pipe executes the downloaded script with the privileges you give
Bash. You can also download, read, and verify the same files below.
The scripts fail on errors, keep credentials out of their normal
output, and perform platform checks before installation. Run
--help to inspect requirements.
01 / Mumble voice server
Target: Linux x86_64 or ARM64 with a local Docker Engine and Compose v2, OpenSSL, iproute2, and coreutils. Follow the per-OS Docker instructions first. This is a fresh-install script.
set -o pipefail
curl --proto '=https' --tlsv1.2 -fsSL https://strife.zip/scripts/mumble.sh | sudo bash
Downloads the official Mumble 1.5.915 image pinned by digest.
Creates /opt/strife-mumble, a Compose file, persistent
data, and separate random join/admin passwords. Publishes
64738/TCP and 64738/UDP on all interfaces, starts
the container with restart enabled, and checks local TLS readiness.
Docker-published ports can bypass UFW; use a provider firewall or
Docker-aware packet filtering. No SSH or firewall rules are edited.
An existing install directory, project, or occupied port causes a
stop before replacement. A failed first run retains its files for
inspection and recovery. Re-running
does not reset passwords. Read them privately with
sudo cat /opt/strife-mumble/mumble.env; share only the
server password with friends.
02 / Helltube + nginx + HTTPS
Target: dedicated Ubuntu 26.04 x86_64 or ARM64 with systemd and an interactive SSH terminal. The upstream installer was designed for an Ubuntu LXC; a VPS must provide the same systemd/network prerequisites. A fresh full VM is the simplest host. Ubuntu 24.04, Debian, Fedora, Windows and macOS use the manual route.
set -o pipefail
curl --proto '=https' --tlsv1.2 -fsSL https://strife.zip/scripts/helltube.sh | sudo bash
Have a DNS-only backend hostname, Let's Encrypt email, and a Cloudflare token scoped to your zone with DNS:Edit and Zone:Read ready. DNS must be hosted on Cloudflare for this installer's DNS-01 flow. The manual Caddy route works with other DNS providers.
The launcher downloads Helltube revision
b8edab6a0faca32fdddadc1ccfbba74444f7d8bf, verifies archive SHA-256
c17e3e90309fb1843d331d2bd43dc6e68e33a464c114fe5bb0289fc3310efc38, then runs that checkout's installer with input from
/dev/tty. Interactive answers never come from the pipe.
The upstream script installs Node/media dependencies, nginx,
Certbot, an unprivileged Helltube service, persistent storage,
protected credentials, and TLS renewal. It replaces seeded passwords
before startup. It offers optional YouTube cookies, WireGuard
routing, and automatic updates; leave these unused for the first
deployment. Opting into updates later follows upstream
main, outside this initial pin.
Reruns replace managed nginx, service and environment
configuration.
Back up first. The launcher does not roll back a failed upstream
install. Retrieve the initial admin password privately with
sudo cat /etc/helltube/.secrets/admin-password. Public
desktop media still needs the
44444/TCP+UDP configuration.
03 / Is it actually reachable?
Target: Linux or macOS, from your laptop or server.
Replace both hostnames. Requires curl; the voice check also needs
OpenSSL and timeout (macOS:
brew install coreutils supplies gtimeout).
set -o pipefail
curl --proto '=https' --tlsv1.2 -fsSL https://strife.zip/scripts/doctor.sh | bash -s -- voice.example.com watch.example.com
Reads relevant listeners and DNS; probes Mumble TLS, Helltube HTTPS health, and the external internal-route block. Failed probes exit nonzero; unavailable optional tools are labeled SKIP. It changes no files or settings and reads no credential files. TLS reachability does not verify the Mumble certificate or UDP delivery. Finish with the two-client acceptance test.
Download, inspect, then run
This downloads all three files and checks them against the published SHA256SUMS. Checksums fetched from the same website detect corrupt or mismatched downloads; they are not an independent signature or a substitute for trusting the publisher. The first two scripts are intended to run as root only on their supported server platforms.
mkdir strife-scripts
cd strife-scripts
for file in mumble.sh helltube.sh doctor.sh SHA256SUMS; do
curl --proto '=https' --tlsv1.2 -fSLO "https://strife.zip/scripts/$file" || exit 1
done
sha256sum -c SHA256SUMS || exit 1 # macOS: shasum -a 256 -c SHA256SUMS || exit 1
less mumble.sh
bash mumble.sh --help
# After reading it, on your Linux server:
sudo bash mumble.sh
All bootstrap scripts are versioned alongside this website in strife-web source. Downloads become available when this site revision is deployed. Infrastructure provisioning, real certificates, and remote media playback must be verified on your own host.