Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Docs / Meilisearch (Hardened) / Install

Install Meilisearch (Hardened)

Launch, connect, and validate — with the expected result after every step.

Prerequisites

AWS

  1. Subscribe and launch.
    Expected result curl http://127.0.0.1:7700/health returns available; master key readable via sudo.
  2. For network use: front it with TLS (nginx/ALB), keep 7700 bound to loopback or your subnet, and open the firewall to your app tier only. Send Authorization: Bearer <key> on every request.
    Expected result Remote search queries authenticate; keyless requests are 401.

Google Cloud

  1. Deploy from the listing (IAP-only SSH; 7700 closed by the package by default).
    Expected result On the VM: curl http://127.0.0.1:7700/health returns available; master key readable via sudo.
  2. For in-VPC clients: front it with TLS, change MEILI_HTTP_ADDR via a systemd drop-in (or keep loopback behind a local proxy), restart, then add a firewall rule for 7700 from your app subnet only.
    Expected result Remote search queries authenticate; keyless requests are 401.

Validate

curl -s http://127.0.0.1:7700/health   → {"status":"available"}

First boot: meilisearch-firstboot.service creates /etc/meilisearch.env with the per-instance master key (ConditionPathExists guard), then meilisearch.service (MEILI_ENV=production, bound to 127.0.0.1:7700, analytics off) starts. Health endpoint answers within seconds.

First login / credentials

  1. SSH in with the key pair you chose at launch (AWS: ssh ec2-user@<public-ip>; GCP: gcloud compute ssh <vm> --tunnel-through-iap).
  2. Read the master key generated for this instance: sudo grep MEILI_MASTER_KEY /etc/meilisearch.env
  3. Use it as a Bearer token: curl -H "Authorization: Bearer <key>" http://127.0.0.1:7700/keys — then create scoped API keys via POST /keys and never hand the master key to applications.

Secure it

Costs & quotas

Software is billed by the marketplace at the listed rate; infrastructure (VM, storage, egress) is billed by your cloud at its standard rates. The recommended size fits default service quotas in most accounts — if you scale out, review your cloud's quota console before launch.

Next: configuration · troubleshooting · security notes