Skip to content
Installing what den needs

Installing what den needs

den runs a few programs it does not ship with: the AWS CLI and its Session Manager plugin for tunnels, a client per data store for the connect commands, and the CLIs behind secrets and the VPN. You only need the ones your den.yaml uses. On your own machine, let den work it out:

den doctor                          # checks everything den.yaml uses
den check-install --for sops,rds    # only these features, config or not
den doctor --for sops --os windows  # another platform's steps, for onboarding notes

den prints install commands; it never runs them. The commands below are the same ones den doctor prints. Download URLs are shown for amd64 (x86_64); den doctor --os debian/arm64 prints the arm64 ones.

Features

den doctor --for takes these names. Tunnelled services assume the ssm transport unless ssh, eice or kubectl is named too.

FeatureForTools
awsAWS SSO loginsaws
aws_secretsmanagerAWS Secrets Manageraws
claudewriting runbooks with Claude Codeclaude
codexwriting runbooks with Codexcodex
dockerDocker Compose environmentsdocker
documentdbDocumentDBmongosh + a transport
eicetunnels through EC2 Instance Connect Endpointaws
keepassxcKeePassXC databaseskeepassxc-cli
kubectltunnels through kubectl port-forwardkubectl
mysqlRDS/Aurora MySQLmysql + a transport
neptuneNeptunecurl + a transport
opensearchOpenSearchcurl + a transport
rdsRDS/Aurora PostgreSQLpsql + a transport
redisElastiCache and MemoryDBredis-cli + a transport
redshiftRedshiftpsql + a transport
runbook-sourcesrunbooks from git repositories (runbooks.sources)git
sopssops-encrypted secret filessops
sshtunnels through an SSH jump hostssh
ssmtunnels through an SSM bastion (the default)aws, session-manager-plugin
tuithe dashboard’s iconsnerd-font
tunneluser-defined SSH/SOCKS tunnelsssh
vaultHashiCorp Vault secretsvault
vpnFortiGate SSL VPNopenfortivpn

Tools

aws

Used for AWS SSO logins, SSM sessions and IAM tokens. Needs 2.0.0 or newer: SSO sessions need AWS CLI v2. Docs: https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html

macOS (Homebrew)

brew install awscli

Debian / Ubuntu (official installer)

curl -fsSLo awscliv2.zip "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip"
unzip -q awscliv2.zip
sudo ./aws/install

Fedora / RHEL (official installer)

curl -fsSLo awscliv2.zip "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip"
unzip -q awscliv2.zip
sudo ./aws/install

Windows (winget)

winget install -e --id Amazon.AWSCLI

session-manager-plugin

Used for SSM tunnels (the AWS CLI hands sessions to it). Docs: https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager-working-with-install-plugin.html

macOS (Homebrew)

brew install --cask session-manager-plugin

Debian / Ubuntu (official installer)

curl -fsSLo session-manager-plugin.deb "https://s3.amazonaws.com/session-manager-downloads/plugin/latest/ubuntu_64bit/session-manager-plugin.deb"
sudo dpkg -i session-manager-plugin.deb

Fedora / RHEL (dnf)

sudo dnf install -y https://s3.amazonaws.com/session-manager-downloads/plugin/latest/linux_64bit/session-manager-plugin.rpm

Windows (winget)

winget install -e --id Amazon.SessionManagerPlugin

psql

Used for the connect command of PostgreSQL and Redshift services. Docs: https://www.postgresql.org/download/

macOS (Homebrew)

brew install libpq
brew link --force libpq

Debian / Ubuntu (apt)

sudo apt-get install -y postgresql-client

Fedora / RHEL (dnf)

sudo dnf install -y postgresql

Windows (winget)

winget install -e --id PostgreSQL.PostgreSQL.18

mysql

Used for the connect command of RDS/Aurora MySQL services. Docs: https://dev.mysql.com/doc/refman/8.4/en/installing.html

macOS (Homebrew)

brew install mysql-client
brew link --force mysql-client

Debian / Ubuntu (apt)

sudo apt-get install -y default-mysql-client

Fedora / RHEL (dnf)

sudo dnf install -y mysql

Windows (winget)

winget install -e --id Oracle.MySQL

redis-cli

Used for the connect command of ElastiCache and MemoryDB services. Needs 6.0.0 or newer: IAM auth needs –user, added in redis-cli 6. Docs: https://redis.io/docs/latest/operate/oss_and_stack/install/

macOS (Homebrew)

brew install redis

Debian / Ubuntu (apt)

sudo apt-get install -y redis-tools

Fedora / RHEL (dnf)

sudo dnf install -y redis

Windows (Scoop)

scoop install redis

mongosh

Used for the connect command of DocumentDB services. Docs: https://www.mongodb.com/docs/mongodb-shell/install/

macOS (Homebrew)

brew install mongosh

Debian / Ubuntu (apt)

# add the MongoDB repository first: https://www.mongodb.com/docs/mongodb-shell/install/
sudo apt-get install -y mongodb-mongosh

Fedora / RHEL (dnf)

# add the MongoDB repository first: https://www.mongodb.com/docs/mongodb-shell/install/
sudo dnf install -y mongodb-mongosh

Windows (winget)

winget install -e --id MongoDB.Shell

curl

Used for the connect command of OpenSearch and Neptune services. Docs: https://curl.se/download.html

macOS (Homebrew)

brew install curl

Debian / Ubuntu (apt)

sudo apt-get install -y curl

Fedora / RHEL (dnf)

sudo dnf install -y curl

Windows (winget)

winget install -e --id cURL.cURL

docker

Used for docker services (docker compose). Docs: https://docs.docker.com/get-started/get-docker/

macOS (Homebrew)

brew install --cask docker-desktop

Debian / Ubuntu (official installer)

curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh

Fedora / RHEL (official installer)

curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh

Windows (winget)

winget install -e --id Docker.DockerDesktop

ssh

Used for user-defined tunnels and the ssh transport. Docs: https://www.openssh.com/portable.html

macOS (Homebrew)

brew install openssh

Debian / Ubuntu (apt)

sudo apt-get install -y openssh-client

Fedora / RHEL (dnf)

sudo dnf install -y openssh-clients

Windows (official installer)

# Windows 10 and later ship OpenSSH; if ssh is missing, in an administrator PowerShell:
Add-WindowsCapability -Online -Name OpenSSH.Client~~~~0.0.1.0

kubectl

Used for the kubectl transport. Docs: https://kubernetes.io/docs/tasks/tools/

macOS (Homebrew)

brew install kubectl

Debian / Ubuntu (official installer)

curl -fsSLO "https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl"
sudo install -m 0755 kubectl /usr/local/bin/kubectl

Fedora / RHEL (official installer)

curl -fsSLO "https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl"
sudo install -m 0755 kubectl /usr/local/bin/kubectl

Windows (winget)

winget install -e --id Kubernetes.kubectl

sops

Used for secrets.sops entries (decrypt and edit). Needs 3.9.0 or newer: editing uses sops edit, added in sops 3.9. Docs: https://getsops.io/docs/#download

macOS (Homebrew)

brew install sops

Debian / Ubuntu (official installer)

curl -fsSLO https://github.com/getsops/sops/releases/download/v3.13.3/sops_3.13.3_amd64.deb
sudo apt-get install -y ./sops_3.13.3_amd64.deb

Fedora / RHEL (dnf)

sudo dnf install -y https://github.com/getsops/sops/releases/download/v3.13.3/sops-3.13.3-1.x86_64.rpm

Windows (winget)

winget install -e --id SecretsOPerationS.SOPS

gpg

Used for sops files encrypted to a PGP key. Docs: https://gnupg.org/download/

macOS (Homebrew)

brew install gnupg

Debian / Ubuntu (apt)

sudo apt-get install -y gnupg

Fedora / RHEL (dnf)

sudo dnf install -y gnupg2

Windows (winget)

winget install -e --id GnuPG.GnuPG

vault

Used for secrets.vault entries. Needs 1.11.0 or newer: den reads with vault kv get -mount=, added in Vault 1.11. Docs: https://developer.hashicorp.com/vault/install

macOS (Homebrew)

brew tap hashicorp/tap
brew install hashicorp/tap/vault

Debian / Ubuntu (apt)

wget -O - https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp-archive-keyring.gpg
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] https://apt.releases.hashicorp.com $(grep -oP '(?<=UBUNTU_CODENAME=).*' /etc/os-release || lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list
sudo apt-get update && sudo apt-get install -y vault

Fedora / RHEL (dnf)

# on RHEL/CentOS use https://rpm.releases.hashicorp.com/RHEL/hashicorp.repo instead
wget -O- https://rpm.releases.hashicorp.com/fedora/hashicorp.repo | sudo tee /etc/yum.repos.d/hashicorp.repo
sudo dnf install -y vault

Windows (winget)

winget install -e --id Hashicorp.Vault

keepassxc-cli

Used for secrets.keepassxc entries. Docs: https://keepassxc.org/download/

macOS (Homebrew)

brew install --cask keepassxc

Debian / Ubuntu (apt)

sudo apt-get install -y keepassxc

Fedora / RHEL (dnf)

sudo dnf install -y keepassxc

Windows (winget)

winget install -e --id KeePassXCTeam.KeePassXC

openfortivpn

Used for vpn entries (FortiGate SSL VPN). Needs 1.23.0 or newer: den logs in with SAML (–saml-login), added in openfortivpn 1.23.0. Docs: https://github.com/adrienverge/openfortivpn#installing

macOS (Homebrew)

brew install openfortivpn

Debian / Ubuntu (apt)

sudo apt-get install -y openfortivpn

If apt installs one older than 1.23.0:

# this release's openfortivpn predates SAML: build 1.24.1 from source
sudo apt-get remove -y openfortivpn
sudo apt-get install -y git gcc automake autoconf libssl-dev make pkg-config ppp
src=$(mktemp -d) && git clone --depth 1 --branch v1.24.1 https://github.com/adrienverge/openfortivpn.git "$src"
(cd "$src" && ./autogen.sh && ./configure --prefix=/usr/local --sysconfdir=/etc --enable-legacy-pppd && make && sudo make install)
# installed den's VPN helper? run den vpn install-helper again: it keeps the old openfortivpn path

Fedora / RHEL (dnf)

sudo dnf install -y openfortivpn

If dnf installs one older than 1.23.0:

# this release's openfortivpn predates SAML: build 1.24.1 from source
sudo dnf remove -y openfortivpn
sudo dnf install -y git gcc automake autoconf openssl-devel make pkg-config ppp
src=$(mktemp -d) && git clone --depth 1 --branch v1.24.1 https://github.com/adrienverge/openfortivpn.git "$src"
(cd "$src" && ./autogen.sh && ./configure --prefix=/usr/local --sysconfdir=/etc --enable-legacy-pppd && make && sudo make install)
# installed den's VPN helper? run den vpn install-helper again: it keeps the old openfortivpn path

Windows: not available. openfortivpn has no Windows build; use FortiClient VPN, or run den in WSL on a kernel with PPP (WSL 3.0.1’s has none; 2.7.14’s has).

nerd-font

Used for the TUI’s icons (select the font in your terminal afterwards). Docs: https://www.nerdfonts.com/font-downloads

macOS (Homebrew)

brew install --cask font-jetbrains-mono-nerd-font

Debian / Ubuntu (official installer)

curl -fsSLO https://github.com/ryanoasis/nerd-fonts/releases/latest/download/JetBrainsMono.zip
mkdir -p ~/.local/share/fonts/JetBrainsMono && unzip -o JetBrainsMono.zip -d ~/.local/share/fonts/JetBrainsMono
fc-cache -f

Fedora / RHEL (official installer)

curl -fsSLO https://github.com/ryanoasis/nerd-fonts/releases/latest/download/JetBrainsMono.zip
mkdir -p ~/.local/share/fonts/JetBrainsMono && unzip -o JetBrainsMono.zip -d ~/.local/share/fonts/JetBrainsMono
fc-cache -f

Windows (winget)

winget install -e --id DEVCOM.JetBrainsMonoNerdFont

git

Used for runbook sources: fetching the repositories in runbooks.sources. Docs: https://git-scm.com/downloads

macOS (Homebrew)

brew install git

Debian / Ubuntu (apt)

sudo apt-get install -y git

Fedora / RHEL (dnf)

sudo dnf install -y git

Windows (winget)

winget install -e --id Git.Git

claude

Used for writing a runbook from a description (den runbook new –agent claude). Docs: https://code.claude.com/docs/en/setup

macOS (Homebrew)

brew install --cask claude-code

Debian / Ubuntu (official installer)

curl -fsSL https://claude.ai/install.sh | bash

Fedora / RHEL (official installer)

curl -fsSL https://claude.ai/install.sh | bash

Windows (winget)

winget install Anthropic.ClaudeCode

codex

Used for writing a runbook from a description (den runbook new –agent codex). Docs: https://github.com/openai/codex

macOS (Homebrew)

brew install --cask codex

Debian / Ubuntu (official installer)

curl -fsSL https://chatgpt.com/codex/install.sh | sh

Fedora / RHEL (official installer)

curl -fsSL https://chatgpt.com/codex/install.sh | sh

Windows (official installer)

powershell -ExecutionPolicy ByPass -c "irm https://chatgpt.com/codex/install.ps1 | iex"
Last updated on