Installing what den needs
den runs a few programs it does not ship with: the AWS CLI and its Session Manager plugin for tunnels, a client per data store for the connect commands, and the CLIs behind secrets and the VPN. You only need the ones your den.yaml uses. On your own machine, let den work it out:
den doctor # checks everything den.yaml uses
den check-install --for sops,rds # only these features, config or not
den doctor --for sops --os windows # another platform's steps, for onboarding notesden prints install commands; it never runs them. The commands below are the
same ones den doctor prints. Download URLs are shown for amd64 (x86_64);
den doctor --os debian/arm64 prints the arm64 ones.
Features
den doctor --for takes these names. Tunnelled services assume the ssm
transport unless ssh, eice or kubectl is named too.
| Feature | For | Tools |
|---|---|---|
aws | AWS SSO logins | aws |
aws_secretsmanager | AWS Secrets Manager | aws |
claude | writing runbooks with Claude Code | claude |
codex | writing runbooks with Codex | codex |
docker | Docker Compose environments | docker |
documentdb | DocumentDB | mongosh + a transport |
eice | tunnels through EC2 Instance Connect Endpoint | aws |
keepassxc | KeePassXC databases | keepassxc-cli |
kubectl | tunnels through kubectl port-forward | kubectl |
mysql | RDS/Aurora MySQL | mysql + a transport |
neptune | Neptune | curl + a transport |
opensearch | OpenSearch | curl + a transport |
rds | RDS/Aurora PostgreSQL | psql + a transport |
redis | ElastiCache and MemoryDB | redis-cli + a transport |
redshift | Redshift | psql + a transport |
runbook-sources | runbooks from git repositories (runbooks.sources) | git |
sops | sops-encrypted secret files | sops |
ssh | tunnels through an SSH jump host | ssh |
ssm | tunnels through an SSM bastion (the default) | aws, session-manager-plugin |
tui | the dashboard’s icons | nerd-font |
tunnel | user-defined SSH/SOCKS tunnels | ssh |
vault | HashiCorp Vault secrets | vault |
vpn | FortiGate SSL VPN | openfortivpn |
Tools
aws
Used for AWS SSO logins, SSM sessions and IAM tokens. Needs 2.0.0 or newer: SSO sessions need AWS CLI v2. Docs: https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html
macOS (Homebrew)
brew install awscliDebian / Ubuntu (official installer)
curl -fsSLo awscliv2.zip "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip"
unzip -q awscliv2.zip
sudo ./aws/installFedora / RHEL (official installer)
curl -fsSLo awscliv2.zip "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip"
unzip -q awscliv2.zip
sudo ./aws/installWindows (winget)
winget install -e --id Amazon.AWSCLIsession-manager-plugin
Used for SSM tunnels (the AWS CLI hands sessions to it). Docs: https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager-working-with-install-plugin.html
macOS (Homebrew)
brew install --cask session-manager-pluginDebian / Ubuntu (official installer)
curl -fsSLo session-manager-plugin.deb "https://s3.amazonaws.com/session-manager-downloads/plugin/latest/ubuntu_64bit/session-manager-plugin.deb"
sudo dpkg -i session-manager-plugin.debFedora / RHEL (dnf)
sudo dnf install -y https://s3.amazonaws.com/session-manager-downloads/plugin/latest/linux_64bit/session-manager-plugin.rpmWindows (winget)
winget install -e --id Amazon.SessionManagerPluginpsql
Used for the connect command of PostgreSQL and Redshift services. Docs: https://www.postgresql.org/download/
macOS (Homebrew)
brew install libpq
brew link --force libpqDebian / Ubuntu (apt)
sudo apt-get install -y postgresql-clientFedora / RHEL (dnf)
sudo dnf install -y postgresqlWindows (winget)
winget install -e --id PostgreSQL.PostgreSQL.18mysql
Used for the connect command of RDS/Aurora MySQL services. Docs: https://dev.mysql.com/doc/refman/8.4/en/installing.html
macOS (Homebrew)
brew install mysql-client
brew link --force mysql-clientDebian / Ubuntu (apt)
sudo apt-get install -y default-mysql-clientFedora / RHEL (dnf)
sudo dnf install -y mysqlWindows (winget)
winget install -e --id Oracle.MySQLredis-cli
Used for the connect command of ElastiCache and MemoryDB services. Needs 6.0.0 or newer: IAM auth needs –user, added in redis-cli 6. Docs: https://redis.io/docs/latest/operate/oss_and_stack/install/
macOS (Homebrew)
brew install redisDebian / Ubuntu (apt)
sudo apt-get install -y redis-toolsFedora / RHEL (dnf)
sudo dnf install -y redisWindows (Scoop)
scoop install redismongosh
Used for the connect command of DocumentDB services. Docs: https://www.mongodb.com/docs/mongodb-shell/install/
macOS (Homebrew)
brew install mongoshDebian / Ubuntu (apt)
# add the MongoDB repository first: https://www.mongodb.com/docs/mongodb-shell/install/
sudo apt-get install -y mongodb-mongoshFedora / RHEL (dnf)
# add the MongoDB repository first: https://www.mongodb.com/docs/mongodb-shell/install/
sudo dnf install -y mongodb-mongoshWindows (winget)
winget install -e --id MongoDB.Shellcurl
Used for the connect command of OpenSearch and Neptune services. Docs: https://curl.se/download.html
macOS (Homebrew)
brew install curlDebian / Ubuntu (apt)
sudo apt-get install -y curlFedora / RHEL (dnf)
sudo dnf install -y curlWindows (winget)
winget install -e --id cURL.cURLdocker
Used for docker services (docker compose). Docs: https://docs.docker.com/get-started/get-docker/
macOS (Homebrew)
brew install --cask docker-desktopDebian / Ubuntu (official installer)
curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.shFedora / RHEL (official installer)
curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.shWindows (winget)
winget install -e --id Docker.DockerDesktopssh
Used for user-defined tunnels and the ssh transport. Docs: https://www.openssh.com/portable.html
macOS (Homebrew)
brew install opensshDebian / Ubuntu (apt)
sudo apt-get install -y openssh-clientFedora / RHEL (dnf)
sudo dnf install -y openssh-clientsWindows (official installer)
# Windows 10 and later ship OpenSSH; if ssh is missing, in an administrator PowerShell:
Add-WindowsCapability -Online -Name OpenSSH.Client~~~~0.0.1.0kubectl
Used for the kubectl transport. Docs: https://kubernetes.io/docs/tasks/tools/
macOS (Homebrew)
brew install kubectlDebian / Ubuntu (official installer)
curl -fsSLO "https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl"
sudo install -m 0755 kubectl /usr/local/bin/kubectlFedora / RHEL (official installer)
curl -fsSLO "https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl"
sudo install -m 0755 kubectl /usr/local/bin/kubectlWindows (winget)
winget install -e --id Kubernetes.kubectlsops
Used for secrets.sops entries (decrypt and edit). Needs 3.9.0 or newer: editing uses sops edit, added in sops 3.9. Docs: https://getsops.io/docs/#download
macOS (Homebrew)
brew install sopsDebian / Ubuntu (official installer)
curl -fsSLO https://github.com/getsops/sops/releases/download/v3.13.3/sops_3.13.3_amd64.deb
sudo apt-get install -y ./sops_3.13.3_amd64.debFedora / RHEL (dnf)
sudo dnf install -y https://github.com/getsops/sops/releases/download/v3.13.3/sops-3.13.3-1.x86_64.rpmWindows (winget)
winget install -e --id SecretsOPerationS.SOPSgpg
Used for sops files encrypted to a PGP key. Docs: https://gnupg.org/download/
macOS (Homebrew)
brew install gnupgDebian / Ubuntu (apt)
sudo apt-get install -y gnupgFedora / RHEL (dnf)
sudo dnf install -y gnupg2Windows (winget)
winget install -e --id GnuPG.GnuPGvault
Used for secrets.vault entries. Needs 1.11.0 or newer: den reads with vault kv get -mount=, added in Vault 1.11. Docs: https://developer.hashicorp.com/vault/install
macOS (Homebrew)
brew tap hashicorp/tap
brew install hashicorp/tap/vaultDebian / Ubuntu (apt)
wget -O - https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp-archive-keyring.gpg
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] https://apt.releases.hashicorp.com $(grep -oP '(?<=UBUNTU_CODENAME=).*' /etc/os-release || lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list
sudo apt-get update && sudo apt-get install -y vaultFedora / RHEL (dnf)
# on RHEL/CentOS use https://rpm.releases.hashicorp.com/RHEL/hashicorp.repo instead
wget -O- https://rpm.releases.hashicorp.com/fedora/hashicorp.repo | sudo tee /etc/yum.repos.d/hashicorp.repo
sudo dnf install -y vaultWindows (winget)
winget install -e --id Hashicorp.Vaultkeepassxc-cli
Used for secrets.keepassxc entries. Docs: https://keepassxc.org/download/
macOS (Homebrew)
brew install --cask keepassxcDebian / Ubuntu (apt)
sudo apt-get install -y keepassxcFedora / RHEL (dnf)
sudo dnf install -y keepassxcWindows (winget)
winget install -e --id KeePassXCTeam.KeePassXCopenfortivpn
Used for vpn entries (FortiGate SSL VPN). Needs 1.23.0 or newer: den logs in with SAML (–saml-login), added in openfortivpn 1.23.0. Docs: https://github.com/adrienverge/openfortivpn#installing
macOS (Homebrew)
brew install openfortivpnDebian / Ubuntu (apt)
sudo apt-get install -y openfortivpnIf apt installs one older than 1.23.0:
# this release's openfortivpn predates SAML: build 1.24.1 from source
sudo apt-get remove -y openfortivpn
sudo apt-get install -y git gcc automake autoconf libssl-dev make pkg-config ppp
src=$(mktemp -d) && git clone --depth 1 --branch v1.24.1 https://github.com/adrienverge/openfortivpn.git "$src"
(cd "$src" && ./autogen.sh && ./configure --prefix=/usr/local --sysconfdir=/etc --enable-legacy-pppd && make && sudo make install)
# installed den's VPN helper? run den vpn install-helper again: it keeps the old openfortivpn pathFedora / RHEL (dnf)
sudo dnf install -y openfortivpnIf dnf installs one older than 1.23.0:
# this release's openfortivpn predates SAML: build 1.24.1 from source
sudo dnf remove -y openfortivpn
sudo dnf install -y git gcc automake autoconf openssl-devel make pkg-config ppp
src=$(mktemp -d) && git clone --depth 1 --branch v1.24.1 https://github.com/adrienverge/openfortivpn.git "$src"
(cd "$src" && ./autogen.sh && ./configure --prefix=/usr/local --sysconfdir=/etc --enable-legacy-pppd && make && sudo make install)
# installed den's VPN helper? run den vpn install-helper again: it keeps the old openfortivpn pathWindows: not available. openfortivpn has no Windows build; use FortiClient VPN, or run den in WSL on a kernel with PPP (WSL 3.0.1’s has none; 2.7.14’s has).
nerd-font
Used for the TUI’s icons (select the font in your terminal afterwards). Docs: https://www.nerdfonts.com/font-downloads
macOS (Homebrew)
brew install --cask font-jetbrains-mono-nerd-fontDebian / Ubuntu (official installer)
curl -fsSLO https://github.com/ryanoasis/nerd-fonts/releases/latest/download/JetBrainsMono.zip
mkdir -p ~/.local/share/fonts/JetBrainsMono && unzip -o JetBrainsMono.zip -d ~/.local/share/fonts/JetBrainsMono
fc-cache -fFedora / RHEL (official installer)
curl -fsSLO https://github.com/ryanoasis/nerd-fonts/releases/latest/download/JetBrainsMono.zip
mkdir -p ~/.local/share/fonts/JetBrainsMono && unzip -o JetBrainsMono.zip -d ~/.local/share/fonts/JetBrainsMono
fc-cache -fWindows (winget)
winget install -e --id DEVCOM.JetBrainsMonoNerdFontgit
Used for runbook sources: fetching the repositories in runbooks.sources. Docs: https://git-scm.com/downloads
macOS (Homebrew)
brew install gitDebian / Ubuntu (apt)
sudo apt-get install -y gitFedora / RHEL (dnf)
sudo dnf install -y gitWindows (winget)
winget install -e --id Git.Gitclaude
Used for writing a runbook from a description (den runbook new –agent claude). Docs: https://code.claude.com/docs/en/setup
macOS (Homebrew)
brew install --cask claude-codeDebian / Ubuntu (official installer)
curl -fsSL https://claude.ai/install.sh | bashFedora / RHEL (official installer)
curl -fsSL https://claude.ai/install.sh | bashWindows (winget)
winget install Anthropic.ClaudeCodecodex
Used for writing a runbook from a description (den runbook new –agent codex). Docs: https://github.com/openai/codex
macOS (Homebrew)
brew install --cask codexDebian / Ubuntu (official installer)
curl -fsSL https://chatgpt.com/codex/install.sh | shFedora / RHEL (official installer)
curl -fsSL https://chatgpt.com/codex/install.sh | shWindows (official installer)
powershell -ExecutionPolicy ByPass -c "irm https://chatgpt.com/codex/install.ps1 | iex"